Courseiva

Fortinet NSE5/NSE6 (Network Security Analyst/Specialist tiers, per-product tracks) (FORTINET-NSE56) (FORTINET-NSE56) — Questions 175

301 questions total · 5pages · All types, answers revealed

Page 1 of 5

Page 2
1
MCQhard

A FortiAnalyzer is failing to receive logs from a FortiGate. After verifying the IP connectivity and the FortiGate registration status, which setting should be checked next?

A.FortiGate log-server configuration
B.Report scheduling
C.FortiView update interval
D.FortiAnalyzer Device registration status
AnswerA

The FortiGate must explicitly point to the FortiAnalyzer to send logs.

Why this answer

The 'log-server' setting on the FortiGate must be correctly configured to point to the FortiAnalyzer IP.

2
MCQmedium

You are configuring FortiWeb in reverse proxy mode. A client is receiving 403 Forbidden errors for legitimate traffic due to a SQL injection false positive. Which feature should you modify to allow this traffic while maintaining security?

A.Enable Auto Learning
B.Disable the SQL Injection scanner entirely
C.Switch to Transparent mode
D.Create a WAF Exception for the specific signature ID
AnswerD

WAF exceptions allow administrators to bypass specific signature triggers for known legitimate traffic patterns.

Why this answer

Custom signatures or exception rules allow for granular bypassing of specific signatures that trigger false positives.

3
MCQhard

You have a high volume of logs and need to ensure that the oldest logs are deleted first to make room for new data. Where is this configured?

A.FortiView settings
B.ADOM settings
C.Log forwarding settings
D.Report settings
AnswerB

Disk quotas and deletion policies are managed per ADOM in the settings.

Why this answer

The 'Log Policy' or 'Disk Quota' settings under System Settings define how logs are managed when storage is full.

4
MCQeasy

Which GUI menu is primarily used for monitoring real-time activity?

A.Profile.
B.Policy.
C.Monitor.
D.System settings.
AnswerC

The Monitor menu displays real-time activity.

Why this answer

The Dashboard and Monitor sections show live traffic and status indicators.

5
Multi-Selectmedium

Which TWO of the following are common reasons for a policy installation failure in FortiManager?

Select 2 answers
A.Referenced objects missing on the target device.
B.Device firmware is too new.
C.Too many policies in the package.
D.The administrator password is incorrect.
E.Device is not synchronized.
AnswersA, E

If a policy references a non-existent object, it will fail validation.

Why this answer

Conflicts in object references or synchronization issues are frequent causes of failure.

6
MCQhard

An administrator needs to enforce DMARC 'reject' policy for incoming mail. Where is this enforced in FortiMail?

A.AntiSpam profile
B.Access Control rules
C.Antivirus policy
D.Routing policy
AnswerA

DMARC enforcement is a feature of the AntiSpam profile.

Why this answer

DMARC settings are managed within the 'AntiSpam' profile under 'Domain settings' or specific DMARC control configurations.

7
MCQeasy

You have imported a new FortiGate into FortiManager. Which operation must you perform to synchronize the existing policy package with the new device?

A.Upgrade the firmware.
B.Re-install the device settings.
C.Perform an Import Policy operation.
D.Run a script to update the policy database.
AnswerC

Import Policy is required to bring local policies into the FortiManager ADOM.

Why this answer

Importing creates the configuration, but you must run 'Import Policy' to move the firewall policies into the ADOM database.

8
MCQmedium

You are deploying FortiWeb in a cloud environment. You need to ensure the WAF learns legitimate user behavior. Which mode should you start in to avoid blocking legitimate traffic?

A.Bypass Mode
B.Offline Mode
C.Prevention Mode
D.Detection Mode
AnswerD

Detection mode allows traffic while logging violations for analysis.

Why this answer

Detection mode allows the FortiWeb to analyze traffic and build a baseline without actively blocking requests.

9
MCQhard

You have multiple FortiADC nodes in a High Availability (HA) cluster. Which synchronization method ensures that the session table is shared between nodes to prevent user disconnects during a failover?

A.Session Synchronization
B.Database Replication
C.VRRP Heartbeat
D.Configuration Sync
AnswerA

This ensures the session state is mirrored to the secondary node.

Why this answer

Session sync (or HA synchronization) is essential for maintaining stateful connections during failover.

10
Multi-Selectmedium

Which THREE types of dashboards can be viewed in FortiAnalyzer?

Select 3 answers
A.Custom widgets/dashboards
B.FortiView dashboards
C.Firmware update dashboard
D.Report scheduling dashboard
E.System Information
AnswersA, B, E

User-defined view support.

Why this answer

FortiAnalyzer includes system dashboards, FortiView, and user-defined custom dashboards.

11
MCQhard

When using 'Log Forwarding', can you filter the logs before they are forwarded?

A.Only for FortiAnalyzer destinations
B.Yes, using log filters
C.No, all logs are forwarded
D.Only for Syslog
AnswerB

Log forwarding profiles support filters.

Why this answer

Yes, you can apply filters to log forwarding profiles to only send specific traffic types.

12
MCQeasy

Where do you configure the global whitelist to ensure specific email addresses are never blocked by AntiSpam?

A.Access Control rules
B.AntiSpam profile
C.System network settings
D.Mail Server settings
AnswerB

The whitelist is a core component of the AntiSpam profile.

Why this answer

The global whitelist is found within the AntiSpam profile settings to ensure that senders are always allowed.

13
MCQeasy

Which of the following is a mandatory step when creating a new ADOM in FortiManager?

A.Selecting a firmware version.
B.Assigning an IP address.
C.Defining a policy package.
D.Configuring SNMP.
AnswerA

ADOMs must be mapped to specific FortiGate firmware versions.

Why this answer

An ADOM must have a version selected that matches the firmware version of the FortiGate devices it will manage.

14
MCQhard

When setting up a 'FortiSoC' playbook to send an email, what must be configured first?

A.The report schedule
B.The SMTP server settings
C.The log forwarder
D.The ADOM mode
AnswerB

SMTP settings are required for email actions.

Why this answer

You must set up the 'Mail Server' or 'SMTP' settings in the System Settings to allow the FortiAnalyzer to send emails.

15
MCQhard

You need to ensure that the FortiMail doesn't relay spam to external addresses. Which feature should be configured?

A.Increase storage.
B.Inbound relay policy.
C.Outbound AntiSpam and relay control.
D.Disable DNS.
AnswerC

This restricts what can leave the network.

Why this answer

Setting up strict relaying/access control rules and AntiSpam profiles on outbound traffic is necessary to prevent relaying spam.

16
MCQhard

FortiAuthenticator is acting as a SAML Service Provider for a FortiGate. Users are failing to authenticate. Where should you check the logs to determine if the SAML assertion was received and parsed correctly?

A.FortiAnalyzer Traffic Log
B.FortiGate Event Log
C.RADIUS Authentication Log
D.FortiAuthenticator SAML log
AnswerD

The SAML specific logs verify if the IDP (FortiAuthenticator) correctly communicated with the SP.

Why this answer

The SAML debug logs on the FortiAuthenticator provide detail on the assertion exchange and attribute mapping.

17
Multi-Selecteasy

Which TWO protocols are commonly used for external communication with FortiAnalyzer?

Select 2 answers
A.Telnet
B.SSH
C.POP3
D.HTTP
E.HTTPS
AnswersB, E

Standard secure command access.

Why this answer

HTTPS is used for management and SSH for CLI, while Syslog/OFTP are for log traffic.

18
MCQmedium

Which tab is used to monitor traffic logs from the managed FortiGates?

A.Log View.
B.FortiView.
C.System Settings.
D.Device Manager.
AnswerA

This is the correct tab for log monitoring.

Why this answer

The Log View tab provides access to traffic and event logs collected from managed devices.

19
MCQmedium

Which feature is essential for protecting against password-based malware in attachments?

A.Sender reputation.
B.AV blocking of encrypted archives.
C.Bayesian filtering.
D.Access control rules.
AnswerB

This blocks the delivery of unscannable archives.

Why this answer

Since malware in password-protected ZIPs cannot be scanned, blocking these archives is a standard security practice in the AV profile.

20
MCQeasy

Where do you go to view the real-time logs currently being received by the FortiAnalyzer?

A.Report module
B.FortiSoC module
C.Device Manager
D.Log View
AnswerD

This provides the real-time log feed.

Why this answer

The 'Log View' page shows incoming logs in real-time.

21
Multi-Selectmedium

Which TWO of the following steps are required to integrate FortiAuthenticator with a FortiGate for RADIUS authentication?

Select 2 answers
A.Install a web certificate on the FortiGate
B.Enable LDAP on the FortiAuthenticator
C.Configure FortiAuthenticator as a RADIUS Server on FortiGate
D.Configure SAML on the FortiGate
E.Add the FortiGate IP as a RADIUS Client on FortiAuthenticator
AnswersC, E

FortiGate needs to know where to send the auth request.

Why this answer

Integration requires defining the FortiAuthenticator as a RADIUS server on the FortiGate and ensuring the FortiGate is a registered client on the FortiAuthenticator.

22
MCQmedium

In the context of the Security Fabric, what is a 'root' FortiGate?

A.The firewall with the most ports
B.The oldest firewall in the office
C.The device that controls the Fabric and collects telemetry
D.A virtual appliance
AnswerC

The root device acts as the central point for Fabric management and data collection.

Why this answer

The root FortiGate is the top-level management device that orchestrates other members in the Fabric.

23
MCQhard

When configuring an Antivirus profile, which option is best to handle password-protected ZIP files?

A.Force decryption.
B.Allow all.
C.Block or quarantine.
D.Always ignore.
AnswerC

Blocking/quarantining is the standard security practice for encrypted archives.

Why this answer

You can configure the AV profile to either block, quarantine, or scan if possible; blocking is often safer for encrypted archives.

24
MCQmedium

What happens when you change an ADOM's version?

A.All logs are cleared.
B.All device policies are automatically converted.
C.The ADOM supports the new firmware version features.
D.The FortiManager reboots.
AnswerC

Version upgrades enable new feature sets.

Why this answer

Changing the ADOM version updates the supported firmware features and requires existing devices to match the new version.

25
MCQmedium

When managing policy packages, what does the 'Policy Package' clone feature do?

A.It merges two packages into one.
B.It resets the package to factory defaults.
C.It creates a duplicate of the package.
D.It deletes the original package.
AnswerC

Cloning is the standard way to duplicate a package.

Why this answer

Cloning creates an exact copy of a policy package, which is useful for creating variations for different deployments.

26
Multi-Selectmedium

Which THREE items are included in a standard email header for DMARC validation?

Select 3 answers
A.DKIM signature
B.SPF result
C.From domain
D.Attachment name
E.User password
AnswersA, B, C

DKIM is one of two pillars.

Why this answer

DMARC checks the From domain, SPF/DKIM alignment, and policy flags.

27
MCQmedium

An administrator is managing multiple FortiGate devices using FortiManager. They need to ensure that policy changes made in the ADOM are only pushed to specific firewalls. Which feature should they use to achieve granular control over policy deployment?

A.Global Policy Packages
B.Policy Packages
C.Provisioning Templates
D.Device Groups
AnswerB

Policy Packages are the standard mechanism to organize and target policies to specific devices.

Why this answer

Policy Packages allow administrators to group policies and apply them specifically to selected device groups or individual devices.

28
MCQmedium

What is the primary function of the 'Sender Reputation' service?

A.To filter based on subject lines.
B.To manage mailboxes.
C.To provide encryption.
D.To block senders based on historical data.
AnswerD

Reputation is based on history.

Why this answer

The reputation service uses real-time data to block senders who are known to be malicious, saving system resources.

29
MCQeasy

What is the purpose of 'Auto-cache' for reports?

A.To speed up report generation
B.To compress logs
C.To alert admins
D.To save logs to disk
AnswerA

Caching improves report performance.

Why this answer

Auto-cache pre-calculates the data for a report to ensure it can be generated quickly on demand.

30
Multi-Selectmedium

Which THREE features are available when FortiAnalyzer is configured in 'Analyzer' mode?

Select 3 answers
A.Collector-only mode
B.Report generation
C.Log forwarding
D.FortiSoC playbooks
E.Hardware acceleration
AnswersB, C, D

Analyzer mode is required for reporting.

Why this answer

Analyzer mode provides the full set of FortiAnalyzer features, including reports, SOC, and analysis.

31
MCQhard

When using FortiSoC playbooks, what is the 'Connector' used for?

A.Integrating with external systems
B.Filtering log traffic
C.Managing device firmware
D.Linking logs to reports
AnswerA

Connectors enable the playbook to interact with external products.

Why this answer

Connectors are used to integrate FortiAnalyzer with external systems like FortiGate or email servers for automated actions.

32
MCQeasy

Which service does FortiAuthenticator provide to enable centralized management of user identities?

A.Identity and Access Management (IAM)
B.Packet filtering
C.Load balancing
D.Web application firewalling
AnswerA

FortiAuthenticator is the centralized IAM solution in the Fortinet portfolio.

Why this answer

FortiAuthenticator serves as an LDAP/RADIUS server for centralized credential management.

33
Multi-Selectmedium

Which THREE objects are required to configure a basic load balancing setup in FortiADC?

Select 3 answers
A.Virtual Server
B.Server Pool
C.WAF Policy
D.Content Routing Policy
E.Real Server
AnswersA, B, E

The listener that clients connect to.

Why this answer

Load balancing requires a real server, a server pool, and a virtual server to bind them.

34
MCQmedium

Which feature allows FortiMail to perform automatic cleanup of old messages in the quarantine?

A.Quarantine maintenance
B.Policy-based expiration
C.Daily report schedule
D.Storage quota limit
E.Email Archiving
AnswerA

Maintenance settings allow defining the TTL for quarantined items.

Why this answer

The Quarantine maintenance settings allow for the automatic purging of messages after a set number of days to conserve disk space.

35
MCQeasy

What is the purpose of the 'Relay Host' setting in FortiMail?

A.To define the destination for outgoing mail.
B.To handle administrative login.
C.To store incoming mail.
D.To manage the quarantine.
AnswerA

Relay host is the next destination.

Why this answer

The relay host defines the next hop for outgoing mail, usually the ISP's server or another MTA.

36
MCQhard

You are experiencing delays in mail delivery. Where is the best place to check for queued messages?

A.System dashboard.
B.Mail Queue.
C.AntiSpam log.
D.Routing policy.
AnswerB

The queue monitoring tool shows specific messages.

Why this answer

The 'Mail Queue' monitoring page shows all messages currently awaiting delivery or retry.

37
Multi-Selecteasy

Which TWO products provide identity-based security within the Fortinet portfolio?

Select 2 answers
A.FortiSwitch
B.FortiAP
C.FortiADC
D.FortiGate
E.FortiAuthenticator
AnswersD, E

FortiGate enforces identity-based policies.

Why this answer

FortiGate and FortiAuthenticator work together to provide identity-based access control.

38
MCQhard

When troubleshooting a missing log issue in FortiAnalyzer, which CLI command is most useful for checking the status of the log database?

A.show system logs
B.get log status
C.get system status
D.diagnose sql status
AnswerD

This verifies the SQL database health.

Why this answer

'diagnose sql status' is the primary command to check the health and status of the SQL database which stores the logs.

39
MCQhard

In a FortiWeb high-availability cluster, how are the synchronization settings for SSL certificates managed?

A.Automatic sync via the HA configuration
B.Manual file upload to each node
C.Using a shared external NFS mount
D.Via FortiManager only
AnswerA

In an HA cluster, FortiWeb synchronizes configuration objects and certificates automatically.

Why this answer

SSL certificates must be synchronized across the cluster to ensure consistent decryption of incoming traffic.

40
MCQhard

You have a cluster of FortiWebs. You need to ensure that the session table is shared among members. What is this feature called?

A.Persistence Sharing
B.State Replication
C.Session Synchronization
D.Configuration Sync
AnswerC

Session synchronization allows members to share the current session table.

Why this answer

Session synchronization is required in clusters to maintain state if a failover occurs.

41
MCQeasy

What is the function of the FortiGate's 'Security Fabric' connector?

A.To connect to physical power outlets
B.To reset the firewall
C.To integrate with external platforms like AWS or Azure
D.To bypass the firewall
AnswerC

Connectors enable the Fabric to extend into hybrid cloud environments.

Why this answer

Connectors link the Security Fabric to external cloud and virtualization platforms.

42
MCQeasy

What is the function of the 'Device Manager' in FortiAnalyzer?

A.To view live threats
B.To create playbooks
C.To manage registered devices
D.To run reports
AnswerC

Device Manager handles device registration.

Why this answer

Device Manager is where Fortinet devices are registered and their connection status is monitored.

43
Multi-Selecthard

Which THREE of the following are benefits of using ADOMs in FortiManager?

Select 3 answers
A.Increased throughput for traffic.
B.Ability to manage different firmware versions.
C.Improved administrative control by assigning roles per ADOM.
D.Automatic hardware upgrades.
E.Logical separation of managed devices.
AnswersB, C, E

ADOMs allow grouping devices by firmware release.

Why this answer

ADOMs provide administrative separation, allow for different firmware version management, and improve scalability.

44
MCQeasy

An administrator needs to revert a firewall configuration to a state from two weeks ago. Which feature in FortiManager allows for this recovery?

A.Provisioning Templates
B.Configuration Backup
C.Revision History
D.Script Manager
AnswerC

Revision History specifically tracks configuration changes and enables restoration.

Why this answer

Revision History allows administrators to view, compare, and revert to previous configuration states.

45
MCQmedium

You are configuring a new ADOM for a department that requires strict data segregation. Which setting must be enabled to ensure that log data from different device groups within this ADOM cannot be accessed by other administrators?

A.Enable ADOM-level disk quotas
B.Use individual management VDOMs for every device
C.Enable log encryption per device
D.Assign device-based administrative profiles
AnswerD

Device-based administrative profiles provide granular access control within an ADOM.

Why this answer

Restricted ADOMs with granular permissions ensure that data visibility is limited based on the administrator's assigned ADOM and device profile.

46
MCQmedium

When configuring a Recipient Policy, what does the 'Action' field determine?

A.Whether the email is allowed, blocked, or quarantined.
B.The language of the notification.
C.The storage location of the email.
D.The encryption algorithm used.
AnswerA

The action defines the disposition of the message.

Why this answer

The 'Action' field in a policy determines if the email is accepted, rejected, relayed, or quarantined based on matching criteria.

47
MCQeasy

Which object type allows you to define a single configuration setting that can be applied to multiple FortiGate devices using Provisioning Templates?

A.Device Objects
B.Meta Fields
C.CLI Templates
D.Policy Objects
AnswerB

Meta fields are designed for dynamic variable substitution in templates.

Why this answer

Meta fields allow for dynamic variables that can be defined once and applied across multiple devices.

48
Multi-Selectmedium

Which TWO of the following are valid options for FortiMail deployment?

Select 2 answers
A.Gateway mode
B.Proxy mode
C.NAT mode
D.Endpoint mode
E.Transparent mode
AnswersA, E

Valid deployment mode.

Why this answer

FortiMail supports Gateway, Transparent, and Server modes.

49
MCQmedium

You are deploying FortiWeb in 'Reverse Proxy' mode. Where should the default gateway of the backend web servers point?

A.To a secondary FortiGate
B.To the FortiWeb internal interface
C.To the Loopback interface
D.Directly to the Internet
AnswerB

Ensures traffic flows symmetrically back through the appliance.

Why this answer

In reverse proxy mode, the FortiWeb handles the traffic; the servers should communicate back through the load balancer or the network gateway.

50
MCQeasy

Which setting in the 'System Settings' is used to define the administrator's password policy?

A.Device Manager.
B.Policy & Objects.
C.FortiGuard.
D.Administrator settings.
AnswerD

This is where admin account security is configured.

Why this answer

Admin password policies are managed within the Administrator settings section of System Settings.

51
MCQhard

When integrating FortiAuthenticator with a Windows Active Directory, why is it recommended to use a service account with limited privileges?

A.To adhere to the principle of least privilege
B.To allow easier backup
C.To increase speed
D.To bypass password expiration
AnswerA

Using a low-privilege service account limits the scope of potential attacks.

Why this answer

Following the principle of least privilege ensures that the compromise of the service account does not compromise the entire domain.

52
MCQeasy

Which of the following is a symptom of a full quarantine storage?

A.Slow email delivery.
B.Loss of admin access.
C.Inability to save new emails to the quarantine.
D.Increased spam.
AnswerC

Lack of space prevents new writes.

Why this answer

When storage is full, the system may stop accepting new quarantined items or fail to save new mail.

53
Multi-Selecteasy

Which TWO actions are commonly performed within the 'Device Manager' module?

Select 2 answers
A.Creating custom reports
B.Archiving old log files
C.Monitoring device connection status
D.Configuring event handlers
E.Registering new FortiGate devices
AnswersC, E

This is a primary status monitoring task.

Why this answer

Device Manager is for registering devices and managing their connection status.

54
MCQmedium

You are troubleshooting a scenario where FortiADC is failing to perform health checks on a backend server. Which log should you prioritize to identify the specific reason for the health check failure?

A.System Event Logs
B.Session Table Logs
C.Application Traffic Logs
D.Security Policy Logs
E.SNMP Traps
AnswerA

Health check status changes are logged under System Event logs.

Why this answer

The FortiADC system logs, specifically those related to health check events, provide details on why a node is marked as down.

55
MCQmedium

Which object type should you use in FortiManager to ensure a consistent naming convention for address objects across multiple ADOMs?

A.Provisioning templates.
B.Local ADOM objects.
C.CLI templates.
D.Global objects.
AnswerD

Global objects are designed for cross-ADOM usage.

Why this answer

Global objects allow you to define objects once and push them to multiple ADOMs for consistency.

56
MCQhard

You are troubleshooting a failed policy installation. Where can you view the detailed diff between the FortiManager policy database and the actual FortiGate running configuration?

A.Policy & Objects > Installation Preview.
B.Object Usage.
C.FortiView.
D.Device Manager > Revision History.
E.System Settings > Task Monitor.
AnswerA

The installation wizard provides a Preview option to view the diff.

Why this answer

The 'Preview' feature in the installation wizard provides a side-by-side diff of the changes to be pushed.

57
Multi-Selecthard

Which TWO of the following are true regarding FortiADC's ability to perform Layer 7 load balancing?

Select 2 answers
A.It can route traffic based on HTTP headers or URL patterns
B.It requires all backend servers to be on the same subnet
C.It can manipulate HTTP request and response headers
D.It only supports TCP-based traffic
E.It cannot perform health checks on web servers
AnswersA, C

Layer 7 inspection is required for content-aware routing.

Why this answer

Layer 7 load balancing allows for content-based routing and cookie-based persistence.

58
MCQmedium

Which protocol is used for communication between the FortiMail and a remote LDAP server for user authentication?

A.SMTP
B.POP3
C.LDAP
D.SNMP
AnswerC

LDAP is used for directory integration.

Why this answer

LDAP (Lightweight Directory Access Protocol) is the standard for directory-based user authentication.

59
MCQmedium

What is the purpose of the 'Session Limit' setting in an Access Control Rule?

A.To limit the number of users.
B.To control the speed of virus scanning.
C.To prevent DoS attacks by restricting concurrent connections.
D.To limit the total email storage space.
AnswerC

Session limits protect the gateway from connection-based attacks.

Why this answer

Session limits prevent resource exhaustion by limiting the number of concurrent connections from a single IP.

60
Multi-Selectmedium

Which TWO methods can be used to authenticate users for access to the FortiMail quarantine portal?

Select 2 answers
A.Syslog
B.LDAP
C.SNMP
D.ICMP
E.Local user database
AnswersB, E

LDAP is a standard external auth method.

Why this answer

FortiMail supports internal authentication and external services like LDAP or RADIUS.

61
MCQeasy

Which tab in the FortiManager GUI is primarily used for managing firewall policies and objects?

A.FortiView
B.Policy & Objects
C.Device Manager
D.System Settings
AnswerB

This is the correct tab for policy and object management.

Why this answer

The Policy & Objects tab is the central location for managing firewall rules, addresses, services, and schedules.

62
MCQmedium

You are troubleshooting a sync issue where a device shows 'Modified' status in the Device Manager. What is the most likely cause?

A.The FortiManager license has expired.
B.The FortiManager firmware is outdated.
C.The policy package was deleted.
D.The configuration on the FortiGate was changed locally.
AnswerD

Local changes on the FortiGate trigger a 'Modified' status in FortiManager.

Why this answer

A 'Modified' status indicates the configuration on the FortiGate has diverged from the configuration stored in the FortiManager database.

63
MCQmedium

You are creating a new policy package. You need to ensure that shared objects from the Global ADOM are available. What is the correct workflow?

A.Use the 'Install Wizard' to sync global objects.
B.Export objects from the Global ADOM and re-import them.
C.Import the objects directly into the local policy package.
D.Assign the Global ADOM to the target ADOM.
AnswerD

The Global ADOM must be assigned to the target ADOM to make global objects available.

Why this answer

Global objects must be assigned to an ADOM before they can be used within that ADOM's policy packages.

64
Multi-Selectmedium

Which THREE types of logs can be generated by FortiWeb?

Select 3 answers
A.Packet Capture Log
B.Event Log
C.Traffic Log
D.User Billing Log
E.Attack Log
AnswersB, C, E

Logs system and maintenance events.

Why this answer

FortiWeb logs include traffic, attack, and system events for comprehensive auditing.

65
MCQmedium

What happens when you change the 'Log Policy' to 'Archive only'?

A.Logs are deleted
B.The system reboots
C.Real-time analysis stops
D.The system automatically upgrades
AnswerC

Without the SQL database, analytics features are disabled.

Why this answer

The FortiAnalyzer will stop inserting logs into the SQL database, making them unavailable for reports and FortiView, storing them only as raw files.

66
Multi-Selecthard

Which TWO tasks are part of the 'Log Management' phase on FortiAnalyzer?

Select 2 answers
A.Defining report schedules
B.Configuring playbook triggers
C.Log ingestion and indexing
D.Pushing firmware to FGT
E.Log archiving and cleanup
AnswersC, E

Essential to make logs searchable.

Why this answer

Log management includes the ingestion/storage of logs and the maintenance (archiving/deletion) of those logs.

67
Multi-Selecthard

Which THREE of the following are components of the 'Policy Package'?

Select 3 answers
A.Firewall policies.
B.Hardware interface settings.
C.Firmware images.
D.Address objects.
E.Services.
AnswersA, D, E

Policies are the main component.

Why this answer

Policy packages contain firewall policies, address objects, and services used by those rules.

68
MCQhard

Which protocol is most secure for retrieving email from the FortiMail server?

A.IMAPS.
B.Telnet.
C.SMTP.
D.POP3.
AnswerA

IMAPS includes SSL encryption.

Why this answer

IMAPS (IMAP over SSL) provides encryption for the retrieval process, making it the most secure choice.

69
MCQhard

Which of the following is true about 'Report Data Masking'?

A.It masks sensitive information
B.It encrypts the report file
C.It deletes the logs
D.It hides the entire report
AnswerA

Masking protects privacy.

Why this answer

Data masking allows you to hide sensitive information (like internal IPs or usernames) in reports while maintaining the ability to see trends.

70
MCQmedium

What is the benefit of using 'FortiGuard' services with FortiMail?

A.It provides updated spam and antivirus signatures.
B.It replaces the need for local policies.
C.It provides cloud-based email storage.
D.It allows remote management by Fortinet.
AnswerA

FortiGuard is a threat intelligence service.

Why this answer

FortiGuard provides real-time updates for spam and virus signatures, keeping the appliance protected against new threats.

71
MCQmedium

How can you ensure that only encrypted traffic is allowed for webmail access?

A.Enable HTTPS and redirect HTTP to HTTPS.
B.Use a VPN for all traffic.
C.Set the port to 25.
D.Disable the Webmail service.
AnswerA

This enforces encryption.

Why this answer

Configuring the system to only listen on HTTPS (443) and redirecting HTTP (80) requests enforces encryption.

72
MCQmedium

When an email is encrypted using FortiMail's Identity-Based Encryption (IBE), what does the recipient receive?

A.The email is blocked.
B.A password protected PDF file.
C.The encrypted message attached to the email.
D.A notification email with a link to the secure portal.
AnswerD

The portal is used to decrypt and view the message.

Why this answer

With IBE, the recipient gets a notification email with a link to a secure portal where they can read the encrypted message.

73
MCQeasy

What is the primary function of the FortiAnalyzer 'Log View' page?

A.Configuring device passwords
B.Creating SOC playbooks
C.Generating PDF reports
D.Viewing raw log data
AnswerD

Log View is the interface for searching and viewing raw database logs.

Why this answer

Log View provides a raw, searchable view of the logs stored in the database.

74
Multi-Selectmedium

Which THREE items are found in the 'System Settings' area?

Select 3 answers
A.Administrators
B.Report templates
C.Mail Server settings
D.FortiView widget configuration
E.Disk maintenance
AnswersA, C, E

User management is in system settings.

Why this answer

System Settings contains global configurations like administrators, mail servers, and maintenance tasks.

75
MCQmedium

In which configuration area are 'Content Profiles' created and modified?

A.Domain settings.
B.System settings.
C.Network settings.
D.Profile settings.
AnswerD

Content profiles are defined in the profiles section.

Why this answer

Content profiles are managed under the 'Policy' or 'Profile' sections depending on the firmware version, focusing on content inspection.

Page 1 of 5

Page 2

All pages