Courseiva

CCNA Nse4 System Network Questions

75 of 149 questions · Page 1/2 · Nse4 System Network topic · Answers revealed

1
MCQmedium

An administrator configures a policy route to force traffic from a specific source subnet to use a particular WAN interface. After applying the configuration, the traffic still uses the default route. What is the most likely cause?

A.The static default route has a lower administrative distance than the policy route
B.The FortiGate's VDOM is enabled and the policy route is in the wrong VDOM
C.The policy route's incoming interface is incorrectly configured
D.The policy route has a lower priority than the static default route
AnswerC

Policy routes are matched based on the incoming interface alongside source and destination criteria. If the configured incoming interface does not match the physical or logical interface on which the traffic actually enters, the FortiGate will skip the policy route and fall back to the routing table. For example, specifying port1 while traffic arrives on port2 means the policy is never evaluated, so the traffic follows the default route instead.

Why this answer

Policy routes are evaluated based on the incoming interface specified in the rule. If the incoming interface is misconfigured (e.g., set to 'any' or the wrong physical interface), the FortiGate will not match the traffic against the policy route, causing it to fall through to the routing table and use the default route. The policy route must explicitly match the interface on which the traffic enters the FortiGate.

Exam trap

The trap here is that candidates often confuse policy routes with static routes or assume that a policy route applies globally, when in fact the incoming interface is a critical matching condition that must be correctly configured for the policy to take effect.

How to eliminate wrong answers

Option A is wrong because administrative distance applies to routes in the routing table, not to policy routes; policy routes override the routing table regardless of administrative distance. Option B is wrong because while VDOM misplacement can cause policy routes to not apply, the question states the configuration was applied, and VDOM issues would typically prevent the policy from being created or visible, not silently ignore it. Option D is wrong because policy routes do not have a 'priority' value relative to static routes; they are evaluated before the routing table lookup, and if the incoming interface matches, the policy route is used unconditionally.

2
MCQmedium

You run 'get system performance status' and see CPU usage at 95% with high context switch rate. The FortiGate is not passing any traffic. What is the most likely cause?

A.A routing loop is causing continuous packet processing
B.The FortiGate is under a DDoS attack
C.The antivirus engine is updating signatures
D.The FortiGate is in transparent mode
AnswerA

A routing loop occurs when packets are repeatedly forwarded between interfaces or virtual domains without reaching a final destination, causing the kernel's forwarding engine to process the same packet iteratively. This can happen with static routes pointing to each other or with dynamic routing protocol inconsistencies, and on FortiGate it often shows high CPU in the kernel's netlink or IP forwarding process. Since the loop re-injects packets into the forwarding pipeline even in the absence of external traffic (e.g., from self-originated packets or multicast), it can sustain 95% CPU utilization.

Why this answer

A routing loop causes the FortiGate to continuously process and re-process packets as they are forwarded in a cycle between routers, leading to high CPU usage and context switch rates. The loop prevents traffic from being successfully delivered, resulting in zero traffic passing through the FortiGate. This matches the observed symptoms of 95% CPU usage and high context switching.

Exam trap

The trap here is that candidates often associate high CPU usage with a DDoS attack, but the key clue is the high context switch rate combined with zero traffic passing, which points to a routing loop rather than a flood of traffic.

How to eliminate wrong answers

Option B is wrong because a DDoS attack would typically cause high CPU usage and packet drops, but the FortiGate would still pass some legitimate traffic or at least process packets; the complete inability to pass traffic is more characteristic of a routing loop. Option C is wrong because antivirus signature updates are a background process that may cause a temporary CPU spike but not sustained 95% usage with high context switching, and they do not prevent all traffic from passing. Option D is wrong because transparent mode does not inherently cause high CPU usage or context switching; it is a Layer 2 forwarding mode that should not impact performance in this way.

3
MCQeasy

Which command is used to back up the FortiGate configuration to a TFTP server?

A.save config tftp <filename> <server_ip>
B.backup tftp config <filename> <server_ip>
C.execute backup config tftp <filename> <server_ip>
D.copy config tftp <filename> <server_ip>
AnswerC

This is the exact and only valid FortiGate CLI command for backing up configuration to a TFTP server. The 'execute' verb initiates an administrative task, 'backup config' specifies the operation, and 'tftp <filename> <server_ip>' supplies the transfer protocol and destination. After entering the command, the FortiGate prompts for confirmation and then uploads the complete configuration file to the specified TFTP server.

Why this answer

The correct command to back up the FortiGate configuration to a TFTP server is 'execute backup config tftp <filename> <server_ip>'. This is because FortiGate uses the 'execute' command for operational tasks, and 'backup config tftp' specifically instructs the system to export the running configuration to a TFTP server. The other options use incorrect syntax or commands that are not recognized by the FortiGate CLI.

Exam trap

The trap here is that candidates familiar with Cisco IOS may mistakenly choose 'copy config tftp' (Option D), which is valid for Cisco but not for FortiGate, where the correct syntax requires 'execute backup config tftp'.

How to eliminate wrong answers

Option A is wrong because 'save config tftp' is not a valid FortiGate command; the correct syntax uses 'execute backup' rather than 'save'. Option B is wrong because 'backup tftp config' reverses the order of keywords and omits 'execute', which is required for operational commands in FortiGate. Option D is wrong because 'copy config tftp' is a Cisco IOS command, not a FortiGate command; FortiGate uses 'execute backup config tftp' for this purpose.

4
MCQhard

A medium-sized enterprise has a FortiGate 100F in NAT/Route mode with three interfaces: port1 (WAN, 203.0.113.1/24, gateway 203.0.113.254), port2 (internal, 192.168.1.1/24), and port3 (DMZ, 10.0.0.1/24). The internal network hosts a web server at 192.168.1.10 and a mail server at 192.168.1.20. The DMZ hosts a public web server at 10.0.0.10 and a public DNS server at 10.0.0.20. The company has a single public IP 203.0.113.1. The administrator has configured the following: - Port forwarding: external HTTP to DMZ web server (10.0.0.10:80) and external DNS to DMZ DNS server (10.0.0.20:53). - Outbound NAT (IP Pool) for internal users to 203.0.113.1. - Firewall policies allowing internal to external, DMZ to external, and external to DMZ (for forwarded services). Users report that they can access the Internet but cannot reach the internal web server (192.168.1.10) via its public IP (203.0.113.1:80). The DMZ web server is accessible from the Internet. What is the most likely cause?

A.The firewall policy from internal to DMZ is blocking traffic
B.Hairpin NAT is not enabled on the FortiGate
C.The port forwarding rule maps the public IP to the DMZ server, not the internal server
D.The IP Pool for outbound NAT is misconfigured
AnswerC

The port forwarding rule, implemented as a Virtual IP (VIP), maps the public IP and port to 10.0.0.10, which is the DMZ server. When internal users attempt to access the internal server via the public IP, the FortiGate uses this VIP and translates the destination to the DMZ server's IP address. Consequently, the traffic never reaches the intended internal server, and the internal users cannot establish a connection to it. To resolve this, the VIP's mapped IP must be changed to the internal server's address, or a separate VIP must be created for the internal server.

Why this answer

The port forwarding rule is configured to forward external HTTP requests (port 80) to the DMZ web server at 10.0.0.10. The internal web server at 192.168.1.10 is not covered by any port forwarding rule. Therefore, when internal users try to access the public IP 203.0.113.1:80, the traffic is not redirected to the internal server, and the request fails.

This is the primary cause, not a missing hairpin NAT or misconfigured outbound NAT.

Exam trap

The trap here is that candidates often assume hairpin NAT is the universal fix for internal access to public IPs, but they overlook that the port forwarding rule must first exist for the target internal server; without that rule, hairpin NAT has no effect.

How to eliminate wrong answers

Option A is wrong because the problem is about accessing the internal web server via its public IP, not about traffic between internal and DMZ zones; the firewall policy from internal to DMZ is irrelevant here. Option B is wrong because hairpin NAT (also called NAT reflection) is only needed when a device on the internal network tries to reach another internal device via the public IP, but in this scenario, the port forwarding rule does not even point to the internal server, so enabling hairpin NAT would not fix the issue. Option D is wrong because the IP Pool for outbound NAT is correctly configured to translate internal users' source IPs to 203.0.113.1 for Internet access, and users can already access the Internet, indicating outbound NAT is functioning properly.

5
MCQeasy

An administrator needs to allow management access to a FortiGate from the internal network only via HTTPS and SSH. The internal interface is named internal. Which configuration should the administrator apply?

A.Create a firewall policy allowing HTTPS and SSH from the internal network to the FortiGate's internal IP address.
B.Enable HTTPS and SSH under System > Settings and set the management port to the internal interface.
C.Under Network > Interfaces, edit the internal interface and enable HTTPS and SSH in the Administrative Access section.
D.Configure an admin user with a trusthost of the internal subnet and set the admin profile to allow HTTPS and SSH.
AnswerC

Enabling HTTPS and SSH under Administrative Access on the internal interface allows management access from that network. This is the correct place to control which protocols are permitted for management on a per-interface basis. Other protocols remain disabled, meeting the requirement.

Why this answer

Management access protocols are enabled per interface under Network > Interfaces by selecting the desired protocols in the Administrative Access section. This directly controls which protocols are allowed on that interface. Firewall policies, trusthost, and global settings do not enable management protocols on an interface.

Exam trap

The trap here is confusing firewall policies with interface administrative access settings, thinking that a policy is needed to allow management traffic to the FortiGate.

6
Multi-Selectmedium

An administrator wants to use FortiManager to manage multiple FortiGates. Which three steps must be performed to establish communication between a FortiGate and FortiManager? (Choose THREE.)

Select 3 answers
A.Place the FortiGate in transparent mode
B.Ensure network connectivity between the FortiGate and FortiManager
C.Configure the FortiGate's management interface with an IP address
D.Enable FortiManager registration and provide a registration password
E.Set the FortiManager IP address on the FortiGate under System > FortiManager
AnswersB, D, E

Network connectivity between the FortiGate and FortiManager is the fundamental prerequisite for registration. The FortiGate must be able to reach the FortiManager's IP address over TCP port 541, and any intermediate firewalls must permit this traffic, or the registration handshake will time out or be rejected. Without end-to-end IP reachability and correct routing, even the most accurate configuration of other registration parameters will fail, making this the first and most critical requirement.

Why this answer

FortiManager communicates with managed FortiGates over TCP/541 (FGFM protocol). Without IP-level connectivity between the two devices, the registration and management tunnel cannot be established. This is a prerequisite before any configuration steps can succeed.

Exam trap

The trap here is that candidates often confuse general FortiGate interface configuration (Option C) with the specific FortiManager registration steps, or incorrectly assume transparent mode (Option A) is required for management, when in fact the three required steps are ensuring connectivity, enabling registration with a password, and setting the FortiManager IP address on the FortiGate.

7
MCQhard

A FortiGate in NAT/Route mode has a policy with NAT enabled. The admin needs the source IP of traffic from internal users (192.168.1.0/24) to be translated to the interface IP of port1 (203.0.113.1) when accessing the internet. Which configuration is necessary?

A.Add a static route for 192.168.1.0/24 with next-hop 203.0.113.1
B.Set the administrative access to HTTPS on port1
C.Create a central NAT rule with source 192.168.1.0/24 and IP pool 203.0.113.2-203.0.113.10
D.Configure a firewall policy with NAT enabled and the outbound interface set to port1
AnswerD

Enabling NAT on the firewall policy with port1 as the outbound interface triggers source NAT, translating internal 192.168.1.0/24 addresses to port1's interface IP 203.0.113.1. This satisfies the requirement without configuring IP pools or central NAT.

Why this answer

In NAT/Route mode, enabling NAT on a firewall policy with the outbound interface set to port1 causes the FortiGate to translate the source IP of traffic from the internal network (192.168.1.0/24) to the IP address of that interface (203.0.113.1) by default. This is the standard method for source NAT (SNAT) in a policy-based configuration, requiring no additional IP pool or static route for the translation itself.

Exam trap

The trap here is that candidates may confuse the need for an IP pool or static route with the simple policy-based NAT, assuming that translating to the interface IP requires additional configuration beyond enabling NAT on the policy.

How to eliminate wrong answers

Option A is wrong because a static route for 192.168.1.0/24 with next-hop 203.0.113.1 is unnecessary and incorrect; the internal subnet is directly connected, and the next-hop for internet-bound traffic should be the default gateway, not the interface IP. Option B is wrong because setting administrative access to HTTPS on port1 only enables management access to the interface, not source NAT translation. Option C is wrong because creating a central NAT rule with an IP pool of 203.0.113.2-203.0.113.10 would translate the source IP to a range of addresses, not the single interface IP (203.0.113.1), which does not match the requirement.

8
MCQmedium

A FortiGate administrator needs to upgrade the firmware from FortiOS 6.4 to 7.0. The administrator downloads the upgrade image but when uploading via the GUI, the FortiGate reboots and comes back with the same firmware version. What is the most likely cause?

A.The firmware image was corrupted during download.
B.The FortiGate does not support firmware upgrade via GUI; CLI must be used.
C.The administrator uploaded the wrong image (e.g., for a different FortiGate model).
D.The administrator must first upgrade to an intermediate version before 7.0.
AnswerC

Uploading a firmware image intended for a different FortiGate model is the most plausible cause. FortiOS image files are model-specific and include a platform identifier in their header. When the FortiGate detects a mismatched platform ID, it rejects the image as invalid and aborts the upgrade, rebooting back into the current firmware without applying any changes. The administrator likely selected the wrong file from the local machine, and the device's built-in compatibility check saved it from becoming unbootable.

Why this answer

Uploading a firmware image intended for a different FortiGate model will cause the upgrade to fail silently. The FortiGate validates the image against its hardware platform; if the image does not match, the device rejects it and reboots with the existing firmware. This is a common issue when administrators accidentally download the image for a different series (e.g., FortiGate 100F vs. 200F).

Exam trap

The trap here is that candidates may assume a reboot with unchanged firmware always indicates corruption or a need for intermediate upgrades, overlooking the critical platform validation that rejects mismatched images.

How to eliminate wrong answers

Option A is wrong because a corrupted image would typically cause a checksum error or fail to upload, not result in a reboot with the same firmware version. Option B is wrong because FortiGate fully supports firmware upgrades via the GUI; CLI is an alternative but not a requirement. Option D is wrong because FortiGate 6.4 to 7.0 is a direct upgrade path supported by Fortinet; no intermediate version is required for this jump.

9
MCQhard

An administrator runs the following CLI command on a FortiGate: 'diagnose sys session filter dport 443' and sees output indicating sessions with proto_state=01 and duration=3600. What does this indicate about the sessions?

A.The sessions are UDP-based and have been active for 3600 seconds.
B.The sessions are TCP connections in SYN state and have a timeout of 3600 seconds.
C.The sessions are TCP connections in established state with a duration of 3600 seconds.
D.The sessions are ICMP packets with a TTL of 3600.
AnswerB

Correct. 'proto_state=01' corresponds to TCP SYN_SENT state, and duration=3600 means the session has been in that state for 3600 seconds.

Why this answer

The command filters sessions on destination port 443. The output field 'proto_state=01' indicates a TCP session in SYN_SENT state (state 1), which is the initial step of a TCP handshake. The 'duration=3600' field shows that the session has been active for 3600 seconds (or represents a time value).

Option B correctly identifies the state as TCP SYN and the number 3600 as a time value, making it the most accurate choice. Option A is wrong because UDP does not have a SYN state. Option C is wrong because state 01 is not established (established is state 06).

Option D is wrong because ICMP does not use ports.

Exam trap

The trap is to associate 'duration' with a timeout or TTL value, and to misinterpret 'proto_state=01' as established (state 6) rather than SYN_SENT (state 1).

How to eliminate wrong answers

Option A is wrong because 'proto_state=01' is specific to TCP, not UDP; UDP sessions use different state codes (e.g., 00 for no state). Option B is wrong because 'proto_state=01' represents the established state, not the SYN state (which would be state 0x02 or similar), and 'duration' is the elapsed time, not a timeout value. Option D is wrong because ICMP packets do not use TCP port numbers like 443, and 'duration' is not related to TTL (Time To Live).

10
MCQhard

An administrator configures an HA cluster of two FortiGates in active-passive mode. The cluster is synchronized, but after a failover, some existing TCP sessions are dropped. What is the most likely cause?

A.The heartbeat interface is configured as a dedicated management interface
B.Session synchronization (session-pickup) is disabled
C.The cluster is operating in NAT mode
D.The cluster is using a virtual MAC address for the HA interface
AnswerB

Session synchronization, also called session pickup on FortiGate, is the feature that continuously replicates the primary unit's session table to the standby unit. When session-pickup is disabled, the standby device boots or takes over with an empty session table, so every existing TCP and UDP flow must be re-established, causing application interruptions and lost user sessions. This is the only option that directly explains why sessions are dropped during a failover event.

Why this answer

Session synchronization (session-pickup) is required for active-passive HA clusters to replicate TCP session state from the primary FortiGate to the secondary. When disabled, the backup unit has no knowledge of existing sessions after a failover, causing those sessions to be dropped because the new primary cannot match incoming packets to any session table entry.

Exam trap

The trap here is that candidates often confuse virtual MAC addressing or heartbeat configuration with session state replication, but the core requirement for session persistence after failover is session-pickup being enabled.

How to eliminate wrong answers

Option A is wrong because a dedicated management heartbeat interface does not affect session synchronization; it only separates management traffic from HA traffic. Option C is wrong because NAT mode does not inherently cause session drops after failover; session-pickup is still required regardless of the operation mode. Option D is wrong because using a virtual MAC address for the HA interface ensures seamless Layer 2 failover but does not impact session state replication; session-pickup is the mechanism that preserves TCP sessions.

11
Multi-Selectmedium

An administrator is troubleshooting why traffic from a specific source IP is not being matched by a policy route. Which THREE steps should the administrator take to diagnose the issue?

Select 3 answers
A.Disable all firewall policies to test routing.
B.Change the administrative distance of the default route to 0.
C.Verify the source address object in the policy route matches the traffic's source IP.
D.Check the policy route list order and ensure the matching condition is above the default route.
E.Use the 'diagnose debug flow' command to trace packet flow.
AnswersC, D, E

Policy routes in FortiOS use address objects as match conditions, and the object must contain the exact source IP or subnet for the traffic in question. If the object is misconfigured—wrong subnet, incorrect IP, or a different object type—the policy route will be silently skipped. Verifying this match is the first step to confirm that the traffic can actually hit the intended policy route.

Why this answer

The most fundamental step in troubleshooting a policy route mismatch is to verify that the source address object defined in the policy route exactly matches the source IP of the traffic. If the object is misconfigured (e.g., wrong subnet mask, incorrect IP range, or a typo), the traffic will never hit the policy route, regardless of other settings.

Exam trap

The trap here is that candidates often jump to modifying routing or firewall policies (Options A and B) instead of first verifying the policy route's matching criteria and order, which are the most common root causes of policy route mismatches.

12
MCQhard

An organization has two FortiGate units in an HA cluster. They need to perform a firmware upgrade on the primary unit without causing a failover. Which procedure should be followed?

A.Upgrade the primary unit first, then the secondary will automatically synchronize
B.Upgrade both units simultaneously using the GUI
C.Disable HA, upgrade both, then re-enable HA
D.Upgrade the secondary unit first, then perform a graceful failover, then upgrade the original primary
AnswerD

Upgrade the secondary (standby) unit first so the active primary continues to pass traffic throughout the upgrade process; the secondary then joins the HA cluster with the new firmware. Once the secondary is fully upgraded and synchronized, perform a graceful failover to make it the new primary, which transfers the active sessions to the upgraded unit. Finally, upgrade the original primary (now standby) during a maintenance window, ensuring only one unit is offline at a time and no traffic is dropped.

Why this answer

In an HA cluster, upgrading the secondary unit first ensures that the primary remains active and can take over if the upgrade fails. After the secondary is upgraded and stable, a graceful failover is performed to make it the new primary, allowing the original primary to be upgraded without causing an unplanned failover or service interruption.

Exam trap

The trap here is that candidates assume upgrading the primary first is safe because the secondary will synchronize, but they overlook that the primary reboot triggers an automatic failover, which is not a 'graceful' upgrade path.

How to eliminate wrong answers

Option A is wrong because upgrading the primary first would cause it to reboot, triggering an automatic failover to the secondary, which is not desired. Option B is wrong because upgrading both units simultaneously can lead to a split-brain scenario or both units rebooting at the same time, causing a complete outage. Option C is wrong because disabling HA breaks the cluster state and requires re-synchronization, which is disruptive and not recommended for a controlled upgrade.

13
MCQmedium

An administrator notices that traffic to a particular subnet is being load-balanced across two WAN links, but they want all traffic to that subnet to use a single link. Which feature should be configured?

A.Policy routing
B.ECMP routing
C.Static route with higher distance
D.Route summarization
AnswerA

Policy routing (also called policy-based routing) uses a route map to match specific packet attributes—such as source IP, destination IP, or protocol—and forwards those packets to a defined next-hop or interface, bypassing the normal longest-prefix-match routing table lookup. For traffic to a particular subnet, this allows an administrator to override the default routing decision and force that traffic out a specific interface, which is exactly what the scenario requires.

Why this answer

Policy routing (also called PBR) allows you to override the routing table based on criteria such as source/destination IP, protocol, or port. By configuring a policy route that matches traffic to the specific subnet and sets the output interface to a single WAN link, you can force all that traffic to use one link instead of being load-balanced.

Exam trap

The trap here is that candidates often confuse ECMP load-balancing with the ability to pin traffic to a single link, mistakenly thinking that adjusting ECMP weights or distances will achieve the same result as policy routing.

How to eliminate wrong answers

Option B is wrong because ECMP (Equal-Cost Multi-Path) routing is exactly what causes load-balancing across multiple equal-cost routes; disabling or not using ECMP would not selectively force traffic to a single link without affecting other traffic. Option C is wrong because a static route with a higher distance would only be used as a backup if the primary route fails, but it does not prevent load-balancing when multiple equal-cost routes exist. Option D is wrong because route summarization aggregates multiple subnets into a single prefix to reduce routing table size, but it does not control which link is used for traffic to a specific subnet.

14
Multi-Selecthard

An administrator is configuring a FortiGate HA cluster in active-passive mode with two units. Which two conditions must be met for failover to occur? (Choose two.)

Select 2 answers
A.A monitored interface on the primary unit goes down
B.The primary unit loses all heartbeat communication with the secondary unit
C.The secondary unit receives a higher priority configuration
D.The primary unit's CPU usage exceeds 90%
E.The primary unit stops sending session synchronization packets
AnswersA, B

A monitored interface failing triggers failover because FortiGate HA actively tracks link health; when a monitored interface on the primary goes down, the cluster treats it as a failure condition and promotes the secondary. This satisfies the stem's requirement for a valid failover trigger in active-passive mode.

Why this answer

Option A is correct because in an active-passive FortiGate HA cluster, failover is triggered when a monitored interface (configured under config system ha with monitor-interface) goes down on the primary unit, causing the cluster to renegotiate and the secondary to take over. Option B is correct because loss of all heartbeat communication (via the HA heartbeat interfaces, using FGCP over UDP/703 or Ethernet frames) causes the secondary to conclude the primary has failed and assume the primary role. Option C is not correct because priority is only evaluated at cluster formation or when a unit rejoins; a higher priority on the secondary does not by itself force a failover of an established cluster.

Option D is not correct because CPU usage thresholds are not a native HA failover trigger in FortiOS. Option E is not correct because session synchronization packets are not heartbeats; stopping session sync alone does not trigger failover, only loss of heartbeat or a monitored interface failure does.

Exam trap

The trap is that candidates may think there are three valid failover conditions, but only two are standard. Often, they mistakenly include CPU threshold or session sync loss as triggers, but FortiGate HA does not use resource utilization or session sync status to initiate failover unless custom configurations are applied.

15
MCQhard

You run the following diagnose command on a FortiGate and see the output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 ... What does the 'proto_state=01' indicate?

A.The session is UDP, indicated by proto_state 01
B.The session is in a half-open state (SYN_SENT)
C.The session has been fully established
D.The session is being terminated
AnswerB

proto_state=01 in a FortiGate session table represents TCP SYN_SENT, which occurs when a client has sent a SYN packet and is waiting for the server's SYN-ACK reply. This is a half-open state because the TCP three-way handshake has not yet completed; the connection is not fully established. If the handshake completes, the state advances to ESTABLISHED (06), so seeing 01 means the session is in the initial connection-attempt phase.

Why this answer

In FortiGate session diagnostics, 'proto_state=01' for a TCP session (proto=6) indicates the session is in a half-open state, specifically SYN_SENT, meaning the initial SYN packet has been sent but the three-way handshake has not yet completed. This is a transient state before the session becomes fully established (proto_state=02).

Exam trap

The trap here is that candidates confuse 'proto_state=01' with a fully established session because they see 'duration' and 'expire' values that look normal, not realizing that a half-open TCP session can still have a duration counter if the initial SYN was sent.

How to eliminate wrong answers

Option A is wrong because proto_state=01 is a TCP state indicator, not UDP; UDP sessions do not use proto_state values in the same way and proto=6 explicitly indicates TCP. Option C is wrong because a fully established TCP session is indicated by proto_state=02 (ESTABLISHED), not 01. Option D is wrong because a session being terminated would show a state like FIN_WAIT or TIME_WAIT, not proto_state=01 which represents an incomplete handshake.

16
MCQhard

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is in established state and has been active for 1 hour
B.The session is in FIN_WAIT state
C.The session is in TIME_WAIT state and will close soon
D.The session is in SYN_SENT state waiting for a SYN-ACK
AnswerA

The session entry shows proto_state=01, which in Fortinet's session table maps to TCP-established. The duration field of 3600 is expressed in seconds, so the session has been continuously active for exactly one hour. This is the normal state for an ongoing HTTPS connection on port 443, so this option correctly interprets the output.

Why this answer

The output shows `proto=6` (TCP), `proto_state=01` (ESTABLISHED state per Fortinet's session state encoding), `duration=3600` seconds (1 hour), and `expire=3599` seconds (nearly full lifetime remaining). This indicates the session is actively established and has been ongoing for one hour, matching the description of an established state session.

Exam trap

The trap here is that candidates misinterpret `proto_state=01` as a generic 'active' state without knowing Fortinet's specific numeric encoding, leading them to confuse it with FIN_WAIT or TIME_WAIT states that have different numeric values and shorter expire times.

How to eliminate wrong answers

Option B is wrong because `proto_state=01` corresponds to TCP ESTABLISHED, not FIN_WAIT (which would be state 05 or 06 in Fortinet's session table). Option C is wrong because TIME_WAIT state (state 09) would show a short expire value near zero, not 3599 seconds, and the session is not closing soon. Option D is wrong because SYN_SENT state (state 02) would show `proto_state=02` and a very short duration, not 3600 seconds of activity.

17
MCQhard

An administrator configures an aggregate interface (port1 and port2) on a FortiGate. After connecting the switch ports, the aggregate interface shows 'down'. The individual member ports are up. What is the MOST likely cause?

A.The member ports are set to different speeds
B.The switch ports are not configured for LACP or static aggregation
C.The aggregate interface IP address is in the same subnet as the management interface
D.The FortiGate needs a reboot after creating an aggregate interface
AnswerB

An aggregate interface on a FortiGate requires the connected switch ports to be placed in a matching port-channel or LACP group. If the switch ports are left as ordinary access or trunk ports without LACP or static aggregation, the FortiGate does not receive the expected LACP protocol data units, and the aggregate interface remains down because the link-aggregation handshake never completes. This is the most common cause of an aggregate that is administratively up but physically down.

Why this answer

The aggregate interface remains down because the switch ports are not configured for LACP or static aggregation. For a FortiGate aggregate interface to come up, both the FortiGate member ports and the corresponding switch ports must be configured with the same aggregation protocol (LACP active/passive or static). Without this, the switch treats the ports as individual links, causing a mismatch that keeps the aggregate interface down.

Exam trap

The trap here is that candidates assume the aggregate interface will come up automatically if the member ports are physically up, overlooking the requirement for matching aggregation configuration on the switch side.

How to eliminate wrong answers

Option A is wrong because different speeds on member ports would cause the aggregate interface to fail to form or degrade performance, but the individual ports would still show up; the aggregate interface would not necessarily show 'down' due to speed mismatch alone, as FortiGate can still form an aggregate with speed differences in some configurations. Option C is wrong because an IP address conflict between the aggregate interface and the management interface would cause routing or connectivity issues, not prevent the aggregate interface from coming up at Layer 1/2. Option D is wrong because a reboot is not required after creating an aggregate interface; the interface state updates dynamically once the configuration and physical connections are correct.

18
MCQmedium

An administrator is configuring a FortiGate in a transparent mode. Which of the following features is NOT available in transparent mode?

A.Source NAT
B.VLAN tagging
C.Intrusion Prevention System (IPS)
D.Security profiles (AV, web filter)
AnswerA

Source NAT is not available in transparent mode because the FortiGate acts as a Layer 2 bridge, forwarding frames based on MAC addresses without performing any Layer 3 routing decisions. NAT requires modifying source IP addresses during packet routing, which is inherently a Layer 3 function, so it cannot be applied to traffic that passes through transparently.

Why this answer

In transparent mode, the FortiGate operates as a Layer 2 bridge without routing capabilities, meaning it cannot perform Source NAT (SNAT) because SNAT requires Layer 3 routing to translate source IP addresses. Transparent mode does not have an IP address on its interfaces for routing, so features dependent on Layer 3 forwarding, such as NAT, are unavailable.

Exam trap

The trap here is that candidates often assume security features like IPS or AV require Layer 3 routing, but they actually operate at higher layers and work in transparent mode, while NAT is the only option that explicitly depends on Layer 3 functionality.

How to eliminate wrong answers

Option B is wrong because VLAN tagging is fully supported in transparent mode; the FortiGate can pass and even tag/untag VLAN frames as a Layer 2 device. Option C is wrong because IPS operates at Layer 2-7 and inspects traffic passing through the bridge, so it works in transparent mode without requiring Layer 3 routing. Option D is wrong because security profiles like antivirus and web filtering inspect application-layer content and are independent of Layer 3 routing, making them available in transparent mode.

19
MCQmedium

A network administrator configures a new FortiGate as the default gateway for a subnet. The FortiGate has two WAN interfaces (port1 and port2) connected to different ISPs. The admin wants to load-balance outbound traffic across both links. Which configuration method will achieve this goal?

A.Configure a single default gateway and rely on ARP for failover
B.Configure a policy route for each subnet directing traffic to a different ISP
C.Configure two static default routes with different distances
D.Configure two static default routes with the same distance and metric
AnswerD

Two static default routes with equal distance and metric create ECMP, so the FortiGate distributes outbound sessions across port1 and port2. This satisfies the load-balancing requirement without policy routes. Unequal distance would make one route standby only, defeating the goal.

Why this answer

Configuring two static default routes with the same distance and metric enables ECMP (Equal-Cost Multi-Path) routing on FortiGate. This allows the FortiGate to load-balance outbound traffic across both WAN interfaces (port1 and port2) using a per-flow or per-packet algorithm, distributing sessions between the two ISPs.

Exam trap

The trap here is that candidates often confuse ECMP (same distance/metric) with floating static routes (different distances), mistakenly thinking that multiple default routes with different distances will load-balance, when in fact they only provide failover.

How to eliminate wrong answers

Option A is wrong because relying on a single default gateway with ARP failover does not provide load balancing; it only offers failover if the gateway becomes unreachable, and ARP is not a load-balancing mechanism. Option B is wrong because policy routes direct traffic based on source/destination criteria, not for general load balancing of all outbound traffic; they are used for selective routing, not equal distribution across two default paths. Option C is wrong because configuring two static default routes with different distances creates a primary/backup scenario (floating static route), where only the route with the lower distance is active, and the other is used only if the primary fails—no load balancing occurs.

20
MCQmedium

A company wants to ensure that administrative access to FortiGate is only allowed from the internal trusted network (192.168.1.0/24) and that all other access attempts are blocked. Which CLI command should the administrator configure first?

A.config system admin; edit admin; set trusthost 192.168.1.0 255.255.255.0; end
B.config system interface; edit port1; set allowaccess ping https ssh; end
C.config system global; set admin-http-redirect enable; end
D.set admin-sport 443
AnswerA

The 'trusthost' command under 'config system admin' defines an allowed source IP or subnet for administrative logins to that specific admin account. By setting '192.168.1.0 255.255.255.0', only clients originating from the 192.168.1.0/24 network can authenticate as 'admin' — all other source IPs are rejected at the management daemon level, regardless of credentials. This is the only provided option that actually restricts administrative access to a specific source address range.

Why this answer

The `config system admin` command with `set trusthost` restricts administrative login attempts to only the specified source IP address or subnet. By setting `trusthost 192.168.1.0 255.255.255.0`, the FortiGate will only allow admin access from the 192.168.1.0/24 network, blocking all other sources. This is the foundational step to enforce source-based access control for administrative interfaces.

Exam trap

The trap here is that candidates often confuse `set allowaccess` (which enables protocols on an interface) with `set trusthost` (which restricts source IPs for admin login), leading them to select Option B thinking it controls who can access the device.

How to eliminate wrong answers

Option B is wrong because `config system interface` with `set allowaccess` controls which administrative protocols (e.g., HTTPS, SSH, PING) are enabled on a specific interface, not the source IP addresses allowed to connect. Option C is wrong because `config system global` with `set admin-http-redirect enable` only redirects HTTP admin traffic to HTTPS for encryption, it does not restrict the source network of admin access. Option D is wrong because `set admin-sport 443` changes the administrative HTTPS port to 443 (or another port), but it does not filter which source IPs can reach that port.

21
MCQmedium

A FortiGate is deployed at a branch office with a single WAN link. The administrator wants to ensure that the FortiGate itself can resolve external hostnames for features like FortiGuard lookups, but does not want internal clients to use the FortiGate as their DNS server. Which configuration should the administrator apply?

A.Configure a DNS filter profile on the outbound firewall policy and set the FortiGate as the primary DNS in the DHCP server.
B.Configure DNS servers under System > DNS on the FortiGate, and leave the internal interface DNS settings unchanged.
C.Set the FortiGate as a DNS forwarder under Network > DNS Servers and configure a firewall policy to allow DNS.
D.Enable DNS server on the internal interface and set the same DNS servers in the DHCP scope.
AnswerB

The System > DNS settings define the DNS servers the FortiGate uses for its own lookups, such as FortiGuard and DNS filtering. This does not enable the FortiGate to answer DNS queries from clients. Internal clients continue using their own DNS servers because the interface DNS settings are not modified.

Why this answer

The FortiGate needs its own DNS settings for system lookups, which are configured under System > DNS. This does not affect clients unless the interface DNS server feature is enabled or DHCP hands out the FortiGate as a DNS server. Leaving the internal interface DNS settings unchanged ensures clients continue using their own DNS servers.

Exam trap

The trap here is assuming that configuring DNS servers under System > DNS automatically makes the FortiGate a DNS server for connected clients.

22
MCQhard

A FortiGate is configured in an HA active-passive cluster. The primary unit fails. After the secondary takes over, a policy route configured on the primary is not working. What is the MOST likely reason?

A.The secondary unit does not support policy routes
B.The policy route configuration is not synchronized in HA
C.The HA cluster requires a reboot after failover
D.The policy route references an interface that does not exist on the new primary
AnswerD

The most plausible cause is that the policy route specifies a destination or source interface that only exists on the original primary, not on the new primary. In an HA cluster, configuration is synced as a whole, but if the physical interfaces are named differently on the secondary (for example, due to different hardware models) or the interface is a VLAN/subinterface whose underlying port is not present, the policy route becomes invalid after failover. FortiGate will then skip or deactivate the route because the referenced interface is missing, resulting in traffic not being routed as expected.

Why this answer

When a FortiGate HA cluster fails over, the new primary unit assumes the configuration synchronized from the original primary. However, if a policy route references a specific interface (e.g., port1 or a VLAN subinterface) that is physically present on the failed unit but not on the new primary (or has a different name/index), the policy route will fail because the kernel cannot resolve the egress interface. FortiGate HA synchronizes the configuration, but interface mappings must match across cluster members for policy routes to work after failover.

Exam trap

The trap here is that candidates assume HA synchronizes everything perfectly, but they overlook that interface-dependent objects like policy routes can break if the physical interface mapping differs between cluster members.

How to eliminate wrong answers

Option A is wrong because FortiGate secondary units in an active-passive HA cluster fully support policy routes; there is no feature restriction based on role. Option B is wrong because HA synchronization includes policy route configuration by default (via the HA configuration synchronization mechanism), so the configuration is present on the secondary. Option C is wrong because HA failover does not require a reboot; the secondary takes over seamlessly without a reboot, and a reboot would only be needed if the cluster is recovering from a split-brain or other severe error.

23
MCQmedium

A FortiGate administrator needs to integrate with FortiAnalyzer for centralized logging. After configuring the FortiAnalyzer IP and enabling logging, the FortiGate shows 'connection status: disconnected'. What is the most likely cause?

A.The FortiGate is in transparent mode.
B.The FortiAnalyzer firmware version is newer than the FortiGate's.
C.The administrator forgot to enable HTTPS for log upload.
D.The FortiGate does not have a route to the FortiAnalyzer.
AnswerD

Without a valid matching route to the FortiAnalyzer's IP address, the FortiGate cannot establish the TCP/HTTPS connection needed for log forwarding. The packet will be dropped, and the FortiGate will report communication failures or timeouts. This is a direct and necessary condition for successful integration, making it the correct explanation.

Why this answer

The most likely cause is that the FortiGate does not have a route to the FortiAnalyzer. Even with the correct IP and logging enabled, the FortiGate must be able to reach the FortiAnalyzer over the network; without a valid route, the TCP connection (typically on port 514 for syslog or port 443/541 for FortiGate-FortiAnalyzer protocol) will fail, resulting in a 'disconnected' status.

Exam trap

The trap here is that candidates often assume a configuration or protocol mismatch (like HTTPS or firmware version) is the cause, when the fundamental issue is simple network reachability—FortiGate cannot connect to FortiAnalyzer without a valid route.

How to eliminate wrong answers

Option A is wrong because transparent mode does not inherently prevent connectivity to FortiAnalyzer; the FortiGate can still send logs as long as it has a management IP and a route. Option B is wrong because firmware version differences do not cause a 'disconnected' status; FortiAnalyzer and FortiGate can interoperate across versions, though some features may be limited. Option C is wrong because HTTPS is not required for log upload; FortiGate typically uses syslog (UDP/TCP 514) or the FortiGate-FortiAnalyzer protocol (TCP 541) for logging, and HTTPS is used for web management, not log transport.

24
Matchingmedium

Match each Fortinet security feature to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Detects and prevents network intrusions

Identifies and controls application traffic

Blocks access to malicious or unauthorized websites

Scans and removes malware from traffic

Decrypts and inspects encrypted traffic

Why these pairings

The correct matches are: Antivirus scans for malware, IPS detects network attacks, Application Control identifies applications, Web Filtering blocks websites. Common confusions include mixing antivirus with anti-spam and IPS with antivirus.

25
MCQmedium

A network administrator has configured a static route on a FortiGate with a distance of 10 and a priority of 0. Later, they add another static route to the same destination with a distance of 15 and priority of 0. Which route will be used for traffic forwarding?

A.The route with distance 15 because it has a higher priority
B.Both routes will be used for ECMP load balancing
C.The route with distance 15 will be used because it was added last
D.The route with distance 10 because it has a lower administrative distance
AnswerD

Administrative distance is the primary metric FortiGate uses to choose between routes to the same destination, with lower values being more trustworthy. A static route with AD 10 is considered more reliable than one with AD 15, so it is installed in the routing table and used for forwarding. Only if both routes had an equal AD would other factors like priority be considered as a tiebreaker.

Why this answer

The FortiGate uses administrative distance as the primary metric for route selection when multiple static routes exist to the same destination. A lower administrative distance (10) is preferred over a higher one (15), regardless of the order in which the routes were added. Priority (0 in both cases) is a tie-breaker only when distances are equal, so it does not affect this decision.

Exam trap

The trap here is that candidates often confuse administrative distance with priority or assume that the most recently added route takes precedence, but FortiGate strictly follows the lower administrative distance rule for route selection.

How to eliminate wrong answers

Option A is wrong because a higher distance value indicates lower preference, not higher priority; administrative distance is the primary metric, and lower is better. Option B is wrong because ECMP (Equal-Cost Multi-Path) requires routes to have the same administrative distance and metric; here distances differ (10 vs 15), so ECMP does not apply. Option C is wrong because the FortiGate does not use the order of addition as a routing decision factor; the route with the lower administrative distance is always preferred, regardless of which was added last.

26
MCQmedium

A FortiGate is configured with two WAN interfaces in an active-passive HA cluster. The administrator notices that the passive unit is not synchronizing configuration changes from the active unit. What is the MOST likely cause?

A.The HA heartbeat interface is not configured or is down.
B.The passive unit has a different firmware version.
C.The HA mode is set to active-active instead of active-passive.
D.The administrator must manually trigger a sync from the active unit.
AnswerA

Configuration synchronization in a FortiGate HA cluster depends on the heartbeat link, which carries both liveness detection and configuration/session sync traffic. If the heartbeat interface is not physically assigned or is down, the primary cannot push configuration updates to the secondary, even though the cluster may still be considered up. This results in configuration drift while failover behavior appears normal, exactly matching the symptom described in the question.

Why this answer

In an HA cluster, the heartbeat interface is responsible for synchronizing configuration changes and monitoring peer status between the active and passive units. If the heartbeat interface is not configured or is down, the passive unit cannot receive configuration updates from the active unit, leading to a synchronization failure. This is the most likely cause because without a functional heartbeat link, the cluster cannot maintain state or configuration consistency.

Exam trap

The trap here is that candidates often assume synchronization is triggered manually or that HA mode affects sync behavior, but FortiGate HA relies entirely on a functional heartbeat link for automatic configuration replication, regardless of the active-passive or active-active mode.

How to eliminate wrong answers

Option B is wrong because while different firmware versions can cause compatibility issues, the HA cluster typically prevents formation or logs a version mismatch error, but the passive unit would not even join the cluster; the question states the passive unit is present but not synchronizing, so a missing or down heartbeat is more likely. Option C is wrong because the HA mode (active-active vs. active-passive) affects failover behavior and load sharing, not the synchronization mechanism itself; both modes use the heartbeat interface for sync, so changing the mode would not prevent sync if the heartbeat is functional. Option D is wrong because configuration synchronization in FortiGate HA is automatic and continuous via the heartbeat link; there is no manual trigger required from the active unit—if the heartbeat is up, sync happens automatically.

27
MCQhard

A FortiGate is configured with two equal-cost default routes to different ISPs. The administrator notices that traffic for a specific destination is load-balanced across both links as expected. However, they want all traffic from a specific source IP to use only ISP1, while other traffic remains load-balanced. Which configuration should be applied?

A.Increase the administrative distance of the ISP2 default route to 20
B.Create a policy route with source address set to the specific IP and set the gateway to ISP1
C.Configure SD-WAN rules to steer the traffic
D.Add a static host route for the specific source IP via ISP1
AnswerB

Policy routes are evaluated before the routing table, so a route matching the specific source IP overrides the equal-cost default routes and forces that traffic out ISP1. Other sources match no policy route and remain load-balanced across both ISPs.

Why this answer

Policy routing allows you to override the routing table for specific traffic based on criteria such as source IP. By creating a policy route that matches the specific source IP and sets the next-hop gateway to ISP1, you ensure that traffic from that source always uses ISP1, while all other traffic continues to be load-balanced across both equal-cost default routes. This is the most direct and flexible method for source-based path selection without altering the global routing behavior.

Exam trap

The trap here is that candidates often confuse policy routing with static routing or administrative distance changes, mistakenly thinking that modifying route preference or adding a host route for the source IP will achieve source-based forwarding, when in fact policy routing is the only method that allows traffic selection based on source IP without affecting other traffic.

How to eliminate wrong answers

Option A is wrong because increasing the administrative distance of the ISP2 default route to 20 would make it less preferred than the ISP1 route (default AD 10), causing all traffic to use ISP1 only, not just traffic from the specific source IP. Option C is wrong because SD-WAN rules are designed for advanced traffic steering and load balancing across multiple WAN links, but they require SD-WAN to be enabled and configured, which is an unnecessary complexity for this simple source-based policy requirement; a policy route is the standard and simpler solution. Option D is wrong because a static host route is used for a specific destination IP, not a source IP; adding a static host route for the source IP would be syntactically incorrect and would not achieve the desired behavior.

28
MCQmedium

A FortiGate administrator wants to send logs to a FortiAnalyzer. The FortiAnalyzer IP is 192.168.1.100, and logging is configured under Log & Report. However, no logs are being received. Which command should the administrator use on the FortiGate to verify connectivity to the FortiAnalyzer?

A.diagnose log device status
B.execute ping 192.168.1.100
C.show full-configuration log fortianalyzer
D.get system ha status
AnswerA

diagnose log device status is the correct diagnostic command because it directly queries the FortiGate's logging subsystem to report the operational state of configured log devices, such as a FortiAnalyzer. This command displays fields like connection state (e.g., 'valid' or 'invalid'), the last log message timestamp, and any error counters, verifying whether the FortiAnalyzer is reachable and accepting logs. Unlike ping or configuration views, it reflects the live status of the log-forwarding pipeline, making it the definitive tool for confirming that logs are being transmitted successfully.

Why this answer

The 'diagnose log device status' command specifically checks the connectivity status and last-acknowledged sequence number between the FortiGate and the configured FortiAnalyzer. This command verifies whether the FortiGate can reach the FortiAnalyzer at the logging protocol level (FGFM), which is essential for log transmission, unlike a basic ICMP ping that only tests network-layer reachability.

Exam trap

The trap here is that candidates assume a successful ping (Option B) proves log connectivity, but the NSE4 exam tests the distinction between network-layer reachability and application-layer log protocol status, making the diagnostic command the only correct verification method.

How to eliminate wrong answers

Option B is wrong because 'execute ping 192.168.1.100' only tests basic ICMP reachability at the network layer; it does not verify that the FortiAnalyzer is accepting logs or that the FGFM (FortiGate-to-FortiAnalyzer) tunnel is established. Option C is wrong because 'show full-configuration log fortianalyzer' displays the current logging configuration (e.g., IP, encryption settings) but does not test live connectivity or the status of the log transmission channel. Option D is wrong because 'get system ha status' shows High Availability cluster state and has no relevance to FortiAnalyzer connectivity or log forwarding.

29
MCQeasy

Which command is used to display the current FortiGate firmware version?

A.get system statistics
B.get hardware status
C.get system status
D.get system performance status
AnswerC

The 'get system status' command is the standard FortiGate CLI command to display the current firmware version, along with build number, serial number, hostname, uptime, and the configured operating mode. This output is essential for troubleshooting, verifying patch compliance, and confirming that the device is running an expected FortiOS release. It is the authoritative source for firmware identification.

Why this answer

The 'get system status' command is the correct way to display the current FortiGate firmware version. This command outputs a comprehensive summary of the system state, including the firmware version (e.g., FortiOS v7.4.0), the system uptime, serial number, and HA status. It is the standard CLI command for verifying the exact build and patch level of the FortiGate.

Exam trap

The trap here is that candidates often confuse 'get system status' with 'get system statistics' because both commands start with 'get system', but only 'get system status' provides the firmware version, while 'get system statistics' focuses on performance counters.

How to eliminate wrong answers

Option A is wrong because 'get system statistics' displays real-time traffic statistics such as CPU and memory usage, session counts, and packet rates, not the firmware version. Option B is wrong because 'get hardware status' shows hardware-related information like chassis temperature, fan speed, and power supply status, not the firmware version. Option D is wrong because 'get system performance status' provides a snapshot of system performance metrics (e.g., CPU load, memory utilization, disk usage) but does not include the firmware version.

30
MCQeasy

Which FortiGate operating mode is used when the device acts as a Layer 2 bridge without performing NAT?

A.HA mode
B.Transparent mode
C.VPN mode
D.NAT/Route mode
AnswerB

Transparent mode makes the FortiGate operate as a Layer 2 bridge, forwarding frames based on MAC addresses without performing routing or NAT. All of its interfaces share the same IP subnet, and the device is invisible to IP routing, which is why it is often described as a 'bump in the wire.' This mode is ideal for inserting security controls into an existing network segment without changing the IP addressing scheme.

Why this answer

Transparent mode (Option B) is correct because in this mode the FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses without performing any NAT or routing. The device is invisible to the network, and all interfaces share the same IP subnet, allowing it to inspect and filter traffic at the application layer while remaining transparent to connected devices.

Exam trap

The trap here is that candidates often confuse Transparent mode with NAT/Route mode, assuming that a firewall must always route or perform NAT, when in fact Transparent mode allows Layer 2 inspection without altering the IP path.

How to eliminate wrong answers

Option A is wrong because HA mode (High Availability) is a clustering configuration for redundancy and failover, not an operating mode that determines Layer 2 bridging or NAT behavior. Option C is wrong because VPN mode is not a standard FortiGate operating mode; VPNs are configured as features within either NAT/Route or Transparent mode. Option D is wrong because NAT/Route mode operates at Layer 3, performing routing and NAT by default, which contradicts the requirement of acting as a Layer 2 bridge without NAT.

31
MCQeasy

A network administrator needs to allow SSH access to the FortiGate from a management subnet 10.0.1.0/24. Which configuration step is required on the interface connected to that subnet?

A.Enable HTTPS administrative access only
B.Set the administrative access to 'any'
C.Enable SSH administrative access on the interface
D.Configure a firewall policy allowing SSH from the subnet
AnswerC

SSH access terminates on the FortiGate interface facing the management subnet, so administrative access must be enabled per-protocol on that interface. Without SSH ticked under Administrative Access, the firewall silently drops inbound TCP 22 even if a permissive policy exists.

Why this answer

To allow SSH access to the FortiGate from a specific subnet, you must enable SSH administrative access on the interface connected to that subnet. This setting controls which management protocols are permitted to reach the FortiGate itself at the interface level, independent of firewall policies. Without enabling SSH on the interface, the FortiGate will drop SSH packets at Layer 3 before any policy lookup occurs.

Exam trap

The trap here is that candidates often assume a firewall policy is sufficient to allow management traffic, forgetting that administrative access must be explicitly enabled on the interface for protocols like SSH, HTTPS, or Telnet.

How to eliminate wrong answers

Option A is wrong because enabling only HTTPS administrative access would allow HTTPS but not SSH; SSH requires its own administrative access toggle on the interface. Option B is wrong because there is no 'any' administrative access setting; administrative access is configured per protocol (e.g., HTTPS, SSH, PING) and cannot be set to a wildcard value. Option D is wrong because a firewall policy allowing SSH from the subnet is not sufficient; the interface-level administrative access must first permit SSH management traffic, otherwise the FortiGate discards the packets before they reach the firewall engine.

32
MCQeasy

What is the primary purpose of configuring a loopback interface on a FortiGate?

A.To provide a stable IP address for management and routing protocols
B.To aggregate bandwidth from multiple physical interfaces
C.To enable NAT for internal networks
D.To increase the number of available physical ports
AnswerA

A loopback interface supplies a permanent, always-up IP address independent of any physical link state, satisfying the need for stable management access and reliable routing protocol peering. Because it never goes down unless manually removed, it anchors BGP router IDs and management connectivity even when physical interfaces flap.

Why this answer

A loopback interface on a FortiGate is a virtual interface that is always up, independent of physical link states. It provides a stable and reachable IP address for management access (e.g., HTTPS, SSH) and for routing protocols like OSPF or BGP to use as the router ID or source interface, ensuring consistent connectivity even if physical interfaces fail.

Exam trap

The trap here is that candidates often confuse a loopback interface with a physical interface used for link aggregation or NAT, not realizing its primary role is to provide a stable, always-up logical endpoint for management and routing protocol stability.

How to eliminate wrong answers

Option B is wrong because aggregating bandwidth from multiple physical interfaces is achieved through link aggregation (LACP or static aggregation), not a loopback interface. Option C is wrong because NAT for internal networks is configured using policies and IP pools, not by creating a loopback interface. Option D is wrong because a loopback interface is virtual and does not increase the number of physical ports; it only provides a logical addressing endpoint.

33
MCQmedium

A FortiGate administrator wants to synchronize the system time with an external NTP server. Which CLI command should be used to configure the NTP server?

A.execute date
B.diagnose ntp status
C.config system ntp
D.config system global
AnswerC

The 'config system ntp' command enters the NTP configuration subtree, which is the correct place on a FortiGate to define NTP servers and enable automatic time synchronization. Under this hierarchy, administrators can set primary and secondary NTP server addresses, configure poll intervals, and optionally configure authentication keys. This persistent configuration is what the FortiGate uses to continuously sync its system clock, fulfilling the requirement to synchronize time via NTP.

Why this answer

The `config system ntp` command enters the NTP configuration context in FortiOS, where you can specify NTP servers, authentication, and synchronization settings. This is the standard CLI path for configuring NTP on FortiGate devices, as opposed to other commands that only display status or set the date manually.

Exam trap

The trap here is that candidates confuse `config system ntp` with `config system global` because both are under the `config system` hierarchy, but NTP configuration has its own dedicated subcommand and is not a global setting.

How to eliminate wrong answers

Option A is wrong because `execute date` is used to manually set the system date and time, not to configure an NTP server for automatic synchronization. Option B is wrong because `diagnose ntp status` is a diagnostic command that shows the current NTP synchronization status, not a configuration command. Option D is wrong because `config system global` is used for global system settings like hostname and admin password, not for NTP server configuration.

34
MCQmedium

A FortiGate is configured as a DHCP server for the internal network. The administrator wants to ensure that clients receive the FortiGate's internal IP address as the default gateway and a specific DNS server. Which configuration step is required?

A.In the DHCP server settings, configure the default gateway and DNS server options, and ensure the internal interface IP is set as the gateway.
B.Configure a DHCP relay on the internal interface pointing to the FortiGate's internal IP address.
C.Enable DNS forwarding on the internal interface and set the DNS server in the system settings.
D.Create a firewall policy that allows DHCP traffic from the internal network to the FortiGate's internal interface.
AnswerA

The DHCP server settings allow you to specify the default gateway and DNS servers that clients receive. Setting the default gateway to the FortiGate's internal IP ensures clients route traffic through it. This is the correct way to provide these parameters to DHCP clients.

Why this answer

When configuring a DHCP server on a FortiGate, you can specify the default gateway and DNS servers that clients receive in the DHCP options. Setting the default gateway to the FortiGate's internal IP ensures clients use it as their gateway. The DNS server option provides the desired DNS server.

Other options do not achieve this.

Exam trap

The trap here is thinking that a firewall policy or DNS forwarding is needed to provide DHCP options, when the DHCP server settings already include those parameters.

35
Multi-Selecthard

An administrator is troubleshooting a FortiGate that is not passing traffic. The policy allows traffic, but the session table shows no sessions. Which THREE steps should the administrator take to diagnose the issue? (Choose three.)

Select 3 answers
A.Verify the interface status and link state.
B.Run 'diagnose npu np6 show' to check offloading.
C.Check the ARP table to ensure the next-hop MAC is resolved.
D.Examine the routing table for the destination network.
E.Disable the firewall policy and check if traffic flows.
AnswersA, C, D

Verifying the physical and logical interface state is the first step in any FortiGate connectivity troubleshooting. If the interface is administratively down or the link has no carrier (e.g., bad cable, remote device powered off), all traffic through that interface is dropped regardless of routes or policies. Use `get system interface physical` and `diagnose hardware deviceinfo nic` to confirm link status, speed, and duplex.

Why this answer

If the interface is down or has a link issue, the FortiGate cannot send or receive any traffic, resulting in no sessions being created even if the policy allows traffic. Verifying interface status and link state is a fundamental first step in troubleshooting connectivity issues, as it ensures the physical or logical layer is operational before checking higher-layer configurations.

Exam trap

The trap here is that candidates may assume a policy allowing traffic guarantees session creation, but they overlook that the FortiGate must first be able to physically receive and forward the traffic, which depends on interface, ARP, and routing being correctly configured.

36
MCQhard

A FortiGate in HA active-passive cluster is experiencing failover events. The administrator runs 'get system ha status' and sees that the 'sync status' is 'out of sync'. What is the most likely cause?

A.The HA mode is set to active-active.
B.The session synchronization is disabled.
C.The passive unit has a different firmware version.
D.The heartbeat interface is down.
AnswerC

In FortiGate FGCP HA, both members must run the exact same firmware version and build. If the passive unit has a different firmware version, the cluster will fail to synchronize configurations and may not establish a proper HA relationship, causing failover to fail or behave unpredictably. This is a known requirement: firmware mismatch is one of the most common causes of HA cluster formation and failover problems, and it is the correct answer because it directly prevents the passive unit from serving as a valid standby.

Why this answer

In an HA active-passive cluster, the 'sync status' indicates whether configuration and session data are synchronized between the primary and secondary units. When the passive unit has a different firmware version, the FortiGate cannot synchronize its configuration or sessions because the data structures and features may differ between versions, leading to an 'out of sync' status. This is a common prerequisite: both units must run the exact same firmware image for HA synchronization to function.

Exam trap

The trap here is that candidates often confuse 'session synchronization' with 'configuration synchronization' and assume that disabling session sync (Option B) would cause the 'sync status' to show 'out of sync', but the command output specifically reflects configuration sync status, not session sync.

How to eliminate wrong answers

Option A is wrong because setting the HA mode to active-active does not directly cause an 'out of sync' status; active-active mode still requires synchronization between units, and the sync status would reflect issues like version mismatch or heartbeat failure, not the mode itself. Option B is wrong because disabling session synchronization would only affect session failover capability, not the configuration sync status; the 'sync status' field primarily reflects configuration synchronization, and even with session sync disabled, configuration sync can still be 'in sync'. Option D is wrong because if the heartbeat interface is down, the HA cluster would likely detect a link failure and trigger a failover or show 'heartbeat lost' rather than 'out of sync'; the 'sync status' specifically tracks data synchronization, not heartbeat connectivity.

37
MCQmedium

An administrator wants to aggregate two physical interfaces (port1 and port2) on a FortiGate to increase bandwidth and provide redundancy. Which interface type should be created?

A.Aggregate interface
B.Loopback interface
C.VLAN interface
D.Software switch interface
AnswerA

An aggregate interface bonds port1 and port2 into a single logical link using LACP, combining their throughput and providing failover if one member fails. This delivers both the increased bandwidth and redundancy the administrator requires.

Why this answer

An aggregate interface (also known as a Link Aggregation Group or LAG) combines multiple physical interfaces into a single logical link, increasing bandwidth and providing redundancy. This is the correct choice because it directly supports the administrator's goal of aggregating port1 and port2 on a FortiGate, using the IEEE 802.3ad standard (LACP) or static aggregation.

Exam trap

The trap here is that candidates often confuse a software switch interface with link aggregation, but a software switch simply bridges ports at Layer 2 without the load-balancing and failover mechanisms of an aggregate interface.

How to eliminate wrong answers

Option B is wrong because a loopback interface is a virtual interface used for management or routing protocol stability, not for aggregating physical links. Option C is wrong because a VLAN interface is a logical interface for 802.1Q VLAN tagging on a single physical or aggregate interface, not a method to combine multiple physical ports. Option D is wrong because a software switch interface creates a Layer 2 bridge between ports, but it does not provide link aggregation for increased bandwidth or redundancy in the same way as an aggregate interface.

38
Multi-Selectmedium

An administrator needs to integrate a FortiGate with FortiManager for centralized management. Which two steps are required? (Choose two.)

Select 2 answers
A.Enable SNMP on the FortiGate to allow FortiManager to monitor.
B.Configure a firewall policy allowing traffic from FortiGate to FortiManager on port 541 (FGFM).
C.Configure a VPN tunnel between FortiGate and FortiManager.
D.Configure the FortiGate to connect to FortiManager using the 'execute fortimanager register' command.
E.Set the FortiGate's operation mode to transparent.
AnswersB, D

FortiGate and FortiManager communicate exclusively via the FGFM protocol, which uses TCP port 541. A firewall policy must explicitly permit FortiGate-originated traffic to the FortiManager's IP address on port 541, otherwise registration and heartbeat messages are blocked. This policy is a prerequisite for both the 'execute fortimanager register' command and ongoing management operations, such as policy push and firmware updates.

Why this answer

FortiGate and FortiManager communicate using the FortiGate-to-FortiManager (FGFM) protocol over TCP port 541. A firewall policy must be configured on the FortiGate to allow outbound traffic to the FortiManager on this port, enabling registration and ongoing management. Option D is correct because the 'execute fortimanager register' command is the standard CLI method to initiate the registration process, providing the FortiManager IP address and optional registration code.

Exam trap

The trap here is that candidates often confuse SNMP (monitoring) or VPN (tunneling) as requirements for FortiManager integration, when in fact the FGFM protocol on TCP 541 and the registration command are the only mandatory steps.

39
MCQeasy

What is the default administrative account on a FortiGate?

A.master
B.root
C.guest
D.admin
AnswerD

The correct default administrative account is 'admin'. Every FortiGate ships with this local account, which is assigned the 'super_admin' profile and provides full control through the web GUI and CLI. On first login, administrators are required to set a password for the admin account, ensuring the factory state does not remain with an empty secret.

Why this answer

The default administrative account on a FortiGate is 'admin'. This account is created automatically during the initial boot process and has full super-admin privileges, allowing complete access to the device's configuration and management interfaces. It is the only default account with administrative rights, and its password must be set during initial setup.

Exam trap

The trap here is that candidates may confuse the FortiGate default admin account with the default accounts of other operating systems or network devices, such as 'root' on Linux or 'master' on Cisco, leading them to select the wrong option.

How to eliminate wrong answers

Option A is wrong because 'master' is not a default account on FortiGate; it is a common default account on some other network devices like Cisco switches. Option B is wrong because 'root' is the default administrative account on Unix/Linux systems, not on FortiGate, which runs a proprietary FortiOS. Option C is wrong because 'guest' is a default read-only account on FortiGate, not an administrative account; it is intended for limited monitoring access without configuration privileges.

40
MCQmedium

An administrator is troubleshooting a connectivity issue. A ping from the FortiGate to 8.8.8.8 succeeds, but traffic from internal hosts to the internet is failing. The firewall policy allows the traffic. What is the most likely cause?

A.The default route on the FortiGate is missing
B.The internal hosts have the wrong default gateway configured
C.DNS resolution is failing
D.The FortiGate's interface to the internal network is down
AnswerB

Hosts forward traffic to destinations outside their subnet via their configured default gateway; in this network, that gateway should be the FortiGate's internal interface IP. If the hosts point to a different or nonexistent IP, their packets for internet destinations are sent to a device that cannot forward them, so the traffic never reaches the FortiGate. Even though the FortiGate can ping 8.8.8.8, the hosts remain isolated, which precisely matches the reported symptoms.

Why this answer

Since the FortiGate can ping 8.8.8.8, its default route and internet connectivity are working. The issue is that internal hosts cannot reach the internet, which points to a Layer 3 forwarding problem at the host level. The most likely cause is that the internal hosts have the wrong default gateway configured, so their traffic is not being sent to the FortiGate for routing.

Exam trap

The trap here is that candidates assume a successful ping from the FortiGate implies end-to-end connectivity, overlooking that the internal hosts' default gateway configuration is independent of the FortiGate's own routing table.

How to eliminate wrong answers

Option A is wrong because if the default route on the FortiGate were missing, the FortiGate itself would not be able to ping 8.8.8.8, but the ping succeeded. Option C is wrong because DNS resolution failure would prevent name resolution, but the question describes a connectivity issue where traffic to the internet is failing, and the ping to 8.8.8.8 uses an IP address, not a hostname, so DNS is not the bottleneck. Option D is wrong because if the FortiGate's interface to the internal network were down, the FortiGate would not be able to communicate with internal hosts at all, but the firewall policy allows the traffic and the FortiGate can still ping external IPs, indicating the internal interface is operational.

41
MCQeasy

Which of the following statements about FortiGate backup is true?

A.The backup includes all current sessions and logs
B.The backup file contains the full configuration and can be encrypted with a password
C.A backup can be restored only on the same hardware model
D.Backup files are saved in plain text format
AnswerB

The FortiGate backup file is a single archive that contains the complete device configuration, including all firewall policies, address objects, VPN settings, and system parameters. During the backup process, you have the option to encrypt the file with a password, which is then required to restore it. This encryption ensures that even if the backup file is intercepted, the configuration data remains confidential and cannot be read without the password.

Why this answer

FortiGate backup files contain the full device configuration, including all settings and policies, and can be encrypted with a password using the 'execute backup config' command with the 'password' option. This ensures confidentiality during storage or transfer, as the backup is stored in a binary format that requires the password for decryption during restoration.

Exam trap

The trap here is that candidates often assume backups include all runtime data like sessions and logs, or that backups are model-specific, but FortiGate explicitly separates configuration from volatile state data, and restoration is firmware-version dependent, not hardware-model dependent.

How to eliminate wrong answers

Option A is wrong because FortiGate backups do not include current sessions or logs; sessions are volatile and stored in memory, while logs are typically stored separately on local disk or external storage, and only the configuration is backed up. Option C is wrong because a backup can be restored on any FortiGate model that supports the same firmware version, not just the same hardware model, though some model-specific features may require manual adjustment. Option D is wrong because backup files are saved in a binary, encrypted format (not plain text) when a password is set, and even without a password, the file is not plain text but a proprietary format that cannot be easily read.

42
MCQmedium

An administrator needs to configure a loopback interface on a FortiGate for management purposes. Which of the following is true regarding loopback interfaces?

A.Loopback interfaces are virtual and can be used as source IP for management traffic.
B.Loopback interfaces require a physical port to be associated.
C.Loopback interfaces cannot be used in firewall policies.
D.Loopback interfaces are only available in transparent mode.
AnswerA

Loopback interfaces in FortiGate are virtual, software-only interfaces that are always up and not tied to any physical port. They can be assigned an IP address and configured as the source IP for management traffic, such as syslog, SNMP, NTP, or administrative HTTPS/SSH sessions. Because they are independent of physical link states, they provide a stable management address even when a physical interface fails.

Why this answer

Loopback interfaces are virtual interfaces that are always up and do not depend on the physical link state. They can be assigned an IP address and used as the source IP for management traffic (e.g., SNMP, syslog, NTP, or administrative access), ensuring consistent reachability even if physical interfaces fail. This makes option A correct.

Exam trap

The trap here is that candidates often assume loopback interfaces are only for routing protocols or require a physical link, but FortiGate allows them to serve as stable management endpoints independent of physical interface status.

How to eliminate wrong answers

Option B is wrong because loopback interfaces are purely virtual and do not require any physical port association; they exist independently of hardware interfaces. Option C is wrong because loopback interfaces can be used in firewall policies just like any other interface, allowing traffic to be inspected or routed to/from the FortiGate itself. Option D is wrong because loopback interfaces are available in both NAT/Route mode and transparent mode, not exclusively in transparent mode.

43
MCQmedium

A FortiGate administrator configures SNMPv2c on the FortiGate to send traps to a monitoring server. However, no traps are received. The monitoring server can ping the FortiGate. What is the MOST likely cause?

A.SNMPv2c is not supported on FortiGate; only v3 is supported.
B.The FortiGate's firewall policy blocks SNMP traffic from the monitoring server.
C.The SNMP community string does not match between FortiGate and server.
D.The monitoring server's IP is not in the SNMP trap receiver list on FortiGate.
AnswerC

In SNMPv2c, the community string operates as a shared secret in each PDU, and the trap receiver uses it to validate the message. If the community string configured for trap sending on FortiGate does not match what the monitoring server expects, the server will silently discard the trap without any response, since SNMP uses UDP. The FortiGate will continue to show the trap as sent, so the administrator sees a successful configuration but no trap arrives at the monitoring station. This mismatch is the most common reason for traps not appearing when network connectivity and receiver IP are correct.

Why this answer

SNMPv2c uses community strings as a form of authentication. If the community string configured on the FortiGate does not match the one configured on the monitoring server, the server will reject the trap. Since the server can ping the FortiGate, network connectivity is fine, and the issue is most likely an authentication mismatch.

Exam trap

The trap here is that candidates assume SNMP traps are blocked by a firewall policy, but since traps are initiated by the FortiGate (outbound), the server's ability to ping the FortiGate confirms Layer 3 reachability, shifting the focus to authentication or receiver configuration.

How to eliminate wrong answers

Option A is wrong because FortiGate fully supports SNMPv2c, not just v3. Option B is wrong because SNMP traps are sent from the FortiGate to the server, not initiated by the server, so a firewall policy blocking inbound SNMP from the server would not prevent outbound traps. Option D is wrong because the trap receiver list specifies where traps are sent, not which IPs are allowed to receive them; if the server's IP were missing from the list, the FortiGate would not send traps to it, but the question states the administrator configured traps to be sent to the server, so this is less likely than a community string mismatch.

44
MCQmedium

An administrator wants to back up the FortiGate configuration to a TFTP server at 10.10.10.10. Which CLI command should be used?

A.execute backup config tftp 10.10.10.10
B.backup config tftp 10.10.10.10
C.copy config tftp 10.10.10.10
D.execute save config tftp 10.10.10.10
AnswerA

The correct FortiOS command begins with the 'execute' keyword, which is required for privileged system-level operations. 'execute backup config' triggers a configuration export, and the protocol 'tftp' followed by the server IP (10.10.10.10) instructs the FortiGate to send the config file via TFTP to that host. This is the exact syntax documented by Fortinet for backing up the configuration to a TFTP server, and it will generate a file typically named after the device hostname and date.

Why this answer

The correct command to back up a FortiGate configuration to a TFTP server is 'execute backup config tftp <server-ip>'. This is because 'execute' is the FortiOS CLI keyword for initiating operational commands, and 'backup config tftp' specifies the action and protocol. The syntax is case-sensitive and must include the 'execute' prefix to be recognized by the FortiGate CLI.

Exam trap

The trap here is that candidates may forget the 'execute' keyword, which is mandatory for all operational commands in FortiOS, and mistakenly choose a command that looks correct but lacks it, such as 'backup config tftp'.

How to eliminate wrong answers

Option B is wrong because it omits the required 'execute' keyword; FortiOS CLI commands for operational tasks like backup must start with 'execute'. Option C is wrong because 'copy config tftp' is not a valid FortiOS command; the correct verb is 'backup', not 'copy'. Option D is wrong because 'execute save config tftp' uses 'save' instead of 'backup', and 'save config' is used for saving the running configuration to flash memory, not for exporting to a TFTP server.

45
MCQhard

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A.The session is in an error state
B.The session has been idle for 3600 seconds
C.The session is to port 3600
D.The session is about to expire in 3599 seconds
AnswerD

The expire field in FortiOS session output indicates the remaining time in seconds before the session entry is removed (i.e., its time-to-live). An expire value of 3599 seconds means the session still has approximately one hour of life left, not that it is expiring immediately. This value decreases as the session ages and is reset by traffic matching the session, so it reflects how much longer the session will be tracked if no further packets arrive.

Why this answer

The 'expire=3599' field indicates the session will be removed from the session table in 3599 seconds. The 'duration=3600' shows the session has been active for 3600 seconds, so the total session lifetime is 7200 seconds (3600 + 3599). This is a normal TCP session (proto=6) in state 01 (SYN_SENT), not an error or idle condition.

Exam trap

The trap here is confusing 'duration' (time since session started) with 'expire' (time until session ends), leading candidates to incorrectly interpret the 3600 value as idle time or a port number.

How to eliminate wrong answers

Option A is wrong because 'proto_state=01' indicates a normal TCP SYN_SENT state, not an error state; error states would show different values like 11 (TIME_WAIT) or 0 (CLOSE). Option B is wrong because 'duration=3600' shows the session has been active for 3600 seconds, not idle; idle time is tracked separately via 'idle' field, which is not present here. Option C is wrong because 'dport=443' is the destination port, and 'duration=3600' is the session age in seconds, not a port number.

46
Multi-Selectmedium

An administrator is setting up SNMP monitoring on a FortiGate. Which two configurations are necessary for a basic SNMP setup? (Choose two.)

Select 2 answers
A.Create a firewall policy to allow SNMP traffic from the monitoring server
B.Configure an SNMP community with read-only access
C.Enable the SNMP agent under System > SNMP
D.Set the SNMP trap destination IP
E.Configure a user for SNMPv3
AnswersB, C

An SNMP community serves as the authentication credential for SNMPv1/v2c queries. Without a correctly configured community string, the FortiGate will silently discard SNMP requests, even if the agent is enabled and interfaces are available. Defining a community with read-only (RO) access allows the monitoring server to poll system statistics, interface counters, and other OIDs while preventing unauthorized configuration changes, which is the standard requirement for read-only monitoring scenarios.

Why this answer

An SNMP community with read-only access defines the basic authentication and access control for SNMPv1/v2c queries, which is essential for monitoring. Option C is correct because the SNMP agent must be enabled on the FortiGate to process SNMP requests from the monitoring server.

Exam trap

The trap here is that candidates often confuse optional features like trap destinations or SNMPv3 authentication as mandatory for basic monitoring, when only the agent enablement and a community string are required.

47
MCQhard

An administrator plans to upgrade FortiGate firmware from version 6.0 to 7.2. The current version is 6.0.10. Which upgrade path is correct?

A.Upgrade to 6.4 first, then to 7.2
B.It is not possible to upgrade from 6.0 to 7.2
C.Direct upgrade from 6.0.10 to 7.2.0 is supported
D.Upgrade to 6.2, then 6.4, then 7.0, then 7.2
AnswerD

This sequence—6.0 → 6.2 → 6.4 → 7.0 → 7.2—is exactly the path generated by Fortinet's Upgrade Path tool for FortiOS 6.0 to 7.2. Each intermediate release handles the necessary database migrations and feature changes that cannot be applied in a single jump, ensuring the firewall's configuration, session state, and security policies are preserved. Following this ordered progression avoids the risk of 'upgrade failed' errors and provides the only officially supported route to 7.2.

Why this answer

FortiGate firmware upgrades must follow a supported path that does not skip major versions. Upgrading from 6.0.10 to 7.2.0 requires stepping through 6.2, 6.4, and 7.0 because Fortinet only supports upgrades from one major version to the next major version (e.g., 6.0→6.2→6.4→7.0→7.2). Option D correctly lists this sequential path.

Exam trap

The trap here is that candidates assume a direct upgrade is possible because both versions are relatively recent, but Fortinet strictly enforces sequential major version upgrades to prevent configuration and system incompatibilities.

How to eliminate wrong answers

Option A is wrong because upgrading directly from 6.0 to 6.4 skips version 6.2, which is not supported by Fortinet's upgrade path requirements. Option B is wrong because upgrading from 6.0 to 7.2 is possible, but only by following the correct multi-step path through intermediate versions. Option C is wrong because a direct upgrade from 6.0.10 to 7.2.0 is not supported; Fortinet requires upgrading through each major version in sequence.

48
MCQmedium

A FortiGate is configured with an aggregate interface (link aggregation group) consisting of two physical ports. The administrator notices that traffic is not being distributed evenly across the two links. Which configuration setting should be verified to improve load balancing?

A.Check the LACP mode (active vs passive)
B.Increase the MTU on the aggregate interface
C.Verify the load-balancing algorithm for the aggregate interface
D.Ensure the physical ports are in the same VDOM
AnswerC

Aggregate interface traffic distribution is governed by the configured load-balancing algorithm, such as L4 or L3/L4 hashing. Uneven distribution across member links usually means the algorithm's hash inputs, not the physical links, are the constraint.

Why this answer

The aggregate interface uses a load-balancing algorithm to distribute traffic across member links. If traffic is uneven, the algorithm (e.g., source-destination IP, source-destination MAC, or layer 4 port) may not match the traffic pattern, causing hash polarization. Verifying and adjusting this algorithm is the correct step to improve distribution.

Exam trap

The trap here is confusing LACP negotiation settings (active/passive) with the actual traffic distribution mechanism, leading candidates to incorrectly select option A instead of recognizing that the load-balancing algorithm directly controls link utilization.

How to eliminate wrong answers

Option A is wrong because LACP mode (active vs passive) controls link negotiation and aggregation establishment, not traffic distribution across already-aggregated links. Option B is wrong because increasing MTU affects maximum packet size but has no impact on how traffic is hashed or distributed among aggregate members. Option D is wrong because VDOM membership ensures logical separation but does not influence the load-balancing algorithm or per-packet distribution across physical ports in an aggregate.

49
MCQmedium

An administrator needs to ensure that all traffic from the internal network to the internet goes through a web proxy for content filtering. Which configuration is required on the FortiGate?

A.Enable the proxy feature and set the web proxy port to 80.
B.Enable web proxy in the firewall policy and set action to accept.
C.Configure an explicit web proxy and create a proxy policy.
D.Configure a transparent proxy by using an SSL inspection profile.
AnswerC

An explicit web proxy requires two things: the proxy feature must be enabled and configured on a listening port, and proxy policies must be created to define which users and destinations are allowed, denied, or filtered. This is the correct way to handle 'all traffic' from clients that are configured to use the FortiGate as their proxy. Without a proxy policy, the proxy will accept connections but only return a default or error behavior.

Why this answer

To enforce web proxy-based content filtering for all internal-to-internet traffic, the FortiGate must be configured with an explicit web proxy (which listens on a specific IP and port, typically 8080) and a corresponding proxy policy that defines the traffic matching criteria and action. This setup ensures that client browsers are configured to send requests to the proxy, and the proxy policy applies content filtering rules.

Exam trap

The trap here is that candidates often confuse enabling the web proxy feature in a firewall policy (transparent proxy) with the explicit proxy configuration that requires a separate proxy policy, leading them to select option B.

How to eliminate wrong answers

Option A is wrong because simply enabling the proxy feature and setting the web proxy port to 80 does not create a functional proxy policy; without a proxy policy, no traffic is actually processed through the proxy for content filtering. Option B is wrong because enabling web proxy in a firewall policy with action set to accept does not redirect traffic through the proxy; it only allows the traffic to pass without proxy inspection. Option D is wrong because a transparent proxy uses an SSL inspection profile to intercept traffic transparently, but it does not require an explicit proxy configuration or a proxy policy; instead, it relies on firewall policies with web proxy enabled, which is not the same as the explicit proxy approach needed for the described requirement.

50
MCQeasy

An administrator needs to back up the full configuration of a FortiGate, including all system settings, policies, and objects. Which CLI command should be used?

A.diagnose debug config-error-log read
B.execute backup config tftp <filename> <server>
C.show full-configuration
D.execute restore config tftp <filename> <server>
AnswerB

The execute backup config tftp command saves the complete current configuration to a TFTP server as a plain-text file, which can later be used for restoration. It requires the TFTP server IP address and a filename, and the FortiGate will transfer the full configuration to that location. This is the standard CLI method for a full configuration backup and is the correct command to use in this scenario.

Why this answer

The correct command is 'execute backup config tftp <filename> <server>' because it explicitly triggers a full configuration backup (including system settings, policies, and objects) to a TFTP server. This is the standard FortiGate CLI command for exporting the entire running configuration to an external TFTP server, ensuring all configuration elements are captured.

Exam trap

The trap here is confusing the 'backup' and 'restore' commands (options B and D) or mistaking a display-only command like 'show full-configuration' for an actual backup operation.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug config-error-log read' is a diagnostic command used to view configuration error logs, not to perform a backup. Option C is wrong because 'show full-configuration' displays the entire configuration on the console but does not save or transfer it to a backup file or server. Option D is wrong because 'execute restore config tftp <filename> <server>' is used to restore a configuration from a TFTP server, not to back it up.

51
MCQmedium

A FortiGate administrator needs to allow remote management from the internet only from a specific IP address. Which configuration achieves this?

A.Create a local-in policy to allow management access only from the trusted host
B.Change the admin port to a non-standard port
C.Enable HTTPS and restrict admin access via admin host
D.Use a firewall policy with source address restriction
AnswerA

A local-in policy is evaluated before any firewall policy and explicitly governs traffic destined to the FortiGate's own IP addresses. By defining a local-in rule that permits management traffic only from the specified trusted host IP, the administrator ensures all other sources are implicitly denied, providing precise source-based access control for the management interface.

Why this answer

A local-in policy is the correct method to restrict remote management access to a FortiGate from the internet because it operates at the control plane level, filtering traffic destined to the FortiGate itself before it reaches the management daemons. By specifying a source IP address in a local-in policy, you can explicitly allow HTTPS or SSH management only from that trusted host, while implicitly denying all other sources. This is more secure than relying on firewall policies, which apply to traffic passing through the FortiGate, not to traffic destined to the FortiGate's own IP addresses.

Exam trap

The trap here is that candidates often confuse firewall policies (which control traffic passing through the FortiGate) with local-in policies (which control traffic destined to the FortiGate), leading them to incorrectly select option D, thinking a standard firewall policy can restrict management access from the internet.

How to eliminate wrong answers

Option B is wrong because changing the admin port to a non-standard port is a form of security through obscurity and does not restrict access to a specific IP address; it only changes the port number, which can still be scanned and accessed from any source. Option C is wrong because enabling HTTPS and restricting admin access via admin host (the 'admin host' setting) is a legacy method that only works for GUI access and does not apply to SSH or other management protocols; it also does not provide the granularity of a local-in policy. Option D is wrong because a firewall policy with source address restriction applies to traffic transiting through the FortiGate (forwarding plane), not to traffic destined to the FortiGate itself (control plane); management traffic is handled by the control plane and must be filtered using local-in policies or the 'trusted host' feature.

52
MCQmedium

An administrator wants to configure SNMPv3 on a FortiGate for secure monitoring. Which configuration is required?

A.Create an SNMPv3 user with authentication and privacy protocols.
B.Enable SNMP agent on the WAN interface only.
C.Configure an access control list for SNMP.
D.Set SNMP community string to 'public' and enable SNMPv1/v2c.
AnswerA

For SNMPv3 on a FortiGate, the administrator must define an SNMPv3 user under the SNMP configuration and assign both an authentication protocol (e.g., SHA or SHA256) and a privacy protocol (e.g., AES or DES) with passphrases. This creates the USM user credentials that provide message authentication and encryption, which is the defining security feature of SNMPv3. Without this user, the FortiGate cannot accept authenticated and encrypted SNMPv3 queries.

Why this answer

SNMPv3 requires a user-based security model (USM) with authentication (e.g., SHA) and privacy (e.g., AES) protocols to provide integrity, authentication, and encryption. Without these, SNMPv3 cannot secure monitoring traffic, making option A the mandatory configuration.

Exam trap

The trap here is that candidates often think enabling SNMP on a specific interface or using ACLs is the primary security requirement, but SNMPv3's security is entirely user-based and requires explicit authentication and privacy protocols.

How to eliminate wrong answers

Option B is wrong because SNMP agent can be enabled on any interface, not only WAN, and the interface selection does not enforce security; SNMPv3 security is user-based, not interface-based. Option C is wrong because while access control lists can restrict SNMP access, they are not required for SNMPv3; the core requirement is the user with authentication and privacy. Option D is wrong because setting the community string to 'public' and enabling SNMPv1/v2c bypasses SNMPv3's security entirely, leaving monitoring unencrypted and unauthenticated.

53
MCQeasy

A FortiGate is configured in NAT/Route mode. Which statement is correct about this mode?

A.Only one interface can be used for traffic.
B.The FortiGate routes traffic between different subnets and can perform NAT.
C.VLAN interfaces are not supported in this mode.
D.The FortiGate acts as a Layer 2 bridge.
AnswerB

This is the correct description of NAT/Route mode, which is the default operating mode of a FortiGate. In this mode, the FortiGate acts as a Layer 3 router and makes forwarding decisions based on IP addresses and routing tables, sending packets from one subnet to another. It can also apply NAT, including source NAT for outbound Internet access and destination NAT for inbound services, as part of its firewall policies.

Why this answer

In NAT/Route mode, the FortiGate operates as a Layer 3 router, forwarding traffic between different subnets while also performing Network Address Translation (NAT) when configured. This is the default operational mode for most FortiGate deployments, enabling both routing and NAT capabilities on the same device.

Exam trap

The trap here is that candidates often confuse NAT/Route mode with Transparent mode, assuming that NAT implies bridging or that only one interface can be used, but FortiGate explicitly supports multiple routed interfaces and VLANs in this mode.

How to eliminate wrong answers

Option A is wrong because NAT/Route mode supports multiple interfaces for traffic forwarding, not just one; each interface can belong to a different subnet. Option C is wrong because VLAN interfaces are fully supported in NAT/Route mode, allowing segmentation of traffic on the same physical port. Option D is wrong because the FortiGate acts as a Layer 3 router in this mode, not a Layer 2 bridge; Layer 2 bridging is associated with Transparent mode.

54
MCQmedium

A FortiGate administrator needs to configure a policy route to send all traffic destined to 10.10.10.0/24 out through interface port3 instead of the default route. Which configuration steps are necessary?

A.Add a firewall policy with source interface any, destination 10.10.10.0/24, and set the egress interface to port3
B.Create a static route for 10.10.10.0/24 with a lower distance pointing to port3
C.Set the default gateway to port3 and remove the existing default route
D.Configure a policy route under 'config router policy' with destination 10.10.10.0/24 and output interface port3
AnswerD

The correct way to route traffic to 10.10.10.0/24 through port3 based on a policy is to configure a policy route in the 'config router policy' section. In FortiOS, policy routes are evaluated before the routing table and can match on source and destination addresses, protocols, and incoming interfaces, then set an explicit output interface. This gives the administrator precise control over traffic engineering without altering the normal routing table or affecting other traffic. Thus, 'config router policy' with destination 10.10.10.0/24 and output interface port3 is the correct implementation.

Why this answer

Policy routes override the routing table for specific traffic based on criteria like source, destination, or protocol. Option D correctly configures a policy route under 'config router policy' to match destination 10.10.10.0/24 and set the output interface to port3, ensuring that traffic is forwarded out port3 regardless of the default route.

Exam trap

The trap here is confusing firewall policies (which control access and NAT) with policy routes (which control forwarding decisions), leading candidates to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because firewall policies control access and NAT, not routing; they cannot override the routing table to force traffic out a specific interface. Option B is wrong because a static route for 10.10.10.0/24 with a lower distance would still be subject to the routing table's longest-match rule and could be overridden by a more specific route or dynamic routing, whereas a policy route takes precedence over the routing table. Option C is wrong because changing the default gateway to port3 would affect all traffic, not just traffic to 10.10.10.0/24, and removing the existing default route would break connectivity for other destinations.

55
MCQeasy

An administrator needs to back up the FortiGate configuration to a remote server using SCP. Which command is correct?

A.execute backup config copy <server> <filename>
B.execute backup config scp <server> <filename>
C.execute backup config tftp <server> <filename>
D.execute backup config ftp <server> <filename>
AnswerB

The command 'execute backup config scp <server> <filename>' is the correct, secure method to back up a FortiGate configuration. SCP (Secure Copy Protocol) runs over SSH, encrypting the entire transfer session, which protects the configuration file and any server credentials from interception. Because the configuration contains sensitive data such as VPN preshared keys, passwords, and certificates, using SCP is strongly recommended, especially when backing up over an untrusted network. The <server> parameter can include a username in user@host format for SSH authentication.

Why this answer

The correct command is 'execute backup config scp <server> <filename>' because SCP (Secure Copy Protocol) is the only option listed that provides encrypted file transfer over SSH, which is required for securely backing up the FortiGate configuration to a remote server. FortiGate uses this CLI command to initiate an SCP session to the specified server and save the configuration file with the given filename.

Exam trap

The trap here is that candidates often confuse 'scp' with 'ftp' or 'tftp' because they all transfer files, but only SCP provides encryption, which is the key requirement for a secure remote backup.

How to eliminate wrong answers

Option A is wrong because 'execute backup config copy' is not a valid FortiGate command; the syntax uses 'copy' incorrectly, and there is no such subcommand for backup operations. Option C is wrong because 'execute backup config tftp' uses TFTP (Trivial File Transfer Protocol), which is unencrypted and lacks authentication, making it unsuitable for secure backups to a remote server. Option D is wrong because 'execute backup config ftp' uses FTP (File Transfer Protocol), which transmits data in cleartext including credentials, and is not the secure method specified in the question (SCP).

56
MCQeasy

What is the purpose of configuring a loopback interface on a FortiGate?

A.To create a logical interface that remains up regardless of physical link status
B.To provide a virtual IP address for NAT
C.To connect to a VLAN
D.To aggregate multiple physical interfaces for increased bandwidth
AnswerA

A loopback interface is a virtual interface that is always administratively up once created, independent of any physical link state. This guarantees a stable IP address for management access, routing protocol peering (e.g., OSPF, BGP), and device identification, even if all physical interfaces fail. Only a manual shutdown or system-wide outage can bring it down.

Why this answer

A loopback interface is a logical interface that is not tied to any physical port, so it remains operational (up/up) as long as the FortiGate itself is running. This makes it ideal for management access, BGP peering, and other services that require a stable IP address independent of physical link failures.

Exam trap

The trap here is that candidates confuse a loopback interface with a virtual IP (VIP) for NAT or with a VLAN sub-interface, because both are 'virtual' constructs, but they serve entirely different purposes in the FortiGate architecture.

How to eliminate wrong answers

Option B is wrong because a loopback interface is not used for NAT; virtual IPs (VIPs) or IP pools are used for NAT purposes. Option C is wrong because VLANs are created as sub-interfaces on physical or aggregate interfaces, not on a loopback interface. Option D is wrong because aggregating multiple physical interfaces for increased bandwidth is achieved via Link Aggregation (LAG) or 802.3ad, not a loopback interface.

57
MCQhard

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is an ICMP session with state 01 and expires in 1 second.
B.The session is a UDP session to port 443 and has been active for 3600 seconds.
C.The session is a TCP session to port 443 that has been active for 3600 seconds and will expire in 3599 seconds.
D.The session is a TCP session that has timed out and will be removed in 3599 seconds.
AnswerC

Protocol 6 is TCP, and the filter dport=443 confirms destination port 443. The duration field shows 3600 seconds elapsed, while expire=3599 indicates the session will time out in 3599 seconds, matching the stated interpretation precisely.

Why this answer

The output shows 'proto=6', which is the protocol number for TCP, and 'dport=443' indicates the destination port is HTTPS. The 'duration=3600' means the session has been active for 3600 seconds, and 'expire=3599' means it will expire in 3599 seconds. The 'proto_state=01' is a TCP state code, confirming this is a TCP session.

Exam trap

The trap here is that candidates often confuse protocol numbers (e.g., thinking '6' is UDP or ICMP) or misinterpret 'expire' as the time since expiration rather than the remaining time until expiration.

How to eliminate wrong answers

Option A is wrong because 'proto=6' is TCP, not ICMP (which uses protocol number 1), and 'dport=443' specifies a port, which is not applicable to ICMP. Option B is wrong because 'proto=6' is TCP, not UDP (which uses protocol number 17), and the session is to port 443, not from it. Option D is wrong because the session has not timed out; 'expire=3599' indicates it is still active and will expire in 3599 seconds, not that it has already timed out.

58
MCQeasy

What is the purpose of configuring an NTP server on a FortiGate?

A.To enable time-based firewall policies.
B.To synchronize the FortiGate's system clock with a reliable time source.
C.To allow the FortiGate to act as an NTP server for the network.
D.To authenticate with FortiGuard services.
AnswerB

This is the correct purpose. Configuring an NTP server on a FortiGate makes the firewall synchronize its internal hardware clock with an authoritative time source, ensuring accurate timestamps for logs, VPN certificates, and protocol operations that depend on consistent time. Without reliable synchronization, the system clock can drift, leading to issues such as expired certificates or misleading security logs. NTP is specifically designed to maintain that accuracy automatically and continuously.

Why this answer

Configuring an NTP server on a FortiGate synchronizes the system clock with a reliable time source, which is essential for accurate logging, certificate validation, and time-based operations. While time-based firewall policies depend on an accurate clock, NTP itself is the mechanism to achieve that accuracy, not the policy feature itself.

Exam trap

The trap here is that candidates confuse the purpose of NTP (time synchronization) with the features that depend on accurate time, such as time-based policies or FortiGuard authentication, leading them to select those as the primary purpose.

How to eliminate wrong answers

Option A is wrong because time-based firewall policies are a feature that uses the system clock, but the purpose of NTP configuration is to synchronize that clock, not to directly enable the policies. Option C is wrong because while a FortiGate can be configured as an NTP server for the network, that is an optional role, not the primary purpose of configuring an NTP server on the device. Option D is wrong because FortiGuard services use the system clock for authentication and license validation, but NTP configuration is not a direct authentication method; it merely ensures the clock is accurate for those services.

59
MCQmedium

An administrator needs to upgrade the firmware on a FortiGate from version 6.4.10 to 7.0.1. The device currently runs FortiOS 6.4.10. Which upgrade path should be followed?

A.Downgrade to 6.2.0 then upgrade to 7.0.1
B.Upgrade to 7.0.0 first, then to 7.0.1
C.Upgrade directly from 6.4.10 to 7.0.1 via the GUI
D.Upgrade to 6.4.99 (if exists) then to 7.0.1
AnswerB

FortiGate requires that you first upgrade to the initial release of the target major branch, in this case 7.0.0, before applying the latest patch 7.0.1. The 6.4.x branch and the 7.0.x branch use different configuration database schemas, and 7.0.0 is the only version that performs the required schema migration. Without this intermediate step, the upgrade to 7.0.1 would be rejected by the firmware validation process.

Why this answer

Fortinet requires a sequential upgrade path for major version jumps. FortiOS 6.4.10 can upgrade directly to 7.0.0, and then to 7.0.1, because 7.0.0 is the first release in the 7.0 branch. Upgrading directly from 6.4.10 to 7.0.1 is not supported as it skips the required intermediate version.

Exam trap

The trap here is that candidates assume GUI or direct upgrades are always safe, but Fortinet strictly enforces sequential version upgrades to prevent configuration and system incompatibilities.

How to eliminate wrong answers

Option A is wrong because downgrading to 6.2.0 is unnecessary and not a valid upgrade path; Fortinet does not support downgrading as a step to upgrade. Option C is wrong because upgrading directly from 6.4.10 to 7.0.1 via the GUI is not supported; the upgrade must go through 7.0.0 first. Option D is wrong because 6.4.99 does not exist as a release; Fortinet uses specific build numbers, not arbitrary patch versions, and the correct intermediate is 7.0.0.

60
MCQmedium

An administrator wants to send FortiGate logs to a FortiAnalyzer for centralized logging and reporting. Which configuration step is required on the FortiGate?

A.Enable SNMP traps to the FortiAnalyzer
B.Create a firewall policy to allow traffic to the FortiAnalyzer
C.Under Log & Report, configure the FortiAnalyzer settings and set the log forwarding
D.Configure a syslog server under System > Settings
AnswerC

This is the correct action because FortiGate has dedicated integration settings for FortiAnalyzer under the Log & Report menu (often System > Log & Report > FortiAnalyzer). Here, you enter the FortiAnalyzer IP/FQDN and serial number, and then enable log sending/archiving for specific log types (e.g., traffic, event). Once configured, FortiGate uses the FGFM (FortiGate-to-FortiAnalyzer) protocol to securely and reliably forward logs, including buffering and retransmission. This is the intended mechanism for centralized logging on FortiAnalyzer, so this option precisely addresses the administrator's goal.

Why this answer

FortiGate uses the Log & Report section to configure FortiAnalyzer settings, specifically under 'Log Settings' or 'Log Forwarding'. This enables the FortiGate to forward logs to a FortiAnalyzer device for centralized logging and reporting, using the FortiGate-FortiAnalyzer protocol (based on syslog over TCP with Fortinet extensions).

Exam trap

The trap here is that candidates often confuse the generic syslog server configuration (Option D) with the FortiAnalyzer-specific log forwarding setup, or they mistakenly think a firewall policy (Option B) is the primary step rather than the log forwarding configuration itself.

How to eliminate wrong answers

Option A is wrong because SNMP traps are used for sending network management alerts (e.g., interface down) to an SNMP manager, not for forwarding logs to FortiAnalyzer. Option B is wrong because while a firewall policy may be needed to allow outbound traffic to the FortiAnalyzer IP, it is not the primary configuration step for log forwarding; the log forwarding settings themselves are configured under Log & Report. Option D is wrong because configuring a syslog server under System > Settings is for sending logs to a generic syslog server, not for the FortiAnalyzer-specific integration which requires the dedicated FortiAnalyzer configuration under Log & Report.

61
Multi-Selectmedium

A network administrator is configuring SNMP on a FortiGate for monitoring. Which three pieces of information are required to complete the SNMPv2c configuration? (Choose THREE.)

Select 3 answers
A.SNMPv3 authentication protocol (MD5/SHA)
B.SNMP manager IP address (allowed hosts)
C.SNMP trap receiver IP and community
D.SNMP community string
E.SNMP interface (the interface that will respond to SNMP queries)
AnswersB, D, E

The SNMP manager IP address (allowed hosts) is a mandatory access-control parameter in FortiGate's SNMP configuration. Without it, the SNMP agent will not accept queries from any network management station, effectively disabling polling. Specifying the NMS IP restricts SNMP access to authorized management systems, ensuring that only the intended server can read the device's MIB data.

Why this answer

SNMPv2c uses community-based security, so the SNMP community string (Option D) is required for authentication. The SNMP manager IP address (Option B) is needed to define which hosts are allowed to query the FortiGate. The SNMP interface (Option E) specifies which network interface will listen for and respond to SNMP queries.

These three pieces are mandatory for SNMPv2c configuration on a FortiGate.

Exam trap

The trap here is that candidates often confuse SNMPv2c requirements with SNMPv3 requirements, selecting authentication protocols (Option A) which are irrelevant for v2c, or they assume trap configuration is mandatory for basic monitoring, when it is actually optional.

62
MCQmedium

An administrator wants to upgrade the FortiGate firmware from version 6.4.9 to 7.0.1. What is the most important consideration before proceeding?

A.Verify the upgrade path and check for any required intermediate versions
B.Upgrade to the latest 7.0.x directly without intermediate steps
C.Disable all firewall policies before upgrading
D.Ensure the configuration is backed up
AnswerA

Fortinet only guarantees a clean upgrade when you follow the documented firmware upgrade path from your current version to the target release. Intermediate versions are often mandatory because each major release can change the configuration schema, firewall object syntax, and internal database structure; skipping them can cause the upgrade to abort or produce corrupt settings. The correct first step is always to consult the FortiOS Upgrade Path tool and the release notes to identify any required stepping stones before attempting the move.

Why this answer

FortiGate firmware upgrades must follow a validated upgrade path to avoid configuration incompatibilities or boot failures. Version 6.4.9 to 7.0.1 requires an intermediate upgrade to 7.0.0 first, as direct jumps across major versions or skipping required intermediate releases can corrupt the firmware image or render the device unbootable. Fortinet publishes explicit upgrade paths in the release notes, and ignoring them is the most common cause of failed upgrades.

Exam trap

The trap here is that candidates assume a configuration backup is the most critical step, but Fortinet specifically tests that verifying the upgrade path is the primary consideration to prevent a non-bootable device.

How to eliminate wrong answers

Option B is wrong because upgrading directly to the latest 7.0.x without intermediate steps violates Fortinet's required upgrade path; 6.4.9 must first go to 7.0.0 before reaching 7.0.1. Option C is wrong because disabling firewall policies is not a prerequisite for firmware upgrades; the upgrade process preserves the configuration, and policies remain intact. Option D is wrong because while backing up the configuration is a best practice, it is not the most important consideration; the upgrade path is critical to avoid a bricked device, whereas a backup only protects against data loss after a failure.

63
Multi-Selecthard

An admin wants to ensure that traffic between two internal subnets (10.0.1.0/24 and 10.0.2.0/24) is inspected by the FortiGate but does not have its source IP translated. Which THREE configuration elements are required? (Choose three.)

Select 3 answers
A.NAT disabled on that policy
B.A static route for each subnet on the FortiGate
C.An IP pool for source NAT
D.A firewall policy allowing traffic between the two subnets
E.Security profiles (e.g., antivirus, IPS) applied to the policy
AnswersA, D, E

To preserve the original source IP of internal hosts when routing between subnets, the firewall policy must have NAT explicitly disabled. With NAT enabled, FortiGate would translate the source address to its own egress interface IP, which breaks end-to-end visibility, compromises logging, and can break return routing when the destination subnet has specifically crafted routes back to the real host address.

Why this answer

When traffic between two internal subnets does not require source IP translation, NAT must be explicitly disabled on the firewall policy. By default, FortiGate policies may have NAT enabled (especially on outbound interfaces), so disabling NAT ensures the original source IP (10.0.1.x) is preserved when communicating with 10.0.2.x. This is configured by setting the 'set nat enable' option to 'disable' in the policy or unchecking NAT in the GUI.

Exam trap

The trap here is that candidates often assume static routes are always needed for inter-subnet routing, but FortiGate automatically creates connected routes for directly attached subnets, making static routes unnecessary in this scenario.

64
MCQmedium

A FortiGate administrator notices that the device's disk usage is critically high, causing logging failures. The administrator wants to free up space without losing important logs. Which action should be taken first?

A.Delete all existing log files
B.Configure log compression
C.Disable logging to the local disk
D.Increase the disk retention period
AnswerB

Configuring log compression on a FortiGate (typically using gzip) reduces the on-disk footprint of stored logs without removing any data, preserving full log fidelity for later analysis. This non-destructive approach directly addresses disk-full pressure by shrinking existing and future log files, and it can be combined with retention policies to keep more history within the same space.

Why this answer

Log compression reduces the size of existing log files on the disk without deleting any data, directly addressing the critically high disk usage while preserving all important logs. This is the safest first step because it reclaims space immediately without risking data loss or altering logging behavior.

Exam trap

The trap here is that candidates may confuse 'increasing retention period' (which makes the problem worse) with 'decreasing retention period' (which would free space but delete logs), or they may think disabling logging is a quick fix without realizing it stops all logging activity.

How to eliminate wrong answers

Option A is wrong because deleting all existing log files would permanently remove important logs, which contradicts the requirement to not lose them. Option C is wrong because disabling logging to the local disk would stop all future logging to the device, potentially losing critical security events, and does not free up space already used. Option D is wrong because increasing the disk retention period would actually cause logs to be kept longer, worsening the disk usage problem rather than solving it.

65
MCQhard

An administrator configures a FortiGate in transparent mode to be deployed between a router and a switch. After installation, traffic passes through but the administrator cannot access the FortiGate's management IP from the management network. What is the MOST likely reason?

A.The management IP is not in the same subnet as the management network.
B.Transparent mode does not support management access; only NAT/Route mode does.
C.The FortiGate's firewall policy blocks management traffic even in transparent mode.
D.The administrator must configure a management VLAN interface to access the FortiGate.
AnswerA

In transparent mode, the FortiGate operates as a layer 2 bridge and uses a dedicated management IP for administrative access. This management IP must belong to the same subnet as the directly connected management network, because the FortiGate resolves the management destination via ARP and does not route management traffic without a routed interface. If the management IP is in a different subnet, the FortiGate cannot respond to ARP requests or forward management packets, making it unreachable. Therefore, the administrator's incorrect subnet selection prevents any management connection.

Why this answer

In transparent mode, the FortiGate acts as a Layer 2 bridge, and its management IP must belong to the same subnet as the management network to be reachable. If the management IP is on a different subnet, the FortiGate will not respond to management traffic because it does not route between subnets in transparent mode; it only forwards traffic at Layer 2.

Exam trap

The trap here is that candidates often assume transparent mode disables all management access or requires special VLANs, when the real issue is simply a subnet mismatch between the management IP and the management network.

How to eliminate wrong answers

Option B is wrong because transparent mode fully supports management access via a dedicated management IP, just like NAT/Route mode, though the IP is used for management only and not for routing. Option C is wrong because by default in transparent mode, there is no firewall policy blocking management traffic; management access is controlled by administrative access settings (e.g., HTTPS, SSH) on the management interface, not by firewall policies. Option D is wrong because a management VLAN interface is not required; the administrator can assign a management IP directly to the FortiGate's management interface (e.g., the internal interface) as long as it is on the same subnet as the management network.

66
MCQmedium

A FortiGate is configured with two equal-cost static default routes via two ISPs. The administrator wants to use both links simultaneously for outbound traffic, distributing sessions per source-destination pair. Which ECMP load balancing method should be configured under config system settings?

A.weighted-round-robin
B.vip-inbound-grpc
C.spillover
D.source-destination-ip
AnswerD

Configuring source-destination-ip hashes each session's source and destination IP pair, so distinct flows spread across both ISP links while a single flow stays pinned to one route. This satisfies the stem's requirement to use both links simultaneously, distributing sessions per source-destination pair rather than per packet.

Why this answer

The source-destination-ip method under ECMP load balancing distributes sessions based on both source and destination IP addresses, ensuring that all packets belonging to the same session (same source-destination pair) are forwarded via the same path. This meets the requirement of using both links simultaneously for outbound traffic while maintaining per-session consistency.

Exam trap

The trap here is that candidates often confuse ECMP load balancing methods with general load balancing techniques, mistakenly selecting weighted-round-robin because it sounds like a standard load balancing algorithm, but it does not guarantee per-source-destination pair distribution in FortiGate's ECMP context.

How to eliminate wrong answers

Option A (weighted-round-robin) is wrong because it distributes sessions in a round-robin fashion based on weights, not per source-destination pair, which can cause session asymmetry. Option B (vip-inbound-grpc) is wrong because it is not an ECMP load balancing method; it relates to gRPC-based VIP configuration for inbound traffic. Option C (spillover) is wrong because it forwards traffic to a secondary link only when the primary link's bandwidth threshold is exceeded, not for simultaneous use of both links.

67
MCQhard

An admin runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A.The session is a half-open TCP connection
B.The session is a multicast session
C.The session is a UDP session for DNS over HTTPS
D.The session is an established TCP session for HTTPS traffic
AnswerD

The session is an established TCP session because the output field proto=6 specifies TCP (protocol 6), and proto_state=01 corresponds to the TCP established state, meaning the three-way handshake completed successfully. The destination port 443 is the well-known port for HTTPS, so this session represents active HTTPS traffic traversing the FortiGate. When combined, these values unambiguously identify a normal, established TCP connection for HTTPS, ruling out half-open, multicast, or UDP alternatives.

Why this answer

The output shows `proto=6` (TCP), `proto_state=01` (TCP established), `dport=443` (HTTPS), and a duration/expire indicating an active session. This confirms an established TCP session for HTTPS traffic, making D correct.

Exam trap

The trap here is that candidates may misinterpret `proto_state=01` as a half-open connection (like SYN_SENT) because they confuse the numeric state value with TCP flags, when in fact 01 specifically means ESTABLISHED in FortiGate's session table.

How to eliminate wrong answers

Option A is wrong because `proto_state=01` indicates a fully established TCP connection (state ESTABLISHED), not a half-open connection (which would show state like SYN_SENT or 02). Option B is wrong because multicast sessions use UDP (proto=17) or IGMP, not TCP (proto=6), and the output shows a unicast TCP session. Option C is wrong because DNS over HTTPS uses TCP port 443 but is a UDP-based protocol (DNS itself is UDP, though DoH uses TCP); the output explicitly shows `proto=6` (TCP), not UDP (proto=17), and the session state indicates TCP, not UDP.

68
MCQmedium

A FortiGate admin notices that HTTPS traffic to a web server is not being scanned by the antivirus profile applied to the firewall policy. The admin confirms the policy is correct and antivirus is enabled. What is the MOST likely reason the traffic is not being scanned?

A.The web server's certificate is self-signed and FortiGate is rejecting the connection
B.The antivirus profile is configured for flow-based inspection instead of proxy-based
C.SSL/TLS deep inspection is not enabled on the firewall policy
D.The FortiGuard antivirus subscription has expired
AnswerC

Antivirus inspection requires decrypted payloads, so encrypted HTTPS sessions bypass scanning unless the policy performs SSL/TLS deep inspection. Without it, FortiGate forwards ciphertext untouched, meaning no antivirus profile can examine the traffic regardless of correct policy configuration.

Why this answer

HTTPS traffic is encrypted with SSL/TLS, so an antivirus profile cannot inspect the payload unless the firewall can decrypt the traffic. Even with antivirus enabled in the policy, without SSL/TLS deep inspection (also called SSL inspection or HTTPS decryption), FortiGate only sees encrypted packets and cannot scan for malware. Therefore, the most likely reason is that SSL/TLS deep inspection is not enabled on the firewall policy.

Exam trap

The trap here is that candidates often assume antivirus profiles automatically inspect all traffic, forgetting that encrypted HTTPS requires explicit SSL/TLS decryption before any content inspection can occur.

How to eliminate wrong answers

Option A is wrong because a self-signed certificate does not cause FortiGate to reject the connection by default; it may generate a warning or require an SSL inspection policy to handle untrusted certificates, but the traffic would still be forwarded (and remain unscanned) unless a specific action is configured. Option B is wrong because both flow-based and proxy-based inspection modes support antivirus scanning; the inspection mode affects performance and some features but does not prevent scanning of HTTPS traffic if decryption is configured. Option D is wrong because an expired FortiGuard antivirus subscription would prevent signature updates and might disable real-time scanning, but the traffic would still be inspected (with potentially outdated signatures) unless the license is completely expired and the feature is blocked; the question states antivirus is enabled, so the subscription expiry is not the most likely reason for no scanning at all.

69
MCQhard

During a firmware upgrade, the FortiGate reboots and the administrator cannot access the GUI via HTTPS. The CLI shows the system is running the previous firmware. What is the most likely cause?

A.The firmware image was corrupted during upload.
B.The administrator booted from the wrong partition.
C.The administrator did not perform a factory reset before upgrading.
D.The upgrade failed and the system rolled back to the previous firmware.
AnswerD

FortiGate incorporates an automatic rollback mechanism that activates when the newly upgraded firmware fails to boot, fails self-integrity checks, or encounters an incompatible configuration during startup. In such cases, the bootloader automatically falls back to the previously known-good partition and reboots the system using the prior firmware, ensuring availability. The observed reboot followed by a return to the previous version is the textbook signature of this controlled rollback after a failed upgrade attempt.

Why this answer

FortiGate firmware upgrades include an automatic rollback mechanism. If the upgrade fails or the new firmware does not boot successfully, the system automatically reverts to the previous firmware partition during the next reboot. The administrator seeing the previous firmware and being unable to access the GUI indicates the upgrade did not complete successfully, triggering this rollback.

Exam trap

The trap here is that candidates may assume a corrupted image (Option A) is the cause, but FortiGate's automatic rollback mechanism masks the corruption by reverting to the previous firmware, making the symptom appear as if the upgrade never took effect.

How to eliminate wrong answers

Option A is wrong because a corrupted firmware image would typically cause the upgrade process to fail before the reboot, or the system would not boot at all; the rollback mechanism is designed to handle such corruption by reverting to the known good partition. Option B is wrong because FortiGate does not have a manual partition selection during boot; the boot process automatically selects the primary partition, and the rollback mechanism controls which partition is active after a failed upgrade. Option C is wrong because a factory reset is not required before a firmware upgrade; upgrades are performed directly on the running configuration, and a factory reset is only recommended for major version jumps or specific scenarios, not as a prerequisite.

70
MCQeasy

An administrator needs to configure a FortiGate to allow remote management via HTTPS from the internet. Which configuration step is required?

A.Create a firewall policy from WAN to LAN with HTTPS service and set action to ACCEPT.
B.Enable SSH access on the WAN interface instead of HTTPS.
C.Enable HTTPS access on the WAN interface and create a firewall policy allowing inbound HTTPS from any to the FortiGate's IP.
D.Configure a port forwarding rule to redirect HTTPS from WAN to the internal management IP.
AnswerC

HTTPS management requires two things: administrative access enabled on the WAN interface itself, plus an explicit firewall policy permitting inbound TCP 443 to the FortiGate's IP. Without the policy, the implicit deny drops the traffic even when HTTPS access is enabled.

Why this answer

Remote HTTPS management of a FortiGate from the internet requires two steps: enabling HTTPS access on the WAN interface (under config system interface) and creating a firewall policy that allows inbound HTTPS traffic (TCP/443) from any source to the FortiGate's own IP address. Without the explicit policy, the traffic is dropped by the implicit deny rule, even if the interface is configured to listen for HTTPS.

Exam trap

The trap here is that candidates assume enabling HTTPS on the interface alone is sufficient, forgetting that FortiGate still requires an explicit firewall policy to permit inbound traffic to its own IP, as the implicit deny rule blocks all traffic not matched by a policy.

How to eliminate wrong answers

Option A is wrong because a firewall policy from WAN to LAN with HTTPS service would forward management traffic to internal LAN hosts, not to the FortiGate itself, and does not enable the WAN interface to accept HTTPS connections. Option B is wrong because enabling SSH instead of HTTPS does not satisfy the requirement to allow remote management via HTTPS; SSH and HTTPS are separate protocols with different purposes. Option D is wrong because port forwarding is used to redirect traffic to internal servers behind the FortiGate, not to the FortiGate's own management interface; the FortiGate's management IP is directly reachable on the WAN interface when HTTPS access is enabled and a policy is in place.

71
MCQmedium

An administrator needs to allow SSH access to the FortiGate's management interface from a specific management subnet (10.0.1.0/24). Which configuration achieves this?

A.Set the administrative access profile to allow SSH from any IP
B.Configure a firewall policy to allow SSH from 10.0.1.0/24 to the FortiGate
C.Under system admin settings, set the trusted host for the administrator to 10.0.1.0/24 and enable SSH access
D.Create a local-in policy to allow SSH from 10.0.1.0/24
AnswerC

This is the standard and correct method: in the System > Admin > Administrators settings, define a trusted host as 10.0.1.0/24 for that administrator, and ensure SSH is enabled in the administrative access for the interface the admin connects to. Trusted hosts explicitly allowlist the source IP ranges that can initiate management sessions, so only devices from 10.0.1.0/24 can SSH to the FortiGate. Additionally, SSH administrative access must be enabled on the relevant interface for the login to be accepted.

Why this answer

The trusted host setting under system admin settings restricts administrative access (including SSH) to only the specified source IP or subnet. By setting the trusted host to 10.0.1.0/24 and enabling SSH access, the FortiGate ensures that only SSH connections originating from that management subnet can reach the management interface. This is the standard method for controlling administrative access to the FortiGate's management plane.

Exam trap

The trap here is that candidates often confuse firewall policies (which control transit traffic) with administrative access controls (which control traffic destined to the FortiGate itself), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because setting the administrative access profile to allow SSH from any IP would permit SSH connections from all sources, not just the specific management subnet, violating the requirement. Option B is wrong because firewall policies control traffic passing through the FortiGate between interfaces, not traffic destined to the FortiGate itself; administrative access is governed by administrative access settings and trusted hosts, not firewall policies. Option D is wrong because local-in policies are used to filter traffic destined to the FortiGate's own IP addresses, but they are not the primary or recommended method for restricting administrative access; the trusted host setting is the correct and simpler approach for this purpose.

72
MCQmedium

A FortiGate is operating in transparent mode. The admin needs to allow HTTP traffic from users to a web server. Which type of firewall policy is required?

A.A layer 2 firewall policy
B.A policy-based NAT rule
C.A firewall policy using zone-based security
D.A VIP policy to map the web server's public IP
AnswerA

In transparent mode, the FortiGate acts as a transparent bridge (bump in the wire) and does not route IP traffic, so all traffic control must occur at Layer 2. A layer 2 firewall policy inspects and forwards frames based on MAC addresses, VLANs, and other Layer 2 attributes, making it the only policy type that can effectively filter traffic in this deployment. This policy type is required because there is no Layer 3 routing table or IP-based decision-making in transparent mode.

Why this answer

In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding traffic without routing. To allow HTTP traffic from users to a web server, a Layer 2 firewall policy is required because it filters traffic based on MAC addresses and Layer 2 headers, not IP addresses or routing decisions. This policy type is the only one that works in transparent mode, as it does not involve NAT or routing.

Exam trap

The trap here is that candidates often assume firewall policies always involve IP addresses and routing, but in transparent mode, the FortiGate uses Layer 2 policies that operate at the data link layer, not the network layer.

How to eliminate wrong answers

Option B is wrong because policy-based NAT rules are used in NAT/route mode to translate IP addresses, not in transparent mode where the FortiGate does not perform IP routing or NAT. Option C is wrong because zone-based security policies are applicable in NAT/route mode for grouping interfaces into zones; transparent mode uses Layer 2 policies, not zones. Option D is wrong because VIP policies are used for destination NAT in NAT/route mode to map public IPs to private IPs, which is irrelevant in transparent mode where the FortiGate does not perform IP address translation.

73
MCQhard

An administrator is configuring a FortiGate to authenticate users via LDAP. The LDAP server uses a self-signed certificate. When testing the connection, the FortiGate returns an error about certificate validation. Which action should the administrator take to resolve this issue while maintaining security?

A.Disable certificate validation on the FortiGate for LDAP connections.
B.Set the LDAP server to use port 389 with StartTLS and enable certificate validation.
C.Import the LDAP server's CA certificate into the FortiGate's local certificate store and configure the LDAP server to use LDAPS.
D.Configure the LDAP server to use a public CA-signed certificate instead of a self-signed one.
AnswerC

Importing the CA certificate allows the FortiGate to validate the LDAP server's certificate. Using LDAPS ensures encryption. This maintains security by verifying the server's identity. The FortiGate must trust the CA that signed the LDAP server's certificate. This is the correct approach to resolve certificate validation errors while keeping the connection secure.

Why this answer

The certificate validation error occurs because the FortiGate does not trust the self-signed certificate of the LDAP server. Importing the CA certificate into the FortiGate's local store allows it to validate the server's certificate. Configuring LDAPS ensures the connection is encrypted.

This maintains security without disabling validation.

Exam trap

The trap here is choosing to disable certificate validation for convenience, which compromises security, instead of importing the CA certificate to establish trust.

74
MCQmedium

An administrator is configuring a new FortiGate and wants to allow management access from the internal network via HTTPS. The internal interface is port2 with IP 192.168.1.1/24. Which CLI command correctly enables HTTPS administrative access on port2?

A.config firewall policy edit 1 set allowaccess https end
B.config system interface edit port2 set allowaccess https end
C.config system admin edit admin set https enable end
D.config system global set admin-https enable end
AnswerB

This is the correct method to enable HTTPS administrative access on a specific interface. The `config system interface` block enters the interface configuration context, `edit port2` selects the target interface, and `set allowaccess https` adds HTTPS to the list of management protocols permitted on that interface. Without this setting, even if the HTTPS daemon is globally enabled, FortiGate will ignore HTTPS connection attempts on port2 and the administrator would be locked out of that interface.

Why this answer

The `config system interface` command is the proper context to set the `allowaccess` parameter, which controls the administrative protocols (such as HTTPS) permitted on a specific FortiGate interface. By editing port2 and setting `allowaccess https`, the administrator enables HTTPS management access on that interface, allowing internal users to reach the FortiGate's web GUI via 192.168.1.1.

Exam trap

The trap here is that candidates confuse the `allowaccess` parameter (which is set under `config system interface`) with global settings or firewall policies, mistakenly thinking that enabling HTTPS globally or in a policy will grant interface-specific management access.

How to eliminate wrong answers

Option A is wrong because `config firewall policy` is used to define traffic filtering rules between zones, not to enable administrative access on an interface; the `allowaccess` parameter does not exist in firewall policy configuration. Option C is wrong because `config system admin` manages administrator accounts and their permissions, not interface-level protocol access; the `set https enable` command is invalid in this context. Option D is wrong because `config system global` sets global system parameters, and `set admin-https enable` would enable HTTPS for the entire FortiGate, but it does not restrict or allow access on a specific interface like port2; the correct global command for interface-specific access is `set admin-sport` or similar, but the question requires interface-level control.

75
MCQhard

A large enterprise is deploying a FortiGate 600F as the perimeter firewall. The security team requires that all administrative access (SSH, HTTPS, and Ping) to the FortiGate must be restricted to a dedicated management network (10.10.10.0/24). Additionally, any failed login attempt from outside the management network should be logged and the source IP should be blocked for 30 minutes. The administrator has configured a local-in policy to deny all administrative access from non-management networks and enabled logging. However, the administrator wants to automatically block the offending IPs. The FortiGate is not connected to any FortiAnalyzer or FortiManager. What should the administrator do to achieve this?

A.Create an automation stitch that triggers on local-in policy logging and adds the source IP to a blocked list via CLI script.
B.Use a FortiAnalyzer to generate alerts and send to SIEM.
C.Configure a firewall policy to block the offending IPs manually based on logs.
D.Enable 'set block-session-ttl' on the local-in policy.
AnswerA

An automation stitch is the correct approach because it creates an event-triggered workflow: a local-in policy log entry (e.g., 'local-in denial') fires an automation trigger, which then executes a CLI script to add the offending source IP to a configured blocked address list. This provides immediate, autonomous enforcement without waiting for human intervention, and it directly addresses the source IP at the device level.

Why this answer

An automation stitch can directly react to local-in policy log events by executing a CLI script that adds the offending source IP to a local banned user list (e.g., via `diagnose user banned-ip add`). This provides automatic, immediate blocking without requiring external devices like FortiAnalyzer, and the 30-minute duration can be set via the ban-time parameter in the script or the local-in policy's block-session-ttl.

Exam trap

The trap here is that candidates confuse 'block-session-ttl' (which only controls session timeout for already-blocked traffic) with automatic IP banning, or assume external devices like FortiAnalyzer are required when the FortiGate's automation stitch can handle the task locally.

How to eliminate wrong answers

Option B is wrong because the FortiGate is not connected to any FortiAnalyzer or FortiManager, so it cannot rely on external devices to generate alerts or forward logs to a SIEM. Option C is wrong because manually blocking IPs based on logs is not automatic and does not meet the requirement for automatic blocking; it also contradicts the need for a real-time response. Option D is wrong because 'set block-session-ttl' on a local-in policy only controls the session timeout for blocked traffic, not the automatic addition of source IPs to a banned list; it does not trigger a dynamic block action.

Page 1 of 2 · 149 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Nse4 System Network questions.