What is the primary function of the 'FortiToken'?
FortiToken is used to generate the OTP for 2FA.
Why this answer
FortiToken provides a secondary factor for authentication, enhancing account security.
301 questions total · 5pages · All types, answers revealed
What is the primary function of the 'FortiToken'?
FortiToken is used to generate the OTP for 2FA.
Why this answer
FortiToken provides a secondary factor for authentication, enhancing account security.
What does the 'Auto-Link' feature in the 'Policy & Objects' tab do?
This is the core function of auto-linking during imports.
Why this answer
Auto-link automatically maps address objects that have the same name between the FortiManager and the FortiGate.
Which THREE elements are essential to define a user in FortiAuthenticator?
Defines the user's role and access rights.
Why this answer
Username, password (or authentication method), and group membership are fundamental.
What is the primary function of the 'Object' menu within the Policy & Objects tab?
This is the core function of the Object menu.
Why this answer
The Object menu allows the management of reusable components like address objects, services, and schedules.
On FortiWeb, which component is used to inspect traffic for protocol-specific attacks like HTTP Request Smuggling?
The WAF policy defines the specific security modules and profiles applied to traffic.
Why this answer
The WAF policy contains the inspection profiles and rules required to detect protocol-level anomalies.
Which THREE elements are part of the Event Handler configuration?
Action determines the notification delivery.
Why this answer
Event handlers are configured with a filter, a trigger/threshold, and the resulting alert method.
When integrating FortiWeb with FortiAnalyzer, which information is passed to FortiAnalyzer?
Security logs provide the necessary data for threat detection and reporting.
Why this answer
FortiWeb sends its security logs, allowing FortiAnalyzer to provide unified visibility.
What should you do to ensure that an encrypted email sent via IBE reaches the recipient correctly?
IBE requires these to function.
Why this answer
You must ensure that the recipient has a valid email address and that the FortiMail can reach the internet to send the notification.
What is the primary benefit of using a 'Device Group' in FortiManager?
Bulk operations are a key use case for grouping.
Why this answer
Device groups help organize devices for easier reporting and management tasks.
How can you disable the 'Greylisting' feature for a specific, trusted sender?
Whitelisting bypasses AntiSpam checks, including greylisting.
Why this answer
You can add the sender to a whitelist in the AntiSpam profile or use an exception list to bypass greylisting.
What is the result of 'Retrieve Config' when the FortiGate has local changes not yet in the FortiManager database?
This is the primary outcome of a retrieval.
Why this answer
Retrieving the config pulls those changes into the FortiManager, bringing the database into sync.
Which FortiWeb feature is best used to detect 'Brute Force' attacks against a login page?
Threshold rules allow you to track failed attempts and block IPs that exceed the limit.
Why this answer
Threshold rules are used to limit the number of attempts within a specific window of time.
Which interface mode is best suited for high-availability setups where you need to minimize configuration changes on existing infrastructure?
Transparent mode requires no infrastructure changes.
Why this answer
Transparent mode sits in-line and requires no IP changes, making it ideal for seamless integration.
Which FortiAuthenticator feature allows you to map LDAP groups to local FortiAuthenticator groups for administrative access?
Group mapping links external identity sources to local policy roles.
Why this answer
Group mapping enables the synchronization of external directory groups with internal policies.
What is the purpose of 'Report Templates'?
Templates ensure consistency.
Why this answer
Report templates provide predefined structures for generating consistent reports.
What is the purpose of 'Policy Package' import?
Importing creates a central copy of existing device policies.
Why this answer
Importing allows you to pull existing policies from a device into a package in FortiManager.
An administrator needs to quickly distribute a CLI command to fifty managed FortiGate devices. Which feature should they use to automate this task efficiently?
Scripts are the designated tool for running CLI commands on managed devices.
Why this answer
Scripts in FortiManager allow administrators to execute CLI commands across multiple devices or ADOMs simultaneously.
In the Security Fabric, which protocol is primarily used for communication between the FortiGate and the FortiAnalyzer?
OFTP is the dedicated protocol for Fabric communication and log delivery.
Why this answer
OFTP (Over-Fabric Transfer Protocol) is the secure protocol used for telemetry and log transport in the Security Fabric.
If you want to ensure that only authorized administrators can access the FortiAnalyzer GUI, which feature should you implement?
Trusted hosts restrict management access to specific IPs.
Why this answer
Trusted hosts and multifactor authentication (MFA) are the primary security controls for administrative access.
Which 'Install Wizard' option ensures that configuration changes on the FortiManager are synchronized back to the device's configuration file?
This option pushes both policies and device-level configurations.
Why this answer
The 'Install Policy & Device Settings' option ensures the full configuration state is updated.
An administrator wants to ensure that a specific policy is always included in all policy packages within an ADOM. What feature should be used?
Global policies are inherited by all policy packages within the hierarchy.
Why this answer
Global Policies allow for centrally defined rules that are inherited by all packages in the ADOM.
Which protocol does FortiManager use to communicate with managed FortiGate devices?
The proprietary FMG protocol is the standard for communication.
Why this answer
FortiManager uses the FortiManager protocol (FMG protocol) which typically operates over TCP port 541.
Which TWO items are required to configure log forwarding to a remote FortiAnalyzer?
Target IP is essential.
Why this answer
You need the target server's IP and the authentication credentials/key to establish the secure connection.
How can you verify that a FortiGate is sending logs to the FortiAnalyzer?
Device manager shows the log reception status.
Why this answer
Check the 'Log View' or 'Device Manager' for active log status.
How can you view the current number of emails in the quarantine?
Dashboard shows usage statistics.
Why this answer
The dashboard displays statistics about the quarantine, including count.
FortiADC is configured with a Layer 7 policy. You notice that the persistence is failing for a specific application. Which persistence method is most appropriate for a cookie-based application?
Cookie insert adds a unique session identifier to the application traffic, ensuring consistent routing.
Why this answer
Cookie insert persistence is the industry standard for tracking sessions in HTTP applications at Layer 7.
What is the primary role of the 'Administrator' profile?
The admin profile defines what a manager can do.
Why this answer
The admin profile manages access rights and permissions for different user accounts managing the FortiMail.
Which TWO types of report formats can be generated by FortiAnalyzer?
CSV is a standard report format.
Why this answer
FortiAnalyzer supports generating reports in PDF, HTML, and CSV formats.
In FortiManager, what is the result of using the 'Re-install Policy' option instead of the 'Install Wizard'?
Re-install policy is designed for quick redeployment using cached settings.
Why this answer
Re-installing uses the last successful installation configuration, which is faster than a full install wizard run.
You notice that the FortiMail system time is incorrect, causing issues with SSL/TLS certificate validation. How do you correct this?
NTP keeps the clock synchronized.
Why this answer
System time is managed through NTP configuration to ensure synchronization with a reliable time server.
You are configuring a FortiWeb WAF policy to protect a web application. Which inspection mode is most effective for blocking SQL injection attacks while minimizing false positives in a production environment?
Prevention mode blocks traffic, and signature-based scanning correctly identifies SQL injection patterns.
Why this answer
Detection mode is for logging, while Prevention mode blocks attacks. Signature-based scanning is the standard for identifying known SQL injection patterns.
You are deploying FortiMail in Transparent Mode. Which network configuration requirement is mandatory for this deployment?
Bridge pairs are required to bridge the internal and external segments in Transparent mode.
Why this answer
Transparent mode operates at Layer 2; the FortiMail must have a bridge pair configured to inspect traffic without requiring changes to the mail server IP addressing.
Which THREE settings are part of an ADOM's configuration?
ADOMs group specific devices.
Why this answer
ADOMs are configured with a name, a mode (Normal/Advanced), and the specific devices assigned to them.
When using 'VPN Manager', what is the main benefit compared to manual VPN configuration?
Automated provisioning of star/mesh topologies is the key benefit.
Why this answer
VPN Manager simplifies the creation of mesh or star topologies by automating the configuration of tunnels on multiple devices.
Where do you configure the expiration period for messages in the quarantine?
These settings control the TTL for quarantined items.
Why this answer
Quarantine maintenance settings allow defining how many days a message is kept before being purged.
Which THREE of the following are key steps in the 'Policy Install Workflow'?
This is the primary action.
Why this answer
Workflow includes installation preview, the actual deployment, and logging the result.
What is the purpose of the 'License' section in the FortiMail menu?
License management is the specific function.
Why this answer
The license section allows you to manage and verify the status of your product licenses.
Which TWO of the following are allowed in an ADOM?
Administrators can maintain various policy sets per ADOM.
Why this answer
ADOMs can contain multiple devices and multiple policy packages.
You need to export logs from FortiAuthenticator to a remote syslog server. Which configuration path allows you to define this destination?
Remote logging configuration is centrally managed under System settings.
Why this answer
System settings allow for log forwarding to external syslog servers.
Which of these is a legitimate reason to place a sender on the 'Block' list in the AntiSpam profile?
Blocking known spam sources improves filtering efficiency.
Why this answer
The block list allows for the manual rejection of known malicious senders, bypassing further analysis.
When using 'Provisioning Templates', which setting allows you to automatically apply CLI commands to new devices as soon as they are added to the FortiManager?
Device Templates allow for the binding of scripts and settings to new devices.
Why this answer
The 'Provisioning Template' feature allows the association of CLI scripts to be executed upon successful device registration.
You are configuring DLP to block emails containing credit card numbers. Which component must be configured to define the pattern matching for the card numbers?
DLP dictionaries define the patterns or keywords to scan for.
Why this answer
Dictionary-based scanning allows for the definition of patterns (using regex or built-in types) to match sensitive data like credit card numbers.
Which TWO FortiAnalyzer tools help in troubleshooting connection issues?
Shows connectivity status.
Why this answer
The 'Device Manager' shows connection status and the 'CLI' allows for network diagnostic commands (ping/traceroute).
An administrator is attempting to move a device from one ADOM to another. Which condition must be met for this to succeed?
A device must be disassociated from its current policy package to be moved to a different ADOM.
Why this answer
Devices must be removed from all policy packages and have their configuration synchronized before they can be moved between ADOMs.
An administrator finds that the disk usage is at 95% and the FortiAnalyzer has stopped receiving new logs. What is the default behavior when the disk reaches the 'Maximum Storage' limit?
The default behavior is to overwrite the oldest logs.
Why this answer
By default, FortiAnalyzer performs 'Log Overwrite' when the disk is full, but this behavior can be configured.
Which dashboard widget provides a high-level summary of system resource usage?
This provides the summary of system resources.
Why this answer
The 'Dashboard' includes a System Information widget showing CPU/Memory/Disk usage.
What is the purpose of 'Log Forwarding' in FortiAnalyzer?
Forwarding is for external data distribution.
Why this answer
It allows you to send logs to a secondary system (like another FortiAnalyzer or a Syslog server).
An administrator notices that the 'Device Manager' status is 'Unsynchronized'. What is the recommended first step to resolve this?
Retrieving the config synchronizes the FortiManager database with the device configuration.
Why this answer
The 'Retrieve Config' task pulls the latest configuration from the device, which typically resolves synchronization issues.
What is the effect of changing an ADOM mode from 'Advanced' to 'Normal'?
Normal mode is a simplified operational state.
Why this answer
Normal mode simplifies the ADOM by disabling features like per-device log management, but it may require removing devices.
When using the Workflow mode for policy management, what happens immediately after a policy change request is submitted?
Workflow mandates an approval step before deployment.
Why this answer
In Workflow mode, the request is placed in a 'Pending' state and must be approved by an authorized administrator before it can be installed.
You are deploying FortiMail in Transparent mode. Which configuration step is mandatory to ensure traffic is inspected without modifying the IP headers of the email packets?
In transparent mode, you must bridge two interfaces so that traffic flows through the FortiMail without IP layer changes.
Why this answer
Transparent mode operates at Layer 2. You must define the Bridge pair interfaces and ensure the FortiMail acts as a transparent bridge.
Which method is the most efficient way to apply a specific set of CLI commands to 50 FortiGate devices simultaneously in FortiManager?
Script Manager provides a centralized way to run CLI commands on multiple managed devices.
Why this answer
The Script Manager allows admins to define a set of commands and run them on multiple devices concurrently.
When adding a FortiWeb appliance to the Security Fabric, what is the primary prerequisite that must be met on the FortiGate?
The FortiGate must have the Fabric connector enabled to accept the connection.
Why this answer
The FortiGate acts as the root of the Security Fabric and must allow the FortiWeb to join via the Fabric connector settings.
Which TWO actions can be performed on items currently residing in the FortiMail global quarantine?
Administrators can purge messages from the quarantine.
Why this answer
Global quarantine management allows administrators to release or delete messages, and potentially download them for forensic analysis.
Which DNS record must be published in the public DNS to enable DKIM signing for outgoing mail?
The public key is published as a DNS TXT record.
Why this answer
DKIM uses a public key published in a DNS TXT record so that receiving servers can verify the signature added to the email header.
When utilizing the 'Install Preview' feature before pushing a policy package, what is the primary benefit to the administrator?
The preview window shows the exact CLI differences that will be executed.
Why this answer
Install Preview allows the administrator to compare the current configuration on the FortiGate with the pending configuration in FortiManager before committing.
A FortiManager administrator needs to migrate an existing local FortiGate policy into a shared policy package. Which process must be followed?
Global ADOM policies allow for central policy management across multiple ADOMs.
Why this answer
To transition a local policy to a shared one, the admin must copy or move the policy to the global ADOM-level policy package.
You are integrating FortiWeb with FortiAnalyzer. What is the benefit of this integration in a Security Fabric context?
This is the primary function of FortiAnalyzer in the Fabric.
Why this answer
FortiAnalyzer provides centralized logging and advanced reporting capabilities for the entire Fabric, including FortiWeb.
Which TWO of the following are valid methods to back up a FortiManager configuration?
This is a supported manual method.
Why this answer
Backups can be performed manually via the GUI or scheduled as a system task.
A user is attempting to authenticate via a FortiAuthenticator-backed portal but receives an 'Access Denied' message. The user exists in the AD group mapped to the policy. What should you check first?
Authentication logs provide the reason for failure, such as wrong password or policy mismatch.
Why this answer
Checking the FortiAuthenticator authentication logs reveals if the credential was rejected or if the policy match failed.
You need to create a custom report that includes historical traffic data spanning six months. What must be configured to ensure the report generation does not time out?
Caching report data significantly reduces processing time for historical reports.
Why this answer
Enabling 'Report Data Masking' or using 'Report Cache' improves performance for long-duration reports.
When configuring an 'Event Handler' with a 'Threshold', what does the 'Count' field represent?
It is the count of events required to trigger the handler.
Why this answer
The count field specifies the number of occurrences of an event that must happen before an alert is triggered.
Which command allows you to verify if the FortiMail can reach a remote mail server on port 25?
Telnet tests the TCP port connection.
Why this answer
The telnet command from the CLI is the standard way to test network-level connectivity to a specific port.
When scheduling a report, what is the purpose of the 'Output Profile'?
Output profiles handle where and in what format the report is saved.
Why this answer
The output profile determines the format (PDF, HTML, CSV) and the destination of the generated report.
You are trying to delete an ADOM, but the option is greyed out. What is the most likely cause?
You must remove all devices from an ADOM before it can be deleted.
Why this answer
An ADOM cannot be deleted if there are still devices registered within it.
What is the purpose of the 'Add Device' wizard?
This is the primary purpose of the wizard.
Why this answer
The wizard simplifies the process of registering a new FortiGate by prompting for IP, credentials, and ADOM assignment.
If a user is locked out of the FortiAnalyzer GUI, which command is used to unlock the account?
This command unlocks a locked user account.
Why this answer
Using the CLI as an admin, you can use 'execute user unlock <username>' or reset the password via the system admin account.
The shared secret is the cryptographic key used to secure RADIUS packets.
Why this answer
The Shared Secret is the mandatory security parameter for RADIUS communication between a client and a server.
An administrator needs to organize logs from multiple regional FortiGate devices into separate containers based on their geography. Which feature should be configured?
ADOMs allow grouping of devices for log management and administrative control.
Why this answer
ADOMs are used to group devices and organize logs into separate logical containers.
Which menu path is used to create a new Administrator account?
This is the correct path for account management.
Why this answer
'System Settings' -> 'Admin' -> 'Administrators' is the standard path.
Which THREE factors are used by the FortiMail sender reputation service to evaluate an IP address?
High spam volume lowers reputation.
Why this answer
Reputation is calculated based on historical activity, spam history, and known blacklists.
Which configuration is required to allow external users to access the Webmail portal?
Access rules permit the traffic.
Why this answer
You must configure an Access Control rule to allow traffic to the Webmail service on the appropriate interface.
How are Revision Histories primarily used in FortiManager when a device configuration has been modified locally on the FortiGate?
Revision history enables comparing the current state versus historical backups.
Why this answer
Revision history allows you to compare the current device state with the last known good configuration stored in FortiManager.
Which THREE of the following are true regarding 'Revision History'?
This is the primary function.
Why this answer
Revision history creates snapshots of configs, allows comparing versions, and enables restoration.
Which component manages the 'Daily Report' schedule?
Reporting is where schedules are defined.
Why this answer
Report settings allow for the scheduling and delivery of summaries regarding system and email activity.
Practice FORTINET-NSE56 by domain
Target a specific domain to shore up weak areas.