Courseiva

Fortinet NSE7 Specialty Modules (SD-WAN and Enterprise Firewall tracks) (FORTINET-NSE7-SPECIALTY) (FORTINET-NSE7-SPECIALTY) — Questions 76150

191 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQhard

A FortiManager administrator needs to ensure that logs from all enterprise FortiGates are aggregated and purged based on storage thresholds. Where is this configured?

A.FortiAnalyzer/Log Settings under Device Manager
B.System settings under 'Network' tab
C.Global Policy settings
D.ADOM management settings
AnswerA

Log settings define disk management for logs.

Why this answer

The log retention and storage settings are managed in the FortiManager's 'FortiView' or 'Device Settings' regarding log management, specifically under 'Log Settings' where disk quota and retention policies are defined.

77
MCQhard

A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?

A.Path MTU Discovery is failing because ICMP unreachable messages are blocked, and TCP MSS clamping is not adjusting the encapsulated IPsec packet size correctly
B.SD-WAN health check probes are overwhelming the IPsec tunnel bandwidth
C.The Antivirus proxy buffer is overflowing due to UDP streaming packets
D.The SSL inspection profile is attempting to decrypt UDP traffic, causing kernel panic and packet drops
AnswerA

Correct. When SD-WAN steers traffic over a tunnel with a smaller MTU, lack of fragmentation or MSS adjustment leads to drops of packets larger than the egress interface MTU.

Why this answer

IPsec encapsulation adds overhead, and if the Path MTU Discovery (PMTUD) fails due to ICMP fragmentation-needed messages being blocked by security profiles or firewalls along the path, packet drops occur for UDP streams exceeding the actual MTU. Adjusting the TCP MSS or enabling ipsec-phase1-interface fragmentation settings/tcp-mss-enforcement resolves this.

78
MCQmedium

An administrator configures an SD-WAN rule to route guest Wi-Fi traffic out of a secondary broadband internet connection. However, guest users are still able to access internal corporate subnets that are routed over the primary IPsec VPN tunnel. What configuration is missing or incorrect?

A.The SD-WAN health check probe is not monitoring the corporate subnet gateway
B.The IPsec Phase 2 security association selectors include the guest subnet range
C.The SD-WAN rule priority for the internal VPN interface is set higher than the broadband interface
D.The firewall policy permitting traffic from the Guest Wi-Fi interface to the internal VPN interface lacks proper security profile enforcement or is missing a deny rule blocking inter-zone access
AnswerD

Correct. Firewall policies control inter-zone traffic access. SD-WAN rules only affect routing for traffic permitted by firewall policies.

Why this answer

SD-WAN rules route internet or specific traffic based on criteria, but traffic between zones (like Guest Wi-Fi to Corporate LAN) is governed by firewall policies. If a firewall policy permits traffic from Guest Wi-Fi directly to Corporate LAN, it bypasses SD-WAN rules because SD-WAN rules only evaluate traffic matching egress SD-WAN zones/interfaces specified by the rule or routing table lookup. To prevent guest traffic from reaching internal subnets, the firewall policy must block or restrict that inter-zone traffic.

79
MCQhard

A FortiGate device is running ADVPN 2.0 with OSPF. A spoke experiences transient routing loops when a shortcut tunnel tears down due to inactivity timeout. Which configuration adjustment on the FortiGate hub and spokes prevents these temporary routing blackholes or loops during shortcut teardown?

A.Disable OSPF on the spoke units and rely entirely on static default routes
B.Adjust the administrative distance or use route redistribution filters with appropriate metrics so hub routes and shortcut routes do not conflict during teardown
C.Set the IPsec phase 1 lifetime to infinite to prevent shortcuts from timing out
D.Configure asymmetric routing bypass on all firewall policies
AnswerB

Correct. Proper administrative distance tuning or route filtering ensures that when a shortcut route is removed from the routing table, the fallback hub route takes over cleanly without routing loops.

Why this answer

When shortcuts time out, routes must cleanly transition back to the hub route without creating transient routing loops. Adjusting route redistribution metrics, using specific distance values, or configuring 'shortcut-routing' / route-map timers / asymmetric routing settings prevents loops. In FortiOS ADVPN, setting appropriate dead timers or using dynamic routing distance adjustments ensures the hub route has a predictable preference when the shortcut drops.

80
Multi-Selectmedium

Which TWO of the following are necessary to successfully deploy an SSL VPN in tunnel mode?

Select 2 answers
A.An IPSec phase 1 configuration
B.A BGP session with the client
C.A valid SSL certificate for the VPN portal
D.A firewall policy allowing the SSL VPN interface to the Internal zone
E.A dedicated hardware switch
AnswersC, D

A trusted certificate is required for secure handshakes.

Why this answer

Tunnel mode requires a configured portal and a policy allowing the VPN tunnel interface to the internal network.

81
MCQmedium

A FortiGate is operating in transparent mode. What is the default behavior when the device receives a frame with an unknown MAC address?

A.Drop the packet
B.Flood to all ports
C.Forward to the management interface
D.Send an ICMP unreachable message
AnswerB

Standard bridging behavior for unknown unicast/broadcast frames.

Why this answer

In transparent mode, the FortiGate acts as a Layer 2 bridge and will flood the unknown frame to all interfaces in the bridge domain except the incoming port.

82
MCQhard

If you modify a shared SD-WAN health check object that is referenced by ten different templates, what happens to the FortiGates?

A.All FortiGates using those templates will be affected after an install
B.The FortiGates will automatically revert to the old settings
C.The health check will be disabled on all devices
D.Only the templates are updated, not the FortiGates
AnswerA

Shared objects propagate changes to all linked entities.

Why this answer

The change affects all templates referencing that object; once pushed, the changes update the health check settings on all associated FortiGates.

83
MCQmedium

What is the maximum number of members allowed in a single SD-WAN zone?

A.8
B.2
C.4
D.Depends on the model, but generally limited by system resources.
AnswerD

The number of members is defined by hardware resource limits.

Why this answer

FortiOS supports a large number of members per zone, typically limited only by the hardware model's scale, not a low fixed number.

84
MCQmedium

In an ADVPN 2.0 deployment, a hub unit uses BGP to advertise routes to spokes. When a spoke learns a prefix via BGP from the hub, what mechanism allows the spoke to automatically initiate an ADVPN shortcut tunnel directly to another spoke when traffic flows between them?

A.The FortiGate kernel detects traffic matching a dynamic BGP route over the IPsec interface and initiates an IKE shortcut negotiation with the target spoke
B.OSPF sends a special multicast hello packet across the hub to establish mesh point-to-point links
C.FortiManager pushes a dynamic static route to both spokes simultaneously
D.The Web Filtering profile intercepts the packet and redirects it via proxy to the destination spoke
AnswerA

Correct. When traffic hits the ADVPN tunnel interface for a destination learned via dynamic routing, the kernel triggers an IKE negotiation directly with the target spoke's public IP.

Why this answer

ADVPN shortcuts are triggered when traffic matches a shortcut trigger mechanism. In ADVPN 2.0, IPsec phase 1 shortcut settings ('set advpn shortcut') and dynamic routing protocols working together allow the kernel to generate shortcut requests when traffic hits the phase 1 interface.

85
MCQhard

During SD-WAN template deployment, what is the role of 'Dynamic Mapping'?

A.To map a single template object to different physical settings on different devices
B.To automate firmware updates
C.To monitor bandwidth usage
D.To dynamically change the SD-WAN rule based on time
E.To calculate the latency of paths
AnswerA

Dynamic mappings solve the problem of non-uniform interface names.

Why this answer

Dynamic mapping allows you to map a single template object to different physical values (like interface names) on different FortiGate devices.

86
Multi-Selectmedium

Which TWO administrative actions require a 'Workspace Mode' enabled in FortiManager?

Select 2 answers
A.Automatic log rotation
B.Creating new ADOMs
C.Forcing a reboot
D.Locking policies for editing
E.Reviewing changes before publishing
AnswersD, E

Workspace mode enables locking.

Why this answer

Workspace mode is required for concurrent editing and locking of policies by multiple administrators.

87
MCQeasy

Where do you configure the 'Gateway' IP address for an SD-WAN member?

A.Under Firewall Policy.
B.Under Network > Static Routes.
C.Under Network > SD-WAN > SD-WAN Members.
D.Under System > Interfaces.
AnswerC

This is the correct path for member gateway configuration.

Why this answer

The gateway for an SD-WAN member is configured within the SD-WAN member settings menu.

88
MCQmedium

When using SD-WAN templates, which option allows you to manage different ISPs on different branches within the same template?

A.Dynamic Mapping
B.Global Objects
C.Device Groups
D.SD-WAN Rules
AnswerA

Dynamic mapping handles device-specific interface differences.

Why this answer

Dynamic mapping allows you to associate the 'WAN' member in the template to 'port1' on one branch and 'wan1' on another.

89
Multi-Selectmedium

Which TWO actions can be performed on a Revision History item in FortiManager?

Select 2 answers
A.Compare with current version
B.Restore to a previous state
C.Delete the entire ADOM
D.Export the revision to an external cloud
E.Modify the version permanently
AnswersA, B

Diff/Compare identifies changes.

Why this answer

Revision history allows you to compare versions (diff) and restore to a previous state.

90
Multi-Selectmedium

An administrator applies security profiles (Antivirus, Web Filtering, and IPS) to traffic steered by an SD-WAN rule. Performance issues arise. Which TWO methods can the administrator use to optimize inspection performance without completely disabling security? (Choose two)

Select 2 answers
A.Switch the inspection mode from proxy-based to flow-based where supported, allowing hardware offloading (NP6/NP7) to accelerate packet processing
B.Set the IPsec Phase 1 encryption algorithm to DES to speed up decryptions
C.Configure security profile exemptions or antivirus inspection overrides for trusted internal subnets or latency-sensitive VoIP traffic
D.Disable all SSL inspection globally across the entire FortiGate device
E.Remove the SD-WAN virtual interface from all firewall zones
AnswersA, C

Correct. Flow-based inspection is less resource-intensive and integrates better with hardware acceleration than proxy-based inspection.

Why this answer

Optimizing security profile performance while maintaining inspection includes switching inspection mode to flow-based where appropriate, tuning antivirus/IPS settings to bypass heavy file types or exempt trusted IPs, and leveraging hardware acceleration.

91
MCQeasy

Which configuration mode allows you to define a virtual MAC address for an HA cluster to prevent ARP cache issues on switches?

A.DHCP relay
B.Static ARP
C.Virtual MAC
D.Physical MAC
AnswerC

Using a virtual MAC ensures the downstream switches do not need to relearn the MAC address during failover.

Why this answer

The 'ha-mgmt-status' and virtual MAC features ensure that the cluster presents a consistent MAC regardless of which node is master.

92
MCQeasy

When configuring an SD-WAN health check to monitor internet reachability using HTTP/HTTPS requests, which parameter defines the specific string the FortiGate expects to receive in the server response body to validate that the path is healthy?

A.probe-packet-size
B.sla-break-time
C.http-match
D.server-response-timeout
AnswerC

Correct. The http-match parameter specifies the string that must be present in the HTTP response body for the health check probe to be considered successful.

Why this answer

In SD-WAN health check (ping, tcp-echo, http, dns), when HTTP is selected as the server-type, administrators can configure a 'security-string' or 'http-match' / 'expect' string to validate the HTTP response body.

93
Multi-Selectmedium

Which THREE of the following criteria are used for SD-WAN rule traffic matching?

Select 3 answers
A.Interface speed
B.Destination address
C.VLAN priority
D.Application/Service
E.Source address
AnswersB, D, E

Matching criteria.

Why this answer

SD-WAN rules match traffic based on Source, Destination, and Application/Service.

94
MCQhard

You are troubleshooting a policy installation failure where the FortiManager reports a 'Configuration conflict'. Which action should you perform to identify the root cause of the mismatch?

A.Force an 'Import Policy' operation
B.Reboot the FortiManager
C.Disable the policy package entirely
D.Use the 'Diff' feature in the Policy & Objects tab to compare the database and device config
AnswerD

The Diff tool is the standard method for resolving conflicts.

Why this answer

The 'Check Configuration' or 'Diff' tool in the Policy & Objects tab allows administrators to compare the database version against the running device configuration to pinpoint the exact setting causing the conflict.

95
MCQhard

In a BGP deployment, your FortiGate is receiving routes from two different ISPs. You want to influence outbound traffic to prefer ISP1 for specific destinations. Which BGP attribute should you modify?

A.Weight
B.Local Preference
C.AS-Path
D.Multi-Exit Discriminator (MED)
AnswerB

Local Preference is the standard BGP attribute for controlling outbound path selection.

Why this answer

Local Preference is used to influence outbound traffic selection within an AS.

96
MCQeasy

When troubleshooting SD-WAN performance SLA packet loss, an administrator wants to view real-time latency, jitter, and packet loss statistics for individual health check members. Which CLI command should be executed?

A.diagnose sys sdwan health-check
B.get system interface physical
C.execute ping-server status
D.show system sdwan
AnswerA

Correct. This command displays the current status, latency, jitter, and packet loss for configured SD-WAN health checks.

Why this answer

FortiOS provides diagnostic commands to check SD-WAN health check status and SLA metrics. The correct command is 'diagnose sys sdwan health-check'.

97
MCQmedium

You notice that an IPsec tunnel is up, but no traffic passes. What is the most common reason related to firewall policy configuration?

A.Missing static route
B.Incorrect IKE ID
C.Phase 1 lifetime expiration
D.Missing firewall policy
AnswerD

Policies are mandatory to permit inter-zone traffic flow.

Why this answer

Even if the tunnel is up, a policy must exist to allow traffic to flow between the internal network and the tunnel interface.

98
MCQmedium

You are troubleshooting high CPU usage on a FortiGate. Which process would you check to see if the IPS engine is the cause?

A.diag sys top
B.get system status
C.diagnose hardware status
D.show sys resource
AnswerA

This shows all running processes and their resource consumption.

Why this answer

The 'diag sys top' command displays real-time resource utilization, allowing the admin to identify specific processes like 'ipsengine' consuming CPU.

99
Multi-Selectmedium

Which TWO of the following are benefits of using the FortiGate flow-based inspection mode?

Select 2 answers
A.It supports deep content inspection for all protocols
B.It uses fewer system resources than proxy-based inspection
C.It provides higher throughput performance
D.It requires manual buffer allocation
E.It offers more granular application control
AnswersB, C

It avoids the overhead of buffering the entire object.

Why this answer

Flow-based inspection is generally faster and provides better performance than proxy-based inspection.

100
MCQeasy

What is the primary function of the FortiGate Security Fabric?

A.To configure OSPF automatically
B.To increase the throughput of the firewall
C.To replace the need for an IPS sensor
D.To synchronize security policies and share intelligence across devices
AnswerD

This is the core value proposition of the Security Fabric.

Why this answer

The Security Fabric integrates multiple devices to provide coordinated, end-to-end security visibility and control.

101
Multi-Selectmedium

Which TWO of the following are valid methods for user authentication on a FortiGate?

Select 2 answers
A.BGP
B.RADIUS
C.LDAP
D.IGMP
E.RIP
AnswersB, C

RADIUS is a standard for enterprise authentication.

Why this answer

FortiGate supports both local user databases and integration with external enterprise servers like RADIUS and LDAP.

102
Multi-Selecthard

Which THREE items are included in the configuration file of a FortiGate?

Select 3 answers
A.User certificates
B.Network interface settings
C.FortiGuard cached updates
D.Real-time session tables
E.Firewall policies
AnswersA, B, E

Stored in the config file.

Why this answer

The configuration file contains system settings, policy rules, and interface definitions.

103
MCQmedium

When using an IPS sensor, what is the difference between 'Protect' and 'Monitor' mode?

A.Protect applies only to WAN; Monitor applies to LAN
B.Protect drops traffic; Monitor only logs it
C.Protect requires SSL inspection; Monitor does not
D.Protect logs traffic; Monitor drops it
AnswerB

'Protect' implies active enforcement.

Why this answer

'Protect' drops the traffic if a signature matches, whereas 'Monitor' logs the hit without dropping the traffic.

104
MCQeasy

Which administrative access type is recommended to be disabled on public-facing interfaces for security best practices?

A.SSH
B.HTTPS
C.SNMP
D.HTTP
AnswerD

HTTP sends credentials in cleartext and should be restricted.

Why this answer

HTTP and Telnet are unencrypted protocols and should always be disabled on external interfaces.

105
Multi-Selectmedium

Which TWO types of reports can be generated in the FortiAnalyzer module of FortiManager?

Select 2 answers
A.Custom reports
B.Pre-defined reports
C.Policy change impact reports
D.Hardware diagnostic reports
E.Firmware compatibility reports
AnswersA, B

Admins can build custom reports.

Why this answer

FortiAnalyzer provides both pre-defined reports and custom reports for tailored analysis.

106
MCQeasy

An administrator wants to apply a Web Filtering security profile to traffic that is being dynamically steered via an SD-WAN rule. Where must this security profile be enforced in FortiOS?

A.Inside the firewall policy that matches the traffic being steered by the SD-WAN rule
B.Directly inside the SD-WAN rule configuration under the advanced settings tab
C.Globally under the system settings as an SD-WAN overlay inspection profile
D.Within the IPsec tunnel phase 2 security association settings
AnswerA

Correct. Traffic steered by SD-WAN rules must still match a firewall policy where security profiles (like Web Filtering, Antivirus, IPS) are attached.

Why this answer

Security profiles in FortiOS are always applied within firewall policies, not directly inside SD-WAN rules or interface configurations. The SD-WAN rule handles routing/path selection, while the firewall policy handling that traffic enforces security profiles.

107
Multi-Selectmedium

Which TWO settings are modified to reduce the impact of a failover event in an HA cluster?

Select 2 answers
A.group-password
B.hb-interval
C.hb-lost-threshold
D.priority
E.monitored-interfaces
AnswersB, C

Faster interval leads to faster detection.

Why this answer

'hb-interval' and 'hb-lost-threshold' determine how quickly the cluster reacts to heartbeat loss.

108
Multi-Selecthard

Which THREE actions can be performed by the FortiGate when a policy match occurs?

Select 3 answers
A.Re-route to a specific switch port
B.Disable hardware acceleration
C.Traffic Shaping
D.Deny
E.Accept
AnswersC, D, E

Limits bandwidth usage.

Why this answer

Firewall policies can accept, deny, or perform traffic shaping and logging depending on the configured profile settings.

109
MCQhard

You need to ensure that session synchronization between HA nodes is as efficient as possible. Which parameter should be tuned in the HA configuration?

A.monitor-interface
B.override
C.heartbeat-interval
D.session-pickup-delay
AnswerD

This setting allows delaying session pickup, which can reduce CPU utilization during high-frequency session creation.

Why this answer

The 'session-pickup' setting, specifically 'session-pickup-delay', helps manage the timing and load of session synchronization to prevent CPU spikes.

110
Multi-Selectmedium

Which TWO of these are valid SD-WAN health check protocols?

Select 2 answers
A.SSH
B.FTP
C.HTTP
D.Ping
E.SNMP
AnswersC, D

HTTP is a supported health check protocol.

Why this answer

FortiGate SD-WAN supports multiple probes, including HTTP, Ping, and DNS, to verify link health.

111
MCQhard

You are using 'SLA Target' as your strategy. What happens if multiple members meet the SLA?

A.The system selects the first member in the list.
B.The system selects the one with the highest bandwidth capacity.
C.The system selects the member with the best performance (e.g., lowest latency).
D.Traffic is sent through all of them simultaneously.
AnswerC

It dynamically selects the best performer.

Why this answer

When multiple members meet the SLA in 'SLA Target' mode, the FortiGate uses the member with the best performance metric (e.g., lowest latency).

112
MCQeasy

When adding a FortiGate to FortiManager, which mode must the FortiGate be in to allow the FortiManager to manage its configuration and policies?

A.Registration-only mode
B.Backup mode
C.Normal mode
D.Read-only mode
AnswerC

Normal mode is required for full management.

Why this answer

The FortiGate must be in 'Normal' mode; if it is in 'Backup' or 'Read-only' mode, full management is not possible.

113
Multi-Selecthard

Which THREE aspects of the FortiGate system are affected by changing the global 'set vdom-mode' to 'multi-vdom'?

Select 3 answers
A.CLI command hierarchy
B.The HA cluster size
C.Management of system resources
D.The physical port order
E.How firewall policies are applied
AnswersA, C, E

The 'config vdom' context becomes available.

Why this answer

Changing the VDOM mode affects the CLI hierarchy, the available memory for VDOMs, and how system resources are partitioned.

114
Multi-Selecthard

Which THREE items are included in a Policy Package when it is pushed from FortiManager?

Select 3 answers
A.Service Objects
B.Firewall Policies
C.System interface settings
D.Routing tables
E.Address Objects
AnswersA, B, E

Services define ports/protocols for policies.

Why this answer

Policy packages include firewall policies, address objects, and services used within those policies.

115
Multi-Selecthard

Which THREE factors influence the Master election in an HA cluster?

Select 3 answers
A.CPU load
B.Device Hostname
C.Uptime (if priority is equal)
D.Device Priority
E.Monitor interface status
AnswersC, D, E

Longest uptime wins if priority matches.

Why this answer

The election process considers the monitor status, the override setting, and the priority values of the devices.

116
MCQhard

In a VDOM-enabled environment, how are administrative accounts managed?

A.Admins can be scoped to specific VDOMs
B.Only the root VDOM admin can change settings
C.Admins must be global
D.All admins see all VDOMs
AnswerA

This is the primary benefit of administrative VDOM access control.

Why this answer

Administrative accounts can be restricted to specific VDOMs (Global admin vs. VDOM admin) for granular access control.

117
Multi-Selecthard

Which THREE features are specific to the FortiManager 'Enterprise Firewall' management workflow?

Select 3 answers
A.Object database management
B.Revision control
C.Traffic shaping on routers
D.Web filter database updates
E.Centralized policy management
AnswersA, B, E

Objects are managed globally.

Why this answer

Centralized policy management, object database management, and revision control are key parts of the enterprise workflow.

118
MCQeasy

What is the primary purpose of an ADOM in FortiManager?

A.To logically group devices for delegated administration and policy management
B.To provide high availability for the FortiGate
C.To allow external API access to the FortiGate
D.To increase the storage capacity of the FortiManager
AnswerA

ADOMs provide administrative segmentation.

Why this answer

Administrative Domains (ADOMs) allow the segregation of managed devices based on geography, customer, or business unit for delegated administration.

119
MCQhard

You are troubleshooting an issue where traffic is not using an SD-WAN rule despite meeting criteria. What is the most likely cause?

A.A higher-priority SD-WAN rule is matching the traffic first.
B.The SD-WAN rule is disabled.
C.The Performance SLA has timed out.
D.The interface is not in an SD-WAN zone.
AnswerA

Rules are processed sequentially.

Why this answer

SD-WAN rules are evaluated top-down. If a higher-priority rule matches the traffic, the lower-priority rule will never be reached.

120
MCQmedium

When configuring SD-WAN services in a template, what does the 'Performance SLA' setting determine?

A.The physical port priority
B.The maximum bandwidth allowed
C.The number of tunnels created
D.The criteria for path selection based on link quality
AnswerD

SLA criteria determine if a link is eligible for traffic.

Why this answer

The Performance SLA defines the criteria (latency, jitter, loss) that must be met for a path to be considered 'healthy' for traffic.

121
MCQmedium

You are configuring a Performance SLA to monitor reachability to a SaaS application. Which parameter determines the threshold for an interface to be considered 'unhealthy' in the SD-WAN routing table?

A.Probe Mode
B.Sequence Number
C.Packet Loss Threshold
D.Update Interval
AnswerC

If packet loss exceeds this percentage, the member is removed from the SD-WAN route table.

Why this answer

The 'threshold-alert' or the individual latency/jitter/packet loss thresholds within the Performance SLA configuration dictate when a member is marked failed.

122
MCQmedium

An administrator is configuring the FortiManager to manage multiple FortiGate devices across different regions. Which method ensures that the device configuration remains synchronized with the FortiManager policy database during an automatic configuration update?

A.Set the FortiGate to 'Read-Only' mode
B.Enable Auto-update in the Device Manager configuration settings
C.Enable ADOM-level scheduling
D.Configure a manual CLI script to push updates
AnswerB

Auto-update ensures configuration synchronization.

Why this answer

The 'Auto-update' feature in the FortiManager Device Manager ensures that the configuration on the managed device is automatically synchronized with the policy package defined in the FortiManager database.

123
MCQhard

An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?

A.Weight replaces the need for SD-WAN SLA rules by performing layer 7 packet inspection
B.Weight automatically adjusts the SD-WAN health check probe frequency based on route stability
C.Weight is evaluated first in the BGP best-path selection algorithm on FortiOS, allowing local preference override without altering global AS path attributes
D.Weight is propagated to all iBGP peers, ensuring cluster-wide path synchronization
AnswerC

Correct. Weight is local to the FortiGate and takes precedence over all other BGP path selection criteria, making it ideal for local path steering.

Why this answer

Weight is a Cisco/FortiOS-specific BGP attribute that is local to the router on which it is configured. It is evaluated first in the BGP best-path selection algorithm, allowing administrators to deterministically force traffic out of a specific SD-WAN/BGP member without affecting other routers in the AS.

124
MCQmedium

An administrator configures an SD-WAN rule using the 'Volume' strategy across two IPsec tunnels with different bandwidth capacities (Tunnel A: 100 Mbps, Tunnel B: 50 Mbps). How does FortiOS distribute traffic across these members when using the Volume strategy?

A.Traffic is balanced equally (50/50) regardless of interface capacity
B.Traffic is sent exclusively over Tunnel A until it reaches 100% packet loss, then fails over to Tunnel B
C.Traffic is distributed proportionally based on the configured weight or bandwidth ratio of each member interface
D.Traffic is steered strictly based on real-time latency measured by health checks
AnswerC

Correct. Volume-based strategy divides traffic proportionally according to the weights assigned to the SD-WAN members, matching their respective link capacities.

Why this answer

The Volume strategy in SD-WAN distributes traffic proportional to the configured volume/weight (bandwidth capacity) of each member interface.

125
MCQmedium

Which type of script in FortiManager is designed to run on the FortiManager itself rather than the managed devices?

A.CLI scripts
B.TCL scripts
C.Configuration scripts
D.Policy scripts
AnswerB

TCL scripts run on the FMG.

Why this answer

TCL scripts can be used to automate FortiManager functions, whereas CLI scripts typically target the managed devices.

126
MCQmedium

Which command is used to verify the current status of SD-WAN members and their SLA health from the CLI?

A.diagnose sys sdwan health-check
B.show router info bgp
C.get system interface
D.get system sdwan member
AnswerA

Provides real-time health data for SLA probes.

Why this answer

The command 'diagnose sys sdwan health-check' shows the status of configured health checks and member reachability.

127
MCQmedium

Which FortiGate feature allows you to bypass SSL inspection for specific known-trusted websites to maintain user privacy?

A.URL Filter category exemption
B.Firewall address object
C.Application Control override
D.IPS signature exclusion
AnswerA

Exempting categories like 'Finance' or 'Health' is standard practice.

Why this answer

SSL Inspection Exemptions allow bypassing decryption for specific categories or domains.

128
MCQeasy

Which FortiGate feature is used to group multiple physical interfaces for redundancy at Layer 2?

A.Loopback interface
B.802.3ad Aggregate
C.SD-WAN
D.VLAN tagging
AnswerB

This provides port-channel functionality.

Why this answer

802.3ad Link Aggregation (LACP) is the standard for binding physical ports into a single logical interface.

129
MCQhard

Which feature allows an administrator to offload SSL inspection to the hardware?

A.CP offloading
B.Flow-based inspection
C.IPS engine offloading
D.NP6 offloading
AnswerA

The Content Processor (CP) offloads encryption/decryption.

Why this answer

The FortiASIC CP (Content Processor) hardware chips are specifically designed to offload CPU-intensive tasks like SSL/TLS decryption.

130
MCQeasy

Which protocol is NOT a valid option for Performance SLA probes?

A.TCP Echo
B.UDP Broadcast
C.HTTP
D.ICMP
AnswerB

UDP Broadcast is not a supported protocol for standard SD-WAN health checks.

Why this answer

FortiGate supports ping (ICMP), TCP echo, HTTP, and Two-Way Active Measurement Protocol (TWAMP).

131
Multi-Selectmedium

Which TWO criteria can be used in SD-WAN rules to select an outgoing interface?

Select 2 answers
A.The name of the administrator
B.System temperature
C.Device serial number
D.Source and destination address
E.Application or service type
AnswersD, E

Address objects are key criteria.

Why this answer

Rules use criteria like source/destination address, services, and application signatures to steer traffic.

132
Multi-Selecthard

Which TWO of the following can be used as a 'Source' in an SD-WAN rule?

Select 2 answers
A.Source IP address object.
B.SLA target name.
C.Interface MAC address.
D.Firewall policy ID.
E.User group.
AnswersA, E

Standard match criteria.

Why this answer

SD-WAN rules can match traffic based on source IP addresses or specific user groups.

133
MCQeasy

Where are SD-WAN zones managed in the FortiGate GUI?

A.Interface > Physical Interfaces.
B.System > Network > Zones.
C.Firewall > Policy > Objects.
D.Network > SD-WAN > SD-WAN Zones.
AnswerD

Correct menu path.

Why this answer

SD-WAN zones are created and managed under the Network > SD-WAN menu.

134
MCQmedium

Which FortiManager feature allows an administrator to test policy changes in a sandbox environment before applying them to production FortiGates?

A.Policy Testing Mode
B.Policy Package Cloning/Revision History
C.Global Policy Lockdown
D.Device Manager Simulation
AnswerB

Cloning allows for safe testing of changes.

Why this answer

The 'Revision History' or 'Policy Package cloning' allows admins to modify and verify changes before pushing them to the production devices.

135
MCQeasy

An administrator wants to view the active SD-WAN rule hit counts and verify which traffic is matching a specific SD-WAN rule in FortiOS. Which command should be used?

A.show system sdwan
B.execute router clear sdwan cache
C.get firewall policy statistics
D.diagnose sys sdwan service
AnswerD

Correct. This diagnostic command displays the configured SD-WAN rules (services), their hit counts, and current status.

Why this answer

To view runtime statistics and hit counts for SD-WAN rules, the command 'diagnose sys sdwan service' is used.

136
Multi-Selectmedium

Which TWO actions should be taken when preparing to upgrade a FortiGate HA cluster?

Select 2 answers
A.Review release notes
B.Clear all sessions
C.Backup the configuration
D.Disable heartbeat interfaces
E.Change HA mode to Standalone
AnswersA, C

Crucial for known issues and upgrade paths.

Why this answer

A configuration backup is mandatory, and checking the release notes for firmware-specific HA behavior is critical for a smooth upgrade.

137
Multi-Selecthard

An administrator troubleshoots a scenario where traffic matching an application-based SD-WAN rule is bypassing the preferred high-speed MPLS tunnel and taking the backup broadband tunnel instead. Which THREE factors should the administrator check to resolve this routing discrepancy? (Choose three)

Select 3 answers
A.Verify the FortiGate factory default administrator password is changed
B.Check the physical layer OSI Model cable category connected to the FortiGate port
C.Inspect the member priorities and weights configured within the specific SD-WAN rule
D.Verify whether the preferred MPLS member is failing the configured performance SLA thresholds, causing the SD-WAN engine to disqualify it
E.Check the sequence order of the SD-WAN rules; an earlier rule might be matching the traffic first
AnswersC, D, E

Correct. Member priorities and weights determine selection order among qualifying links in the SD-WAN rule.

Why this answer

When an SD-WAN rule bypasses preferred paths, potential causes include SLA health check failure (the preferred link fails the SLA threshold), incorrect rule evaluation order (an earlier rule matches first), or interface priority/weight settings within the rule. Checking these three areas is standard practice.

138
MCQhard

An IPsec VPN tunnel used as an SD-WAN member is experiencing intermittent flapping due to DPD (Dead Peer Detection) timeout issues over a high-latency satellite link. How should the administrator adjust the Phase 1 IPsec settings on FortiOS to stabilize the tunnel without completely disabling failure detection?

A.Disable DPD entirely so the FortiGate never tears down the tunnel
B.Enable NP6/NP7 hardware offloading for Phase 1 SA renegotiation
C.Change the IPsec phase 1 mode from Main mode to Aggressive mode
D.Increase the DPD retry count and interval settings under the IPsec Phase 1 configuration
AnswerD

Correct. Increasing the DPD interval and retry count gives the satellite link more time to respond to liveness probes, preventing unnecessary flapping.

Why this answer

On high-latency or high-jitter links like satellite connections, the default DPD retry count and interval may be too aggressive. Increasing the DPD retry count and/or interval or switching the DPD mode to 'on-idle' or 'on-demand' helps prevent false drops.

139
MCQeasy

How do you apply an SD-WAN template to multiple managed FortiGates simultaneously?

A.By manually editing each FortiGate config
B.By assigning the template in the Device Manager tab
C.Through individual CLI console sessions
D.By creating a global profile
AnswerB

Templates are assigned to devices via the Device Manager UI.

Why this answer

In the Device Manager tab, you can assign an SD-WAN template to multiple devices by selecting them and applying the template.

140
MCQhard

An SD-WAN rule is configured with 'Lowest Cost (SLA)' strategy. If all members in the SLA meet the requirements, how does the FortiGate select the outgoing interface?

A.The member with the lowest interface cost value defined in the SD-WAN member configuration.
B.Round Robin
C.The interface with the highest bandwidth.
D.The interface that was most recently added to the zone.
AnswerA

Lowest cost strategy specifically uses the manual cost value.

Why this answer

In 'Lowest Cost (SLA)' mode, the FortiGate selects the member with the lowest configured cost that meets the SLA requirements.

141
Multi-Selecthard

Which THREE factors influence log storage efficiency on a FortiAnalyzer/FortiManager?

Select 3 answers
A.Log compression settings
B.Log retention days
C.The firewall firmware version
D.Disk quota for specific devices
E.The number of active users
AnswersA, B, D

Compression reduces storage footprint.

Why this answer

Log compression, log retention settings, and disk quota management determine how long logs persist and how much space they consume.

142
MCQeasy

Which feature in FortiManager allows you to monitor SD-WAN performance across all managed FortiGates?

A.Device Manager
B.Log View
C.Dashboard > SD-WAN Monitor
D.Policy & Objects
AnswerC

This provides unified visibility into SD-WAN metrics.

Why this answer

SD-WAN Monitor within FortiManager provides visibility into performance metrics for all managed SD-WAN devices.

143
Multi-Selecthard

Which THREE conditions must be met for a successful Inter-VDOM link?

Select 3 answers
A.IP addresses in the same subnet
B.One side is in a different VDOM
C.Hardware acceleration must be disabled
D.The link must be added to a policy
E.The link must be in transparent mode
AnswersA, B, D

Point-to-point links require an L3 subnet.

Why this answer

Inter-VDOM links require pairing, routing, and specific interface assignment within the relevant VDOMs.

144
MCQmedium

You are setting up an SD-WAN configuration via FortiManager. Which object type is used to group multiple WAN interfaces for SD-WAN member assignment?

A.IP Pool
B.Virtual Wire Pair
C.SD-WAN Zone
D.Interface Group
AnswerC

Zones allow grouping of SD-WAN members.

Why this answer

The 'SD-WAN Zone' object is used in FortiManager to group multiple interfaces together for use in SD-WAN policies.

145
MCQeasy

What is the purpose of the 'Any' interface in a firewall policy?

A.To force traffic through the hardware switch
B.To bypass the routing table
C.To match traffic only on the WAN port
D.To match traffic regardless of the ingress or egress interface
AnswerD

'Any' is a wildcard for interface matching.

Why this answer

The 'Any' interface enables the policy to match traffic originating from or destined to any physical or logical interface on the FortiGate.

146
MCQeasy

Where can an administrator check the status of the connection between a FortiGate and FortiManager?

A.Log View
B.Device Manager
C.Policy & Objects
D.System Settings
AnswerB

Device Manager shows connectivity status.

Why this answer

The 'Device Manager' page lists all managed devices and displays their status (e.g., 'Up', 'Down', 'Synchronized').

147
MCQhard

An administrator is troubleshooting an issue where hardware acceleration is not working after upgrading firmware. Which command identifies if the NP configuration has changed?

A.diag hardware npu np6 port-list
B.config system npu
C.diagnose firewall npu
D.get hardware status
AnswerA

This allows verification of the port-to-NPU mapping.

Why this answer

'diag hardware npu np6 port-list' or similar status commands help verify the current operational state and mapping of physical ports to NPU cores.

148
MCQmedium

In a site-to-site VPN, you need to allow traffic initiated from the remote site. What configuration is essential on the local FortiGate?

A.An IPSec phase 3 policy
B.A static route to the remote subnet
C.A firewall policy allowing traffic from the VPN zone to the Internal zone
D.A NAT rule for the remote subnet
AnswerC

This policy enables the inbound connection flow.

Why this answer

A local firewall policy must exist to permit traffic arriving from the VPN interface and destined for the internal network.

149
Multi-Selectmedium

An administrator is configuring SD-WAN rules with performance SLAs. Which TWO strategies are available in FortiOS when configuring an SD-WAN rule based on SLA metrics? (Choose two)

Select 2 answers
A.Lowest Cost (SLA)
B.Priority
C.Round-Robin DNS Load Balancing
D.Dynamic BGP AS-Prepending
E.Static Flow-Hashing
AnswersA, B

Correct. Lowest Cost (SLA) selects the path with the best metric that meets the SLA threshold.

Why this answer

FortiOS SD-WAN rule strategies include Lowest Cost (SLA), Max Bandwidth, Service-ID, Volume, and Priority. Among these, Priority and Lowest Cost (SLA) are standard strategy options utilizing SLA performance metrics.

150
MCQhard

You are troubleshooting a scenario where an SD-WAN template is not pushing to a FortiGate. Which log file on the FortiManager is most useful to identify the specific CLI command causing the failure?

A.fmg_event.log
B.fmg_debug.log
C.fmg_audit.log
D.fmg_system.log
AnswerB

This log contains detailed task execution and CLI command push history.

Why this answer

The fmg_debug.log or the task monitor logs show the specific CLI commands being pushed and the FortiGate response.

Page 1

Page 2 of 3

Page 3

All pages