Courseiva

Fortinet NSE5/NSE6 (Network Security Analyst/Specialist tiers, per-product tracks) (FORTINET-NSE56) (FORTINET-NSE56) — Questions 151225

301 questions total · 5pages · All types, answers revealed

Page 2

Page 3 of 5

Page 4
151
MCQeasy

What is the primary function of the 'FortiToken'?

A.User database management
B.Secure storage for passwords
C.Two-factor authentication (2FA)
D.VPN encryption
AnswerC

FortiToken is used to generate the OTP for 2FA.

Why this answer

FortiToken provides a secondary factor for authentication, enhancing account security.

152
MCQmedium

What does the 'Auto-Link' feature in the 'Policy & Objects' tab do?

A.It maps matching objects between the managed device and the FortiManager database.
B.It automatically creates rules.
C.It links two separate ADOMs.
D.It enables VPN tunnels.
AnswerA

This is the core function of auto-linking during imports.

Why this answer

Auto-link automatically maps address objects that have the same name between the FortiManager and the FortiGate.

153
Multi-Selectmedium

Which THREE elements are essential to define a user in FortiAuthenticator?

Select 3 answers
A.Home address
B.Group Membership
C.Password / Auth method
D.Username
E.Operating System Version
AnswersB, C, D

Defines the user's role and access rights.

Why this answer

Username, password (or authentication method), and group membership are fundamental.

154
MCQeasy

What is the primary function of the 'Object' menu within the Policy & Objects tab?

A.To manage administrator accounts.
B.To create reusable entities like IP addresses, services, and address groups.
C.To configure system interfaces.
D.To monitor log traffic.
AnswerB

This is the core function of the Object menu.

Why this answer

The Object menu allows the management of reusable components like address objects, services, and schedules.

155
MCQmedium

On FortiWeb, which component is used to inspect traffic for protocol-specific attacks like HTTP Request Smuggling?

A.WAF Policy
B.Service Object
C.Virtual Server
D.Server Pool
AnswerA

The WAF policy defines the specific security modules and profiles applied to traffic.

Why this answer

The WAF policy contains the inspection profiles and rules required to detect protocol-level anomalies.

156
Multi-Selectmedium

Which THREE elements are part of the Event Handler configuration?

Select 3 answers
A.Alert action (email/SNMP)
B.Report output profile
C.Firmware update schedule
D.Log filter
E.Threshold (count/time)
AnswersA, D, E

Action determines the notification delivery.

Why this answer

Event handlers are configured with a filter, a trigger/threshold, and the resulting alert method.

157
MCQmedium

When integrating FortiWeb with FortiAnalyzer, which information is passed to FortiAnalyzer?

A.Full packet captures of all traffic
B.SSL Private keys
C.Only administrative login logs
D.Full security event logs
AnswerD

Security logs provide the necessary data for threat detection and reporting.

Why this answer

FortiWeb sends its security logs, allowing FortiAnalyzer to provide unified visibility.

158
MCQhard

What should you do to ensure that an encrypted email sent via IBE reaches the recipient correctly?

A.Configure the IBE settings and verify internet connectivity.
B.Disable antivirus.
C.Increase the disk space.
D.Remove the sender from the whitelist.
AnswerA

IBE requires these to function.

Why this answer

You must ensure that the recipient has a valid email address and that the FortiMail can reach the internet to send the notification.

159
MCQmedium

What is the primary benefit of using a 'Device Group' in FortiManager?

A.They are required for ADOM creation.
B.They provide better firewall performance.
C.They allow for easier organization and bulk actions on devices.
D.They enable automatic failover.
AnswerC

Bulk operations are a key use case for grouping.

Why this answer

Device groups help organize devices for easier reporting and management tasks.

160
MCQhard

How can you disable the 'Greylisting' feature for a specific, trusted sender?

A.Increase the greylisting timer.
B.Add them to the AntiSpam whitelist.
C.Delete their account.
D.Change their IP.
AnswerB

Whitelisting bypasses AntiSpam checks, including greylisting.

Why this answer

You can add the sender to a whitelist in the AntiSpam profile or use an exception list to bypass greylisting.

161
MCQhard

What is the result of 'Retrieve Config' when the FortiGate has local changes not yet in the FortiManager database?

A.All policies are deleted.
B.The FortiGate resets to factory settings.
C.The FortiGate goes offline.
D.The FortiManager database is updated with the device configuration.
AnswerD

This is the primary outcome of a retrieval.

Why this answer

Retrieving the config pulls those changes into the FortiManager, bringing the database into sync.

162
MCQmedium

Which FortiWeb feature is best used to detect 'Brute Force' attacks against a login page?

A.IP Reputation
B.Rate Limiting / Thresholds
C.Cookie signing
D.SQL Injection protection
AnswerB

Threshold rules allow you to track failed attempts and block IPs that exceed the limit.

Why this answer

Threshold rules are used to limit the number of attempts within a specific window of time.

163
MCQeasy

Which interface mode is best suited for high-availability setups where you need to minimize configuration changes on existing infrastructure?

A.Transparent mode
B.NAT mode
C.Gateway mode
D.Server mode
AnswerA

Transparent mode requires no infrastructure changes.

Why this answer

Transparent mode sits in-line and requires no IP changes, making it ideal for seamless integration.

164
MCQeasy

Which FortiAuthenticator feature allows you to map LDAP groups to local FortiAuthenticator groups for administrative access?

A.SSO Domain
B.LDAP Filter
C.RADIUS Client
D.Group Mapping
AnswerD

Group mapping links external identity sources to local policy roles.

Why this answer

Group mapping enables the synchronization of external directory groups with internal policies.

165
MCQmedium

What is the purpose of 'Report Templates'?

A.To update firmware
B.To filter logs
C.To provide consistent report formats
D.To configure alerts
AnswerC

Templates ensure consistency.

Why this answer

Report templates provide predefined structures for generating consistent reports.

166
MCQmedium

What is the purpose of 'Policy Package' import?

A.To backup policies.
B.To share policies between ADOMs.
C.To push policies to a new device.
D.To add existing FortiGate policies to the FortiManager.
AnswerD

Importing creates a central copy of existing device policies.

Why this answer

Importing allows you to pull existing policies from a device into a package in FortiManager.

167
MCQeasy

An administrator needs to quickly distribute a CLI command to fifty managed FortiGate devices. Which feature should they use to automate this task efficiently?

A.Device Groups
B.Policy Packages
C.Scripts
D.Provisioning Templates
AnswerC

Scripts are the designated tool for running CLI commands on managed devices.

Why this answer

Scripts in FortiManager allow administrators to execute CLI commands across multiple devices or ADOMs simultaneously.

168
MCQeasy

In the Security Fabric, which protocol is primarily used for communication between the FortiGate and the FortiAnalyzer?

A.HTTPS
B.SNMP
C.Syslog
D.OFTP
AnswerD

OFTP is the dedicated protocol for Fabric communication and log delivery.

Why this answer

OFTP (Over-Fabric Transfer Protocol) is the secure protocol used for telemetry and log transport in the Security Fabric.

169
MCQhard

If you want to ensure that only authorized administrators can access the FortiAnalyzer GUI, which feature should you implement?

A.Log encryption
B.ADOM mode switching
C.Trusted hosts
D.Report scheduling
AnswerC

Trusted hosts restrict management access to specific IPs.

Why this answer

Trusted hosts and multifactor authentication (MFA) are the primary security controls for administrative access.

170
MCQmedium

Which 'Install Wizard' option ensures that configuration changes on the FortiManager are synchronized back to the device's configuration file?

A.Install Policy Package & Device Settings.
B.Install Policy Package only.
C.Device Settings only.
D.Retrieve Config.
AnswerA

This option pushes both policies and device-level configurations.

Why this answer

The 'Install Policy & Device Settings' option ensures the full configuration state is updated.

171
MCQhard

An administrator wants to ensure that a specific policy is always included in all policy packages within an ADOM. What feature should be used?

A.Script.
B.Provisioning Template.
C.Global Policy.
D.Standard Policy.
AnswerC

Global policies are inherited by all policy packages within the hierarchy.

Why this answer

Global Policies allow for centrally defined rules that are inherited by all packages in the ADOM.

172
MCQeasy

Which protocol does FortiManager use to communicate with managed FortiGate devices?

A.FMG protocol.
B.SSH.
C.SNMP.
D.HTTP.
AnswerA

The proprietary FMG protocol is the standard for communication.

Why this answer

FortiManager uses the FortiManager protocol (FMG protocol) which typically operates over TCP port 541.

173
Multi-Selecteasy

Which TWO items are required to configure log forwarding to a remote FortiAnalyzer?

Select 2 answers
A.The current report schedule
B.Remote server IP address
C.A copy of the local firmware
D.SNMP community string
E.Authentication key
AnswersB, E

Target IP is essential.

Why this answer

You need the target server's IP and the authentication credentials/key to establish the secure connection.

174
MCQmedium

How can you verify that a FortiGate is sending logs to the FortiAnalyzer?

A.By checking the interface status
B.By looking at the routing table
C.By running a report
D.By checking the log status in Device Manager
AnswerD

Device manager shows the log reception status.

Why this answer

Check the 'Log View' or 'Device Manager' for active log status.

175
MCQeasy

How can you view the current number of emails in the quarantine?

A.By running a hardware diagnostic.
B.In the policy editor.
C.On the dashboard.
D.In the system logs.
AnswerC

Dashboard shows usage statistics.

Why this answer

The dashboard displays statistics about the quarantine, including count.

176
MCQhard

FortiADC is configured with a Layer 7 policy. You notice that the persistence is failing for a specific application. Which persistence method is most appropriate for a cookie-based application?

A.Cookie Insert
B.Source IP Persistence
C.SSL Session ID
D.Round Robin
AnswerA

Cookie insert adds a unique session identifier to the application traffic, ensuring consistent routing.

Why this answer

Cookie insert persistence is the industry standard for tracking sessions in HTTP applications at Layer 7.

177
MCQeasy

What is the primary role of the 'Administrator' profile?

A.To store quarantined emails.
B.To manage administrative access and permissions.
C.To filter email content.
D.To configure mail routing.
AnswerB

The admin profile defines what a manager can do.

Why this answer

The admin profile manages access rights and permissions for different user accounts managing the FortiMail.

178
Multi-Selecteasy

Which TWO types of report formats can be generated by FortiAnalyzer?

Select 2 answers
A.CSV
B.EXE
C.ISO
D.PDF
E.MP4
AnswersA, D

CSV is a standard report format.

Why this answer

FortiAnalyzer supports generating reports in PDF, HTML, and CSV formats.

179
MCQhard

In FortiManager, what is the result of using the 'Re-install Policy' option instead of the 'Install Wizard'?

A.It forces a factory reset of the FortiGate.
B.It deletes all objects not in use.
C.It uses the last saved installation parameters to re-push the configuration.
D.It performs an automatic firmware update.
AnswerC

Re-install policy is designed for quick redeployment using cached settings.

Why this answer

Re-installing uses the last successful installation configuration, which is faster than a full install wizard run.

180
MCQhard

You notice that the FortiMail system time is incorrect, causing issues with SSL/TLS certificate validation. How do you correct this?

A.Disable SSL certificate validation.
B.Configure an NTP server.
C.Restart the system clock service.
D.Manually update via the CLI.
AnswerB

NTP keeps the clock synchronized.

Why this answer

System time is managed through NTP configuration to ensure synchronization with a reliable time server.

181
MCQeasy

You are configuring a FortiWeb WAF policy to protect a web application. Which inspection mode is most effective for blocking SQL injection attacks while minimizing false positives in a production environment?

A.Offline mode with learning enabled
B.Prevention mode with signature-based scanning enabled
C.Transparent mode with only DoS prevention
D.Detection mode with no signatures
AnswerB

Prevention mode blocks traffic, and signature-based scanning correctly identifies SQL injection patterns.

Why this answer

Detection mode is for logging, while Prevention mode blocks attacks. Signature-based scanning is the standard for identifying known SQL injection patterns.

182
MCQeasy

You are deploying FortiMail in Transparent Mode. Which network configuration requirement is mandatory for this deployment?

A.The mail server must point to the FortiMail IP as its default gateway.
B.The FortiMail must be configured with a unique IP address for each physical port for routing.
C.The FortiMail must be configured as a mail relay agent.
D.You must configure a bridge pair of interfaces to pass traffic transparently.
AnswerD

Bridge pairs are required to bridge the internal and external segments in Transparent mode.

Why this answer

Transparent mode operates at Layer 2; the FortiMail must have a bridge pair configured to inspect traffic without requiring changes to the mail server IP addressing.

183
Multi-Selectmedium

Which THREE settings are part of an ADOM's configuration?

Select 3 answers
A.Report server IP
B.Assigned Devices
C.Firmware version
D.ADOM Mode
E.ADOM Name
AnswersB, D, E

ADOMs group specific devices.

Why this answer

ADOMs are configured with a name, a mode (Normal/Advanced), and the specific devices assigned to them.

184
MCQhard

When using 'VPN Manager', what is the main benefit compared to manual VPN configuration?

A.It automates the creation of complex VPN topologies.
B.It automatically updates the ISP routing.
C.It increases encryption strength.
D.It removes the need for IPsec.
AnswerA

Automated provisioning of star/mesh topologies is the key benefit.

Why this answer

VPN Manager simplifies the creation of mesh or star topologies by automating the configuration of tunnels on multiple devices.

185
MCQhard

Where do you configure the expiration period for messages in the quarantine?

A.Access rules.
B.Quarantine maintenance settings.
C.System logs.
D.AntiSpam profile.
AnswerB

These settings control the TTL for quarantined items.

Why this answer

Quarantine maintenance settings allow defining how many days a message is kept before being purged.

186
Multi-Selecthard

Which THREE of the following are key steps in the 'Policy Install Workflow'?

Select 3 answers
A.Initiate install.
B.Check installation status.
C.Delete old policies manually.
D.Factory reset the device.
E.Run Install Preview.
AnswersA, B, E

This is the primary action.

Why this answer

Workflow includes installation preview, the actual deployment, and logging the result.

187
MCQeasy

What is the purpose of the 'License' section in the FortiMail menu?

A.To check for updates.
B.To reboot the system.
C.To view and manage product licenses.
D.To view logs.
AnswerC

License management is the specific function.

Why this answer

The license section allows you to manage and verify the status of your product licenses.

188
Multi-Selectmedium

Which TWO of the following are allowed in an ADOM?

Select 2 answers
A.Multiple policy packages.
B.Multiple administrative domains.
C.Multiple FortiManager units.
D.Multiple firmware versions per device.
E.Multiple FortiGate devices.
AnswersA, E

Administrators can maintain various policy sets per ADOM.

Why this answer

ADOMs can contain multiple devices and multiple policy packages.

189
MCQhard

You need to export logs from FortiAuthenticator to a remote syslog server. Which configuration path allows you to define this destination?

A.System > Log Settings > Remote Logging
B.Authentication > RADIUS > Logging
C.General > Reporting
D.Network > Interfaces
AnswerA

Remote logging configuration is centrally managed under System settings.

Why this answer

System settings allow for log forwarding to external syslog servers.

190
MCQeasy

Which of these is a legitimate reason to place a sender on the 'Block' list in the AntiSpam profile?

A.The sender's domain has a valid SPF record.
B.The sender is a partner company.
C.The sender is an internal employee.
D.The sender consistently sends unwanted spam emails.
AnswerD

Blocking known spam sources improves filtering efficiency.

Why this answer

The block list allows for the manual rejection of known malicious senders, bypassing further analysis.

191
MCQmedium

When using 'Provisioning Templates', which setting allows you to automatically apply CLI commands to new devices as soon as they are added to the FortiManager?

A.Auto-Link
B.Device Templates
C.ADOM Policies
D.Install On Install
AnswerB

Device Templates allow for the binding of scripts and settings to new devices.

Why this answer

The 'Provisioning Template' feature allows the association of CLI scripts to be executed upon successful device registration.

192
MCQhard

You are configuring DLP to block emails containing credit card numbers. Which component must be configured to define the pattern matching for the card numbers?

A.Access Control Rule
B.Content profile
C.DLP dictionary
D.Antivirus policy
AnswerC

DLP dictionaries define the patterns or keywords to scan for.

Why this answer

Dictionary-based scanning allows for the definition of patterns (using regex or built-in types) to match sensitive data like credit card numbers.

193
Multi-Selecteasy

Which TWO FortiAnalyzer tools help in troubleshooting connection issues?

Select 2 answers
A.Log View
B.Device Manager
C.CLI tools (ping, get sys status)
D.Report module
E.FortiView map
AnswersB, C

Shows connectivity status.

Why this answer

The 'Device Manager' shows connection status and the 'CLI' allows for network diagnostic commands (ping/traceroute).

194
MCQhard

An administrator is attempting to move a device from one ADOM to another. Which condition must be met for this to succeed?

A.The device must not be assigned to any policy package.
B.The device must be in an 'Unregistered' state.
C.The device must be placed in a 'Group' folder first.
D.The device must be running the latest firmware version.
AnswerA

A device must be disassociated from its current policy package to be moved to a different ADOM.

Why this answer

Devices must be removed from all policy packages and have their configuration synchronized before they can be moved between ADOMs.

195
MCQhard

An administrator finds that the disk usage is at 95% and the FortiAnalyzer has stopped receiving new logs. What is the default behavior when the disk reaches the 'Maximum Storage' limit?

A.Shutdown the device
B.Alert via SNMP only
C.Overwriting old logs
D.Pause all services
AnswerC

The default behavior is to overwrite the oldest logs.

Why this answer

By default, FortiAnalyzer performs 'Log Overwrite' when the disk is full, but this behavior can be configured.

196
MCQeasy

Which dashboard widget provides a high-level summary of system resource usage?

A.System Information
B.Report Settings
C.Log View
D.FortiView Threats
AnswerA

This provides the summary of system resources.

Why this answer

The 'Dashboard' includes a System Information widget showing CPU/Memory/Disk usage.

197
MCQeasy

What is the purpose of 'Log Forwarding' in FortiAnalyzer?

A.To backup the configuration
B.To increase report speed
C.To reduce CPU usage
D.To send logs to external systems
AnswerD

Forwarding is for external data distribution.

Why this answer

It allows you to send logs to a secondary system (like another FortiAnalyzer or a Syslog server).

198
MCQmedium

An administrator notices that the 'Device Manager' status is 'Unsynchronized'. What is the recommended first step to resolve this?

A.Retrieve Config.
B.Change the ADOM version.
C.Reboot the FortiGate.
D.Re-install the firmware.
AnswerA

Retrieving the config synchronizes the FortiManager database with the device configuration.

Why this answer

The 'Retrieve Config' task pulls the latest configuration from the device, which typically resolves synchronization issues.

199
MCQmedium

What is the effect of changing an ADOM mode from 'Advanced' to 'Normal'?

A.It forces all devices to reboot
B.It increases storage capacity
C.It simplifies ADOM management
D.It enables full FortiSoC capabilities
AnswerC

Normal mode is a simplified operational state.

Why this answer

Normal mode simplifies the ADOM by disabling features like per-device log management, but it may require removing devices.

200
MCQhard

When using the Workflow mode for policy management, what happens immediately after a policy change request is submitted?

A.The policy is pushed to the device automatically.
B.The policy is locked and sent to the approval queue.
C.The device immediately reboots.
D.The policy is applied to the 'Staging' ADOM.
AnswerB

Workflow mandates an approval step before deployment.

Why this answer

In Workflow mode, the request is placed in a 'Pending' state and must be approved by an authorized administrator before it can be installed.

201
MCQmedium

You are deploying FortiMail in Transparent mode. Which configuration step is mandatory to ensure traffic is inspected without modifying the IP headers of the email packets?

A.Configure the Bridge pair and disable IP forwarding.
B.Configure the Bridge pair under Network > Interface.
C.Configure static IP routing on the management interface.
D.Assign a virtual IP to the WAN interface.
AnswerB

In transparent mode, you must bridge two interfaces so that traffic flows through the FortiMail without IP layer changes.

Why this answer

Transparent mode operates at Layer 2. You must define the Bridge pair interfaces and ensure the FortiMail acts as a transparent bridge.

202
MCQmedium

Which method is the most efficient way to apply a specific set of CLI commands to 50 FortiGate devices simultaneously in FortiManager?

A.Using the Script Manager.
B.Updating the firmware.
C.Manual CLI access to each device.
D.Modifying the Provisioning Template.
AnswerA

Script Manager provides a centralized way to run CLI commands on multiple managed devices.

Why this answer

The Script Manager allows admins to define a set of commands and run them on multiple devices concurrently.

203
MCQeasy

When adding a FortiWeb appliance to the Security Fabric, what is the primary prerequisite that must be met on the FortiGate?

A.Configure static routing between the devices
B.Enable the Security Fabric connector on the FortiGate
C.Disable all firewall policies
D.Manually create an IPsec tunnel between devices
AnswerB

The FortiGate must have the Fabric connector enabled to accept the connection.

Why this answer

The FortiGate acts as the root of the Security Fabric and must allow the FortiWeb to join via the Fabric connector settings.

204
Multi-Selecthard

Which TWO actions can be performed on items currently residing in the FortiMail global quarantine?

Select 2 answers
A.Modify the sender's IP address.
B.Re-encrypt the message body.
C.Delete the message.
D.Change the recipient's email address.
E.Release the message to the intended recipient.
AnswersC, E

Administrators can purge messages from the quarantine.

Why this answer

Global quarantine management allows administrators to release or delete messages, and potentially download them for forensic analysis.

205
MCQmedium

Which DNS record must be published in the public DNS to enable DKIM signing for outgoing mail?

A.TXT record containing the public key
B.PTR record
C.A record
D.MX record
AnswerA

The public key is published as a DNS TXT record.

Why this answer

DKIM uses a public key published in a DNS TXT record so that receiving servers can verify the signature added to the email header.

206
MCQmedium

When utilizing the 'Install Preview' feature before pushing a policy package, what is the primary benefit to the administrator?

A.To update the FortiManager revision history database.
B.To view the CLI commands that will be pushed to the device.
C.To automatically correct syntax errors in the policy.
D.To bypass the approval workflow.
AnswerB

The preview window shows the exact CLI differences that will be executed.

Why this answer

Install Preview allows the administrator to compare the current configuration on the FortiGate with the pending configuration in FortiManager before committing.

207
MCQhard

A FortiManager administrator needs to migrate an existing local FortiGate policy into a shared policy package. Which process must be followed?

A.Manually re-import the config
B.Use the Policy Import tool to move to Global ADOM
C.Disable policy management
D.Delete local policy and recreate
AnswerB

Global ADOM policies allow for central policy management across multiple ADOMs.

Why this answer

To transition a local policy to a shared one, the admin must copy or move the policy to the global ADOM-level policy package.

208
MCQmedium

You are integrating FortiWeb with FortiAnalyzer. What is the benefit of this integration in a Security Fabric context?

A.It enables hardware acceleration on FortiWeb
B.It bypasses the need for WAF policies
C.It provides centralized logging and advanced analytics
D.It allows FortiWeb to perform SSL offloading
AnswerC

This is the primary function of FortiAnalyzer in the Fabric.

Why this answer

FortiAnalyzer provides centralized logging and advanced reporting capabilities for the entire Fabric, including FortiWeb.

209
Multi-Selectmedium

Which TWO of the following are valid methods to back up a FortiManager configuration?

Select 2 answers
A.Copying files via USB drive.
B.Manual backup via the System Settings GUI.
C.Using the 'Backup' button on the FortiGate.
D.Scheduled backup to an FTP or SCP server.
E.Automatic cloud sync to FortiCloud.
AnswersB, D

This is a supported manual method.

Why this answer

Backups can be performed manually via the GUI or scheduled as a system task.

210
MCQhard

A user is attempting to authenticate via a FortiAuthenticator-backed portal but receives an 'Access Denied' message. The user exists in the AD group mapped to the policy. What should you check first?

A.The AD domain controller's disk space
B.The FortiGate session table
C.FortiAuthenticator Authentication Logs
D.The WAF policy on FortiWeb
AnswerC

Authentication logs provide the reason for failure, such as wrong password or policy mismatch.

Why this answer

Checking the FortiAuthenticator authentication logs reveals if the credential was rejected or if the policy match failed.

211
MCQhard

You need to create a custom report that includes historical traffic data spanning six months. What must be configured to ensure the report generation does not time out?

A.FortiView data archiving
B.Report cache
C.Log archive compression
D.ADOM mode change
AnswerB

Caching report data significantly reduces processing time for historical reports.

Why this answer

Enabling 'Report Data Masking' or using 'Report Cache' improves performance for long-duration reports.

212
MCQhard

When configuring an 'Event Handler' with a 'Threshold', what does the 'Count' field represent?

A.The total number of logs
B.The number of matches
C.The priority of the alert
D.The time window in seconds
AnswerB

It is the count of events required to trigger the handler.

Why this answer

The count field specifies the number of occurrences of an event that must happen before an alert is triggered.

213
MCQhard

Which command allows you to verify if the FortiMail can reach a remote mail server on port 25?

A.ping <IP>
B.arp -a
C.traceroute <IP>
D.telnet <IP> 25
AnswerD

Telnet tests the TCP port connection.

Why this answer

The telnet command from the CLI is the standard way to test network-level connectivity to a specific port.

214
MCQmedium

When scheduling a report, what is the purpose of the 'Output Profile'?

A.Configuring data retention
B.Defining report formats and destinations
C.Setting the report time range
D.Adding user permissions
AnswerB

Output profiles handle where and in what format the report is saved.

Why this answer

The output profile determines the format (PDF, HTML, CSV) and the destination of the generated report.

215
MCQmedium

You are trying to delete an ADOM, but the option is greyed out. What is the most likely cause?

A.The ADOM contains devices
B.The ADOM is set to 'Read-Only'
C.The ADOM has log data
D.The administrator lacks super_admin rights
AnswerA

You must remove all devices from an ADOM before it can be deleted.

Why this answer

An ADOM cannot be deleted if there are still devices registered within it.

216
MCQeasy

What is the purpose of the 'Add Device' wizard?

A.To update the FortiGate firmware.
B.To register a new device to be managed by FortiManager.
C.To migrate policies.
D.To configure VPN tunnels.
AnswerB

This is the primary purpose of the wizard.

Why this answer

The wizard simplifies the process of registering a new FortiGate by prompting for IP, credentials, and ADOM assignment.

217
MCQhard

If a user is locked out of the FortiAnalyzer GUI, which command is used to unlock the account?

A.config system admin
B.execute user unlock
C.get system status
D.set password
AnswerB

This command unlocks a locked user account.

Why this answer

Using the CLI as an admin, you can use 'execute user unlock <username>' or reset the password via the system admin account.

218
MCQhard

When using FortiAuthenticator to provide RADIUS authentication for a third-party VPN gateway, which setting must match between the two devices?

A.The Shared Secret
B.The RADIUS accounting port
C.The NAS-IP-Address
D.The VSA Vendor ID
AnswerA

The shared secret is the cryptographic key used to secure RADIUS packets.

Why this answer

The Shared Secret is the mandatory security parameter for RADIUS communication between a client and a server.

219
MCQeasy

An administrator needs to organize logs from multiple regional FortiGate devices into separate containers based on their geography. Which feature should be configured?

A.Administrative Domains (ADOMs)
B.FortiView Filters
C.Log Filtering
D.Log Forwarding
AnswerA

ADOMs allow grouping of devices for log management and administrative control.

Why this answer

ADOMs are used to group devices and organize logs into separate logical containers.

220
MCQeasy

Which menu path is used to create a new Administrator account?

A.Device Manager
B.System Settings > Admin
C.Report Settings
D.FortiSoC
AnswerB

This is the correct path for account management.

Why this answer

'System Settings' -> 'Admin' -> 'Administrators' is the standard path.

221
Multi-Selecthard

Which THREE factors are used by the FortiMail sender reputation service to evaluate an IP address?

Select 3 answers
A.Recent spam volume
B.DNS PTR record existence
C.Email body content
D.TLS version
E.Connection frequency
AnswersA, B, E

High spam volume lowers reputation.

Why this answer

Reputation is calculated based on historical activity, spam history, and known blacklists.

222
MCQmedium

Which configuration is required to allow external users to access the Webmail portal?

A.An AntiSpam profile.
B.An Access Control rule.
C.A relay host.
D.A static route.
AnswerB

Access rules permit the traffic.

Why this answer

You must configure an Access Control rule to allow traffic to the Webmail service on the appropriate interface.

223
MCQeasy

How are Revision Histories primarily used in FortiManager when a device configuration has been modified locally on the FortiGate?

A.To automatically roll back local changes without user input.
B.To perform a diff between the current device configuration and stored revisions.
C.To create new ADOMs.
D.To schedule daily firmware upgrades.
AnswerB

Revision history enables comparing the current state versus historical backups.

Why this answer

Revision history allows you to compare the current device state with the last known good configuration stored in FortiManager.

224
Multi-Selecthard

Which THREE of the following are true regarding 'Revision History'?

Select 3 answers
A.It restricts administrative access.
B.It automatically deletes old logs.
C.It stores snapshots of device configurations.
D.It facilitates reverting to a known-good state.
E.It allows comparing two different configurations.
AnswersC, D, E

This is the primary function.

Why this answer

Revision history creates snapshots of configs, allows comparing versions, and enables restoration.

225
MCQeasy

Which component manages the 'Daily Report' schedule?

A.Access control rules.
B.Quarantine settings.
C.Report settings.
D.System logs.
AnswerC

Reporting is where schedules are defined.

Why this answer

Report settings allow for the scheduling and delivery of summaries regarding system and email activity.

Page 2

Page 3 of 5

Page 4

All pages