Courseiva

Fortinet NSE5/NSE6 (Network Security Analyst/Specialist tiers, per-product tracks) (FORTINET-NSE56) (FORTINET-NSE56) — Questions 226300

301 questions total · 5pages · All types, answers revealed

Page 3

Page 4 of 5

Page 5
226
MCQeasy

What is the primary function of the FortiMail 'Quarantine' feature?

A.To provide long-term email archiving.
B.To compress outgoing attachments.
C.To bypass SMTP authentication.
D.To hold emails identified as spam or viruses for review.
AnswerD

Quarantine is specifically for holding flagged messages.

Why this answer

The quarantine stores suspicious emails that have been flagged by filters, allowing administrators or users to review them rather than automatically deleting them.

227
Multi-Selecthard

Which THREE actions can be performed by a FortiWeb appliance when it detects a violation in a web request?

Select 3 answers
A.Automatically patch the server vulnerability
B.Log the request details
C.Redirect the client to a block page
D.Increase the backend server CPU
E.Drop the connection (Reset)
AnswersB, C, E

Logging is essential for audit and forensics.

Why this answer

FortiWeb can block the request, log it for analysis, or reset the connection.

228
Multi-Selectmedium

Which TWO of the following are valid methods for FortiAuthenticator to receive user information from an external source?

Select 2 answers
A.SAML
B.SNMP Traps
C.ICMP
D.LDAP
E.HTTP Proxy
AnswersA, D

SAML is a primary protocol for IDP/SP communication.

Why this answer

LDAP and SAML are standard protocols used by FortiAuthenticator to sync or authenticate users.

229
MCQhard

An administrator sees a large volume of '451 4.7.1' errors in the logs. What does this indicate?

A.The recipient domain is invalid.
B.The email has a virus.
C.The sender is being greylisted.
D.The server is down.
AnswerC

Greylisting uses 451 to defer delivery.

Why this answer

451 errors are typical of greylisting, where the mail server is temporarily deferring the email for verification.

230
Multi-Selecthard

When configuring log forwarding from FortiAnalyzer to a remote Syslog server, which TWO of the following parameters must be correctly configured to ensure the remote server accepts the logs?

Select 2 answers
A.Remote server IP address
B.Log filter criteria
C.Enable compression for all logs
D.Syslog server port
E.Include device hostname in logs
AnswersA, D

This is required for the connection to be established.

Why this answer

The server IP and the log format (Syslog) are critical for successful handshakes.

231
Multi-Selectmedium

Which TWO of the following are true about 'Scripts' in FortiManager?

Select 2 answers
A.They can only be run once.
B.They can be scheduled to run at specific times.
C.They automatically convert to policies.
D.They require a separate license.
E.They can be run on multiple devices simultaneously.
AnswersB, E

Script scheduling is a supported feature.

Why this answer

Scripts can be executed on devices and can be stored for reusability.

232
MCQeasy

Which component in FortiManager is responsible for managing the logical grouping of multiple FortiGate devices that share the same policy package?

A.Policy Package
B.Firmware Template
C.ADOM
D.Device Group
AnswerA

Policy packages are assigned to devices to dictate their security rules.

Why this answer

Folders in the Device Manager are used to organize devices, but 'Policy Packages' are the logical unit used to group devices for policy application.

233
MCQmedium

When should you use 'Log Archive' instead of 'Log Database'?

A.For real-time traffic analysis
B.For long-term storage
C.For triggering alerts
D.For generating daily reports
AnswerB

Archive is for cold, long-term storage.

Why this answer

'Log Archive' is used for long-term cold storage of raw logs, whereas the database is for active searching.

234
Multi-Selecteasy

Which TWO of the following are primary functions of a Web Application Firewall (WAF) like FortiWeb?

Select 2 answers
A.Managing local user account provisioning
B.Performing deep packet inspection for malware on email attachments
C.Offloading SSL/TLS processing from backend servers
D.Routing static IP traffic between subnets
E.Protecting against SQL injection and XSS
AnswersC, E

WAFs are commonly used for SSL offloading.

Why this answer

WAFs protect against OWASP Top 10 vulnerabilities and provide SSL termination/offloading for web applications.

235
MCQmedium

You are implementing a WAF policy for a web application. Which profile should you use to prevent the disclosure of sensitive server-side information in error messages?

A.XSS profile
B.SQL Injection profile
C.Data Leak Prevention profile
D.Cookie security profile
AnswerC

DLP/Leak prevention masks sensitive info like error strings or credit card data.

Why this answer

The Leak Detection or Information Disclosure profile masks sensitive data like stack traces in error messages.

236
MCQhard

A FortiManager administrator attempted to install a policy package, but the installation failed due to an object conflict. Where can the administrator view the detailed reason for the installation failure?

A.Device Manager > Revision History
B.System Settings > Event Log
C.Policy & Objects > Task Monitor
D.Policy & Objects > Installation Targets
AnswerC

Task Monitor captures the logs and error codes during policy installation.

Why this answer

The Task Monitor provides detailed logs and error messages for installation tasks, including specific object conflicts.

237
Multi-Selecthard

Which TWO actions can be taken when an event handler triggers?

Select 2 answers
A.Log the event
B.Delete the logs
C.Auto-patch the FGT
D.Reboot the device
E.Send an email
AnswersA, E

Creating a record of the trigger.

Why this answer

Event handlers can send email notifications and generate log entries or trigger webhooks for further processing.

238
MCQeasy

What is the primary benefit of the Security Fabric's 'Automation Stitch' feature?

A.Improving log compression
B.Increasing bandwidth
C.Automating incident response actions
D.Updating firmware
AnswerC

Automation stitches provide predefined triggers and actions for incident response.

Why this answer

Automation stitches allow for triggering actions (like isolating a host) based on detected events.

239
MCQmedium

Which type of scan should be enabled to detect known malware in email attachments?

A.Spam scanning.
B.Antivirus scanning.
C.Reputation scanning.
D.Content scanning.
AnswerB

AV is for malware.

Why this answer

Antivirus scanning is specifically designed to detect known malware signatures in attachments.

240
MCQmedium

What does the 'Heuristic' score measure in the AntiSpam engine?

A.The probability that the email content is spam.
B.The sender's reputation.
C.The attachment size.
D.The speed of the sender.
AnswerA

Heuristics look for spam characteristics.

Why this answer

Heuristic scores are generated by evaluating the structure and content of an email for common spam patterns.

241
MCQmedium

If an administrator uses the 'Import Policy' function, what is the effect on the FortiManager ADOM?

A.It forces a firmware downgrade.
B.It automatically creates a new ADOM.
C.It deletes all existing policies in the ADOM.
D.It merges the FortiGate policies into the FortiManager policy package.
AnswerD

Importing pulls the current device policies into the manager's database.

Why this answer

Importing policies brings existing firewall policies from a FortiGate into the FortiManager database for centralized management.

242
MCQmedium

A customer is experiencing false positives with the FortiMail Antispam engine. Which feature should be configured to allow trusted sender domains while still performing virus scanning?

A.Disable the Antispam engine globally.
B.Add the sender to the Global Whitelist in the Antispam Profile.
C.Modify the recipient's personal whitelist.
D.Create an Access Control List (ACL) policy with the 'Bypass antispam' action.
AnswerD

ACL policies allow granular control to bypass specific modules without disabling virus scanning.

Why this answer

The Access Control List (ACL) allows you to define policies based on sender IP/domain to bypass antispam scanning while maintaining other security layers.

243
MCQmedium

When deploying a policy package, what is the function of the 'Policy Package Status' column in the Install Wizard?

A.It displays the device firmware version.
B.It indicates if the package is in sync with the device.
C.It shows the last modified date.
D.It shows the number of policies in the package.
AnswerB

This column confirms the deployment status of the specific package.

Why this answer

It displays whether the policy package has been successfully installed on the device.

244
Multi-Selectmedium

Which TWO of the following protocols does FortiMail support for mail retrieval?

Select 2 answers
A.POP3
B.FTP
C.IMAP
D.HTTP
E.DNS
AnswersA, C

Standard protocol for retrieving mail.

Why this answer

FortiMail supports POP3 and IMAP for accessing mailboxes.

245
MCQhard

A FortiADC deployment is experiencing high latency for HTTPS traffic. You suspect the SSL handshake is the bottleneck. Which tool in FortiADC is best suited to verify the SSL negotiation time?

A.Packet Capture (sniffer)
B.Traffic Monitor / SSL Dashboard
C.Log Access
D.System Health Monitor
AnswerB

These tools track handshake timing and SSL performance metrics.

Why this answer

The built-in traffic analyzer and SSL handshake metrics provide insight into the time taken to complete the TLS exchange.

246
Multi-Selectmedium

Which TWO components can be included in a 'Provisioning Template' to manage device settings?

Select 2 answers
A.System Templates
B.ADOM Variables
C.CLI Templates
D.Firewall Policies
E.Firmware Images
AnswersA, C

System templates manage global device settings.

Why this answer

Provisioning templates typically include CLI snippets and specific metadata or system settings.

247
Multi-Selectmedium

Which TWO methods are used to share user group information in the Security Fabric?

Select 2 answers
A.SSO
B.VLAN tagging
C.LDAP group synchronization
D.DHCP option 43
E.DNS records
AnswersA, C

Single Sign-On propagates identities.

Why this answer

SSO and LDAP group synchronization are primary ways user metadata is propagated in the Fabric.

248
MCQhard

A user reports that legitimate emails are being quarantined due to a high spam score. You want to add the sender's email address to a whitelist. Where should this be configured to be effective for the specific user?

A.AntiSpam profile block list
B.Personal Safe List in the quarantine portal
C.Recipient policy whitelist
D.System global whitelist
AnswerB

The user-level Safe List is the correct place to whitelist senders for individual accounts.

Why this answer

The Personal Address Book or the per-user Safe List in the user's quarantine portal allows for individual whitelisting.

249
MCQeasy

What is the default port for SMTP communication?

A.110
B.25
C.80
D.443
AnswerB

25 is the standard SMTP port.

Why this answer

SMTP standard communication occurs on port 25.

250
MCQhard

If a FortiAnalyzer is in 'Collector' mode, what is its primary limitation?

A.It cannot forward logs
B.It cannot store logs
C.It cannot run reports
D.It cannot receive logs from FortiGate
AnswerC

Collectors offload the reporting duty to an Analyzer unit.

Why this answer

Collector mode is optimized for log reception and forwarding, but it cannot generate reports.

251
MCQmedium

You are configuring a FortiWeb policy to protect a web application. You need to ensure that the WAF blocks SQL injection attempts while allowing legitimate traffic. Which operational mode should you configure in the server policy?

A.Prevention mode
B.Transparent mode
C.Learning mode
D.Detection mode
AnswerA

Prevention mode actively drops traffic that matches configured security signatures.

Why this answer

Prevention mode is the standard setting for WAF policies to actively block detected threats based on configured signatures.

252
MCQeasy

What is the default port used for log transmission from FortiGate to FortiAnalyzer?

A.443
B.80
C.8888
D.514
AnswerD

514 is the standard port for log transmission.

Why this answer

FortiAnalyzer uses TCP port 514 for Syslog, but OFTP/FortiGate-to-Analyzer traffic typically uses port 514 or SSL-encrypted channels.

253
MCQmedium

What is the maximum number of ADOMs supported on a FortiAnalyzer?

A.50
B.Depends on the model
C.10
D.Infinite
AnswerB

ADOM capacity is model-dependent.

Why this answer

The number of ADOMs is limited by the specific hardware/VM model and licensing.

254
MCQeasy

Which object in FortiWeb is used to define the specific web server or virtual host that the WAF should inspect?

A.Inspection Profile
B.Server Object
C.Server Policy
D.Virtual Host Profile
AnswerC

The Server Policy links the virtual server and the security settings.

Why this answer

A Server Policy in FortiWeb defines the virtual server and the rules applied to it.

255
Multi-Selecthard

Which TWO factors impact the performance of report generation?

Select 2 answers
A.The number of registered devices
B.The firmware version of the devices
C.Whether report caching is enabled
D.The size of the log data
E.The CPU temperature
AnswersC, D

Caching significantly speeds up generation.

Why this answer

Report performance is affected by the amount of data being processed and the complexity of the report/data caching.

256
MCQmedium

What is the primary purpose of using 'Provisioning Templates' in FortiManager?

A.To manage FortiClient endpoints.
B.To create firewall policies across all devices.
C.To generate performance reports.
D.To standardize system settings like NTP, DNS, and logging on multiple devices.
AnswerD

Templates are specifically designed for system-level configuration consistency.

Why this answer

Provisioning templates allow administrators to standardize global settings across multiple FortiGate devices automatically.

257
Multi-Selecteasy

Which THREE of the following are core components of the Fortinet Security Fabric?

Select 3 answers
A.FortiGate
B.Standard Web Browser
C.Third-party printer
D.FortiAnalyzer
E.FortiManager
AnswersA, D, E

The firewall is the center of the Fabric.

Why this answer

FortiGate, FortiAnalyzer, and FortiManager are the primary pillars of the Security Fabric.

258
MCQmedium

What is the function of the 'Check for Updates' feature in FortiManager's FortiGuard settings?

A.To check for new FortiGate hardware models.
B.To update antivirus, IPS, and application control signatures.
C.To verify the license key.
D.To update the FortiManager firmware.
AnswerB

FortiGuard service updates are for security databases.

Why this answer

This feature checks the FortiGuard servers for updates to services like IPS, AV, and Application Control databases.

259
MCQmedium

You need to restrict an administrator to only viewing reports for a specific ADOM. How do you achieve this?

A.Change their password
B.Create a log filter
C.Assign to a specific ADOM
D.Enable 2FA
AnswerC

ADOM-level assignment restricts visibility.

Why this answer

You assign the administrator to an 'Admin Profile' and associate them with a specific ADOM.

260
Multi-Selectmedium

Which THREE items are required to successfully integrate a FortiAuthenticator with an Active Directory (AD) environment for identity-based policies?

Select 3 answers
A.Service account with read permissions
B.LDAP server IP address or FQDN
C.A list of all client machine MAC addresses
D.Domain administrator credentials for the bind user
E.The AD database file export
AnswersA, B, D

A service account is necessary to perform queries against the AD.

Why this answer

You need the AD server details, a service account with read access, and the domain credentials to bind to the directory.

261
MCQmedium

You are configuring an Event Handler to monitor for failed login attempts. To ensure you do not receive too many alerts for the same source IP in a short duration, what should you configure?

A.Log aggregation
B.Event rate limiting
C.Database auto-delete
D.Log forwarding filter
AnswerB

Setting a rate limit or threshold in the event handler allows suppression of duplicate alerts.

Why this answer

Event handlers support 'Threshold' and 'Frequency' settings to prevent alert fatigue.

262
MCQeasy

Which administrative account type has full access to all ADOMs and system settings?

A.Report Admin
B.Log Admin
C.Super_User
D.Restricted Admin
AnswerC

Super_User provides full control.

Why this answer

The 'Super_User' account has unrestricted access.

263
MCQeasy

What does the 'FortiView' module provide?

A.Configuration templates
B.Raw log data
C.Visual traffic analytics
D.Firmware management
AnswerC

FortiView is an analytics/visualization tool.

Why this answer

FortiView provides a visual representation of network traffic and threats.

264
MCQmedium

If an administrator wants to perform a 'Config Check' to see what changes will be deployed during an installation, which option should they select in the 'Install Wizard'?

A.Policy Check
B.Install Config
C.Install Preview
D.Sync Device
AnswerC

The preview option shows the diff between the current and proposed configuration.

Why this answer

The Install Preview allows the administrator to view the changes before they are actually pushed to the device.

265
MCQmedium

You are configuring a FortiWeb WAF policy for a web application. You need to ensure that the WAF blocks requests that contain SQL injection patterns. Which feature should you enable in the WAF profile?

A.Enable SQL Injection in the WAF profile
B.Enable Buffer Overflow protection
C.Enable HTTP Protocol Validation
D.Enable Cross-site Scripting protection
AnswerA

This feature specifically targets SQL injection patterns.

Why this answer

SQL injection protection is a core feature of the signature-based protection in FortiWeb WAF profiles.

266
MCQeasy

Which component of the FortiAuthenticator is responsible for the self-service portal where users can manage their own two-factor authentication tokens?

A.AD Connector
B.Admin GUI
C.RADIUS Server
D.User Portal
AnswerD

The User Portal allows users to manage their own settings.

Why this answer

The User Portal is the dedicated interface for end-users to manage their accounts and 2FA tokens.

267
MCQmedium

A FortiADC is load balancing an HTTPS application. You need to offload SSL processing to the ADC to reduce server load. What is the correct object to configure for this?

A.Content Routing Policy
B.Client SSL Profile
C.Server SSL Profile
D.Layer 7 Persistence Rule
AnswerB

The Client SSL profile allows the ADC to act as the SSL endpoint for incoming client connections.

Why this answer

SSL offloading requires a Client SSL profile applied to the Virtual Server to handle the handshake and decryption.

268
MCQmedium

What is the consequence of deleting a device from an ADOM in FortiManager?

A.The FortiGate is automatically rebooted.
B.The FortiGate will stop passing traffic.
C.The FortiGate configuration is wiped.
D.The FortiGate is no longer managed by that ADOM.
AnswerD

Management connectivity is severed within the FortiManager interface.

Why this answer

Deleting a device removes its configuration and status tracking from FortiManager, but does not affect the physical FortiGate.

269
Multi-Selecteasy

Which THREE are key benefits of using FortiWeb to protect web applications?

Select 3 answers
A.Replacing the ISP
B.Physical security of the server room
C.Protection against SQL Injection
D.SSL Offloading
E.Regulatory compliance reporting
AnswersC, D, E

WAF blocks common web attacks.

Why this answer

FortiWeb protects against injection, provides SSL offloading, and offers compliance reporting.

270
MCQhard

A user authenticated via FortiAuthenticator is unable to access a resource protected by a FortiGate policy. The policy uses the user's LDAP group. What is the most likely cause?

A.The FortiGate remote group is not defined for the LDAP server
B.The LDAP user account is locked
C.FortiAuthenticator is in maintenance mode
D.The user is using the wrong password
AnswerA

The FortiGate must explicitly know about the group to enforce policy-based access.

Why this answer

If the group is not correctly mapped in the FortiGate's remote group list, the user will not match the policy.

271
Multi-Selectmedium

Which TWO features in FortiMail help prevent email spoofing?

Select 2 answers
A.Syslog
B.Antivirus
C.POP3
D.DKIM
E.SPF
AnswersD, E

DKIM verifies the signature integrity.

Why this answer

SPF and DKIM are the primary mechanisms for verifying sender identity and preventing spoofing.

272
MCQmedium

An administrator needs to identify which application is consuming the most bandwidth on the network. Which feature in FortiView provides the most efficient visual representation for this task?

A.FortiView Applications
B.Log View
C.FortiView Sources
D.FortiView Destinations
E.Reports
AnswerA

FortiView Applications allows sorting by bandwidth to identify high consumers.

Why this answer

The Applications dashboard in FortiView is designed specifically to aggregate bandwidth usage by application.

273
MCQmedium

Which FortiWeb feature allows you to block traffic based on the geographic origin of the IP address?

A.Threshold rules
B.Country Blocking
C.IP Reputation
D.Signature set
AnswerB

Country blocking is a standard WAF feature to filter traffic by origin.

Why this answer

Geo-IP blocking allows administrators to restrict access based on country codes.

274
MCQhard

When configuring 'Global Objects' in FortiManager, what happens to the specific objects in the ADOM-level database?

A.They are hidden from the administrator.
B.They are deleted.
C.They are referenced by the ADOM.
D.They are converted to CLI commands.
AnswerC

Global objects are created at the global level and referenced within ADOMs.

Why this answer

Global objects can override or be assigned to ADOMs, ensuring consistent configuration across the organization.

275
Multi-Selectmedium

Which THREE components are required to create a functional FortiSoC Playbook?

Select 3 answers
A.Workflow Actions
B.Report Template
C.Log retention policy
D.Target Connector/Device
E.Playbook Trigger
AnswersA, D, E

Actions define what the playbook does.

Why this answer

A playbook requires a trigger, a workflow of actions, and a target device or connector.

276
MCQmedium

When modifying a policy package, what does 'Lock' indicate?

A.The package is deleted.
B.The package is ready to be pushed.
C.The package cannot be edited by other admins.
D.The package is corrupted.
AnswerC

Locking ensures exclusive access for editing.

Why this answer

Locking prevents other administrators from making changes to the policy package simultaneously.

277
MCQeasy

Which of the following is a component of the Fortinet Security Fabric?

A.A personal printer
B.A standard consumer router
C.A generic web server
D.FortiAnalyzer
AnswerD

FortiAnalyzer provides the central logging and analysis function of the Fabric.

Why this answer

FortiAnalyzer is a core element of the Security Fabric ecosystem.

278
Multi-Selecthard

When defining an Install Workflow, which THREE settings or options can be configured to manage the deployment process?

Select 3 answers
A.Change Firmware automatically
B.Set Notification Email
C.Auto-install on Approve
D.Delete Policy after Install
E.Enable Approval
AnswersB, C, E

Notifications are part of the workflow management.

Why this answer

Workflow settings include approval requirements, notifications, and task locks.

279
MCQeasy

In the Security Fabric, which feature allows the FortiGate to automatically quarantine a host that is identified as compromised by another Fabric device?

A.Security Rating
B.Automation Stitch
C.Fabric Connector
D.Log Correlation
AnswerB

Automation Stitches allow for cross-product automated responses.

Why this answer

The Automation Stitch is the component that triggers actions across the Fabric based on identified events.

280
MCQmedium

What happens if a message matches multiple policies?

A.The system throws an error.
B.All matching policies are applied.
C.The most restrictive action is taken.
D.The first matching policy is applied.
AnswerD

Policies are processed in sequential order.

Why this answer

FortiMail evaluates policies in order; the first match determines the action.

281
Multi-Selecthard

Which THREE features are provided by FortiAuthenticator when integrated into a Security Fabric to enforce identity-based access?

Select 3 answers
A.Single Sign-On (SSO) agentless polling
B.Certificate Authority (CA) services
C.LDAP/RADIUS user directory synchronization
D.Web Application Firewall (WAF) traffic inspection
E.FortiGate firewall policy enforcement
AnswersA, B, C

FAC supports SSO methods to authenticate users across the network.

Why this answer

FortiAuthenticator handles LDAP synchronization, certificate management, and SSO token issuance for the Fabric.

282
Multi-Selecthard

Which TWO conditions must be met for a report to run successfully?

Select 2 answers
A.Report queries must be valid
B.All logs must be archived
C.Logs must be in the database
D.The system must be in collector mode
E.The FortiGate must be offline
AnswersA, C

The logic must be correct to produce results.

Why this answer

The report must have valid query parameters and the necessary log data must be available and processed in the database.

283
MCQhard

You are debugging a SAML authentication issue where FortiAuthenticator is the IDP. The logs show 'Assertion expired'. What is the most likely cause?

A.The browser is blocked
B.The SAML certificate is self-signed
C.The user password is too old
D.Time skew between IDP and SP
AnswerD

SAML assertions have a strict validity window; if clocks are out of sync, the assertion is rejected.

Why this answer

Time skew between the IDP and SP (Service Provider) is the most common cause of expired assertion errors.

284
MCQmedium

How does FortiMail identify the policy to apply to an incoming email?

A.By the size of the email.
B.By the sender IP and recipient domain.
C.By the file type.
D.By the subject line.
AnswerB

Policies are matched based on these criteria.

Why this answer

FortiMail evaluates the incoming connection and recipient information against the configured Access Control and Recipient policies.

285
MCQhard

If you need to change the log storage retention period for a specific ADOM, where is this setting located?

A.FortiView Filters
B.Report Settings
C.Global System Settings
D.ADOM Log Policy
AnswerD

Retention is managed within the ADOM log settings.

Why this answer

Each ADOM has its own 'Log Policy' or 'Disk Quota' configuration.

286
MCQmedium

A customer wants to offload logs from FortiAnalyzer to a remote Syslog server. Where is this configured?

A.Log Forwarding
B.Device Manager
C.FortiView
D.Report Settings
AnswerA

Log forwarding allows sending logs to remote Syslog servers.

Why this answer

Log forwarding is managed in the Device Manager or under System Settings for log forwarding configurations.

287
Multi-Selectmedium

Which THREE types of information are displayed in the System Information widget?

Select 3 answers
A.ADOM mode
B.Firmware version
C.Resource usage (CPU/RAM)
D.System uptime
E.Log forwarding destination
AnswersB, C, D

System versioning info.

Why this answer

The system information widget provides at-a-glance status of uptime, firmware, and resource usage.

288
MCQeasy

Which protocol does FortiAnalyzer primarily use for Web UI access?

A.SSH
B.HTTPS
C.FTP
D.HTTP
AnswerB

HTTPS ensures encrypted access.

Why this answer

FortiAnalyzer uses HTTPS for secure web management.

289
MCQmedium

You are setting up a FortiGate Security Fabric. How do you authorize a downstream FortiSwitch to be managed by the FortiGate?

A.Via CLI using the 'exec switch authorize' command
B.By adding it to the FortiAnalyzer
C.By enabling LLDP on the port
D.By rebooting the switch
AnswerA

Authorizing the switch via the CLI or GUI is the mandatory step for Fabric control.

Why this answer

Authorization is required in the Managed FortiSwitch list to establish the management connection.

290
MCQhard

An administrator wants to perform a 'Re-install Policy' on a subset of devices without changing their current configuration settings. Which install option should be selected?

A.Install Config and Policy
B.Re-install Policy
C.Factory Reset and Install
D.Install Device Settings
E.Re-install Objects Only
AnswerB

Re-install Policy targets only policy and object database synchronization.

Why this answer

When reinstalling, selecting 'Re-install Policy' only updates the firewall policies and objects, leaving existing device settings intact.

291
MCQeasy

What is the primary function of the 'AntiSpam' profile?

A.To encrypt mail.
B.To compress mail.
C.To route mail.
D.To block unwanted emails.
AnswerD

Blocking spam is the core function.

Why this answer

The AntiSpam profile is used to aggregate and configure multiple spam filtering techniques to protect users.

292
Multi-Selecthard

Which TWO methods can be used to perform 'Greylisting' in FortiMail?

Select 2 answers
A.By attachment type
B.By sender email address
C.By sender IP
D.By recipient password
E.By email subject
AnswersB, C

Address-based greylisting is supported.

Why this answer

Greylisting can be configured based on the sender's IP or the sender's email address.

293
MCQmedium

What is the primary difference between a Gateway and a Server mode deployment?

A.Gateway mode relays to backend servers.
B.Gateway mode provides storage.
C.Gateway mode supports LDAP.
D.Gateway mode ignores AntiSpam.
AnswerA

This is the primary distinction.

Why this answer

Gateway mode acts as an MTA for existing servers, while Server mode acts as the mail server itself.

294
MCQmedium

Which of these is a benefit of 'Transparent' mode?

A.It is faster than Gateway mode.
B.It supports only one domain.
C.It hides the mail server IP.
D.It requires no changes to mail server settings.
AnswerD

Ease of deployment is a key benefit.

Why this answer

Transparent mode allows for installation without reconfiguring mail servers, providing ease of deployment.

295
MCQmedium

How can you view the 'Total' number of policies in a specific policy package?

A.In the Device Manager.
B.Using a CLI script.
C.In the Policy & Objects tab list view.
D.By going to the Dashboard.
AnswerC

The policy list view shows the count.

Why this answer

The status bar at the bottom of the policy list displays the total number of policies in the currently selected package.

296
MCQeasy

What is the primary benefit of deploying FortiMail in a cluster?

A.To provide high availability and fault tolerance.
B.To bypass the need for a mail server.
C.To reduce the cost of licensing.
D.To increase the number of physical ports.
AnswerA

Clustering ensures redundancy and service uptime.

Why this answer

Clustering provides high availability and load balancing to ensure mail service continuity.

297
Multi-Selecteasy

Which TWO of these are valid administrative roles in FortiAnalyzer?

Select 2 answers
A.Storage_Manager
B.Firewall_Admin
C.Log_Admin
D.Report_Guest
E.Super_User
AnswersC, E

This is the log-focused role.

Why this answer

FortiAnalyzer supports predefined roles such as Super_User and Log_Admin.

298
MCQeasy

What is the main advantage of using the FortiMail 'Quarantine' portal for end-users?

A.It hides spam messages.
B.It deletes all mail automatically.
C.It allows users to manage their own quarantined emails.
D.It provides full system logs.
AnswerC

User self-service is the main benefit.

Why this answer

The portal empowers users to manage their own spam, reducing the load on IT administrators.

299
MCQhard

An administrator wants to ensure that all outgoing emails are archived to a secondary server. Where is this configured?

A.Archiving policy
B.Access Control rule
C.AntiSpam profile
D.Routing policy
AnswerA

The archiving policy handles the duplication of mail for storage.

Why this answer

Archiving policies are configured to define the source and destination for email archival.

300
MCQhard

You are performing a packet capture on FortiMail. Which command-line tool is most effective for viewing SMTP traffic in real-time?

A.show log traffic
B.execute telnet
C.diagnose sniffer packet any 'port 25' 4
D.get system status
AnswerC

This is the correct command for capturing SMTP traffic.

Why this answer

The 'diagnose sniffer packet' command is the standard way to capture and view traffic in real-time on Fortinet appliances.

Page 3

Page 4 of 5

Page 5

All pages