Courseiva

Fortinet NSE 7 Advanced Security NSE7 (NSE7) — Questions 1–75

718 questions total · 10pages · All types, answers revealed

Page 1 of 10

Page 2
1
MCQhard

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a specific physical interface to a non-management VDOM and ensure that the interface is not visible or configurable from other VDOMs. The interface is currently assigned to the root VDOM. What is the correct procedure to reassign the interface to VDOM-1?

A.In the global configuration, directly change the interface's VDOM to VDOM-1; the FortiGate automatically deletes all references in the root VDOM.
B.In the root VDOM, remove all references to the interface (such as firewall policies and routing entries), then use the global configuration to set the interface's VDOM to VDOM-1.
C.From VDOM-1, use the command 'config system interface' and edit the interface, then set its VDOM to VDOM-1. The FortiGate automatically removes it from the root VDOM.
D.Create a new VDOM link between the root VDOM and VDOM-1, then bridge the physical interface to the VDOM link so that VDOM-1 can use it without reassigning the interface.
AnswerB

To move a physical interface from one VDOM to another, you must first remove any configuration that references the interface in its current VDOM, such as firewall policies, routes, and DHCP server settings. Then, in the global configuration, you can change the interface's VDOM assignment. This ensures that the interface is cleanly detached before being reassigned. After reassignment, the interface becomes visible only in the target VDOM.

Why this answer

Reassigning a physical interface to a different VDOM requires removing all references to that interface in its current VDOM, such as firewall policies, routes, and DHCP settings. Once the interface is free of references, you can change its VDOM assignment in the global configuration. This process ensures that the interface is cleanly moved and becomes exclusively available to the target VDOM, maintaining proper isolation between VDOMs.

Exam trap

The trap here is thinking that changing the VDOM assignment automatically cleans up references or that you can edit the interface from the target VDOM, when in fact you must manually remove references from the current VDOM first.

2
MCQmedium

An administrator is troubleshooting why a FortiGate is not applying the expected application control profile to traffic from a specific subnet. The administrator wants to verify which application signature is matching a live session in real time. Which CLI command should be used to display the application name and category for active sessions?

A.diagnose sys session filter clear
B.diagnose firewall iprope list
C.diagnose sys session list
D.diagnose debug application ipsmonitor -1
AnswerC

This command lists all active sessions and includes the application name and category if application control is inspecting the session. It provides real-time visibility into which application signature matched, allowing the administrator to confirm whether the correct profile is applied. It is the standard tool for session-level troubleshooting on FortiGate.

Why this answer

The administrator needs to see the application name and category for active sessions. The diagnose sys session list command provides detailed session information, including application identification when application control is enabled. This allows real-time verification of which signature is matching, confirming whether the correct application control profile is applied to the subnet's traffic.

Exam trap

The trap here is assuming that any diagnose debug command will show application identification, when only session listing commands provide that level of detail.

3
MCQeasy

What is the purpose of BFD (Bidirectional Forwarding Detection) in a FortiGate routing configuration?

A.To encrypt routing protocol traffic
B.To detect forwarding path failures quickly
C.To authenticate routing peers
D.To provide load balancing across multiple paths
AnswerB

BFD sends sub-second control packets over the forwarding path, so FortiGate can tear down a failed route or adjacency far faster than routing protocol hellos allow. This satisfies the stem's requirement for rapid failure detection, enabling quicker reconvergence than standard dead-interval timers.

Why this answer

BFD (Bidirectional Forwarding Detection) provides fast failure detection for forwarding paths between two adjacent routers, independent of any routing protocol. In FortiGate configurations, BFD is used to detect link or neighbor failures in sub-second intervals (e.g., 50-100 ms), enabling rapid convergence for dynamic routing protocols like OSPF or BGP. This is critical for SD-WAN and high-availability scenarios where traditional keepalive timers (e.g., OSPF Hello/Dead intervals of 10-40 seconds) are too slow.

Exam trap

The trap here is that candidates confuse BFD's role in fast failure detection with routing protocol features like authentication or encryption, or mistakenly think BFD itself provides load balancing, when in fact it only monitors path liveliness and triggers convergence.

How to eliminate wrong answers

Option A is wrong because BFD does not encrypt routing protocol traffic; encryption is handled by protocols like IPsec or authentication mechanisms within routing protocols (e.g., OSPF MD5 authentication). Option C is wrong because BFD does not authenticate routing peers; authentication is a separate feature of routing protocols (e.g., BGP MD5 password or OSPF authentication) and BFD itself has no authentication mechanism. Option D is wrong because BFD is a detection mechanism, not a load-balancing tool; load balancing across multiple paths is achieved by ECMP (Equal-Cost Multi-Path) routing or SD-WAN rules, while BFD simply detects failures on those paths.

4
MCQeasy

An administrator wants to use a FortiGate to manage FortiSwitch units via the LAN. Which interface configuration is required on the FortiGate to allow this management?

A.The interface must have 'set role lan' configured
B.The interface must be configured as a 'trunk' mode to connect to the FortiSwitch
C.The interface must be a member of a VDOM
D.The interface must have 'set type switch' enabled
AnswerD

Correct. Setting 'set type switch' enables FortiLink, allowing the FortiGate to manage connected FortiSwitch units.

Why this answer

The interface must have 'set type switch' enabled to manage FortiSwitch units. This configuration sets the interface as a FortiLink port, enabling automatic discovery, provisioning, and management of FortiSwitch devices. Trunk mode is not required; in fact, setting the interface as a trunk (set mode trunk) is for aggregating multiple ports or carrying multiple VLANs but does not enable FortiLink control protocols.

Therefore, option D is correct.

Exam trap

The trap is that candidates often assume that a trunk port is needed to carry multiple VLANs, but for FortiSwitch management, the interface must be configured as a switch type to enable FortiLink.

How to eliminate wrong answers

Option A is wrong because 'set role lan' is a generic interface role used for regular LAN access, not for FortiSwitch management; FortiLink requires a trunk interface to handle multiple VLANs and control protocols. Option C is wrong because while the interface can be a member of a VDOM, VDOM membership is not a requirement for FortiSwitch management—FortiLink works in both VDOM and non-VDOM modes. Option D is wrong because 'set type switch' is not a valid FortiGate interface command; FortiGate interfaces are typically physical, VLAN, or aggregate types, and FortiSwitch management uses a trunk interface, not a switch-type interface.

5
MCQeasy

Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?

A.FortiSandbox
B.FortiEDR
C.FortiDeceptor
D.FortiClient
AnswerC

FortiDeceptor deploys decoys and lures across network segments, mimicking real assets to attract attackers. Any interaction with these decoys generates high-fidelity alerts on lateral movement and early-stage intrusion attempts, satisfying the requirement for deception-based threat detection rather than perimeter or signature-based defence.

Why this answer

FortiDeceptor is specifically designed to deploy decoys and lures that mimic real assets (e.g., servers, endpoints, IoT devices) to attract and detect lateral movement and early-stage attacks inside the network. It uses deception technology to create a realistic attack surface, triggering alerts when an attacker interacts with a decoy, without relying on signatures or behavioral analysis.

Exam trap

The trap here is that candidates often confuse FortiDeceptor with FortiSandbox or FortiEDR because all three are part of the Advanced Threat Protection portfolio, but only FortiDeceptor focuses on deception-based detection of lateral movement rather than file analysis or endpoint response.

How to eliminate wrong answers

Option A is wrong because FortiSandbox is a threat analysis and sandboxing solution that detonates files and URLs in a controlled environment to detect unknown malware, not a deception-based tool for deploying decoys and lures. Option B is wrong because FortiEDR is an endpoint detection and response solution that monitors and responds to threats on endpoints using behavioral analysis and machine learning, not a decoy deployment system. Option D is wrong because FortiClient is a lightweight endpoint agent for VPN, web filtering, and basic antivirus, lacking the dedicated deception capabilities to deploy decoys and lures for lateral movement detection.

6
MCQeasy

An administrator needs to monitor traffic flows across multiple FortiGate devices in a Security Fabric. The administrator wants to see a unified view of all traffic, including inter-device traffic, from a single pane. Which Fortinet tool provides this capability?

A.FortiAP
B.FortiManager
C.FortiGate local logs
D.FortiAnalyzer
AnswerD

FortiAnalyzer aggregates logs and provides cross-device traffic visibility.

Why this answer

FortiAnalyzer is the correct tool because it aggregates logs and traffic data from multiple FortiGate devices within a Security Fabric, providing a unified view of all traffic, including inter-device flows. It uses the FortiTelemetry protocol to collect logs and supports the Security Fabric's topology mapping, allowing administrators to monitor cross-device traffic from a single pane of glass.

Exam trap

The trap here is that candidates often confuse FortiManager's centralized management capabilities with FortiAnalyzer's log aggregation and monitoring functions, leading them to select FortiManager for traffic visibility when it is actually designed for policy and configuration management, not real-time traffic analysis.

How to eliminate wrong answers

Option A is wrong because FortiAP is a wireless access point device that provides Wi-Fi connectivity, not a centralized log aggregation or traffic monitoring tool for multiple FortiGates. Option B is wrong because FortiManager is primarily a centralized management platform for configuration and policy deployment, not a log analysis or traffic monitoring tool; it does not provide the unified traffic view that FortiAnalyzer offers. Option C is wrong because FortiGate local logs are stored locally on each device and cannot provide a unified view across multiple FortiGates or show inter-device traffic flows.

7
MCQmedium

A FortiGate administrator is deploying ZTNA to provide access to internal applications for remote users. The administrator wants to ensure that users can only access the specific applications they are authorized for, and that the ZTNA access proxy performs authentication and authorization before forwarding traffic. Which FortiGate component must be configured to define the protected applications and the authentication rules for ZTNA access?

A.A firewall policy with the destination set to the internal application server's IP address and the action set to accept.
B.An SSL VPN portal with a tunnel mode configuration that maps internal subnets to remote users.
C.A ZTNA server configuration that includes the virtual host, server certificate, and application mappings.
D.An IPsec dial-up VPN with extended authentication configured on the phase 1 gateway.
AnswerC

The ZTNA server on the FortiGate defines the access proxy that protects internal applications. It includes the virtual host name, the server certificate used for TLS, and the application mappings that specify which internal resources are published and how they are accessed. Authentication and authorization are enforced through the ZTNA policy that references the ZTNA server, ensuring users only reach authorized applications.

Why this answer

The ZTNA server configuration on the FortiGate is the component that defines the access proxy, including the virtual host, server certificate, and application mappings for protected applications. The ZTNA policy then references this server to enforce authentication and authorization. Without the ZTNA server, there is no application-level proxy to control access, so users could not be restricted to specific applications.

Exam trap

The trap here is assuming that a standard firewall policy or SSL VPN portal can provide ZTNA application-level access control without a ZTNA server configuration.

8
MCQmedium

A FortiGate in HA active-passive mode has two VDOMs. VDOM-1 is configured for management (management VDOM). The administrator connects to the management VDOM IP to manage the device. What is a characteristic of the management VDOM?

A.It provides administrative access and is separate from data VDOMs
B.It automatically synchronizes configuration to other VDOMs
C.It must be the root VDOM
D.It can only be accessed via the console port
AnswerA

The management VDOM is a dedicated administrative VDOM that isolates management-plane traffic from the data VDOMs, so administrative access to the FortiGate is kept separate from user traffic. This satisfies the requirement to manage the HA pair without exposing data-plane interfaces.

Why this answer

In an HA active-passive setup with multiple VDOMs, a management VDOM is dedicated to administrative access (e.g., SSH, HTTPS, SNMP) and is logically separated from data VDOMs that handle production traffic. This separation ensures that management traffic does not interfere with data plane operations and that administrative access remains available even if data VDOMs experience issues. The management VDOM can be any VDOM, not necessarily the root, and its configuration is not automatically synchronized to other VDOMs.

Exam trap

The trap here is that candidates often assume the management VDOM must be the root VDOM or that it automatically syncs configurations to other VDOMs, but Fortinet explicitly separates these concepts to allow flexible administrative isolation without affecting global settings or HA synchronization.

How to eliminate wrong answers

Option B is wrong because the management VDOM does not automatically synchronize its configuration to other VDOMs; configuration synchronization in HA is handled at the system level (e.g., via FGCP), not by the management VDOM itself. Option C is wrong because the management VDOM does not have to be the root VDOM; any VDOM can be designated as the management VDOM, and the root VDOM is a separate concept used for global settings. Option D is wrong because the management VDOM can be accessed via any allowed administrative interface (e.g., network interfaces with HTTPS/SSH enabled), not only the console port; console access is just one of many possible methods.

9
MCQmedium

A FortiGate is configured to send logs to FortiAnalyzer. The administrator notices that logs are not appearing on FortiAnalyzer. Running 'diagnose log device show' shows 'connected=no'. What is the most likely cause?

A.The log rate is too high and logs are being dropped
B.The FortiGate's log buffer is full
C.The FortiGate cannot reach the FortiAnalyzer due to a network issue
D.The FortiAnalyzer license has expired
AnswerC

Connectivity failure is the primary reason for 'connected=no'.

Why this answer

The 'diagnose log device show' output showing 'connected=no' indicates that the TCP connection between the FortiGate and FortiAnalyzer (typically on port 514 for syslog or port 514/3000 for FortiAnalyzer protocol) is not established. The most likely cause is a network issue preventing the FortiGate from reaching the FortiAnalyzer, as the connection status is directly tied to Layer 3 reachability and TCP handshake completion.

Exam trap

The trap here is that candidates often confuse 'connected=no' with log delivery failures caused by high log rates or buffer issues, but the connection status is a Layer 4 TCP state indicator, not a measure of log throughput or storage capacity.

How to eliminate wrong answers

Option A is wrong because a high log rate would cause logs to be dropped or buffered locally, but the connection status ('connected=no') would still show as 'connected=yes' if the TCP session to FortiAnalyzer is up; log dropping does not affect the device connectivity state. Option B is wrong because a full log buffer would cause log loss or overwriting, but the 'connected=no' status indicates the FortiGate has not established a TCP connection to the FortiAnalyzer, which is independent of buffer utilization. Option D is wrong because an expired FortiAnalyzer license would still allow log reception and the TCP connection to remain established; the FortiAnalyzer would simply stop processing or storing logs, but the FortiGate would still show 'connected=yes'.

10
Multi-Selectmedium

Which TWO of the following are required components for a Fortinet ZTNA solution? (Select two.)

Select 2 answers
A.FortiAuthenticator
B.FortiWeb
C.FortiAnalyzer
D.FortiGate
E.FortiClient EMS
AnswersD, E

FortiGate is the ZTNA gateway.

Why this answer

FortiGate is the enforcement point in a ZTNA solution, acting as the ZTNA gateway that verifies device posture and user identity before granting access to protected applications. It terminates ZTNA tunnels from FortiClient and applies identity-based policies, making it a required component for traffic inspection and access control.

Exam trap

The trap here is that candidates often assume FortiAuthenticator is required because ZTNA involves identity, but FortiGate can handle authentication locally or via any SAML IdP, making FortiAuthenticator optional, not mandatory.

11
MCQhard

An admin creates a VDOM named 'CustomerA' with inter-VDOM link to the management VDOM. The admin wants CustomerA administrators to manage only their own VDOM. Which configuration step is required?

A.Use the 'config system admin' command and set trusthost to the admin's IP
B.Place the management VDOM and CustomerA in different administrative domains (ADOMs) in FortiManager
C.Create a new administrator and set the 'VDOM' field to 'CustomerA' and assign a profile with appropriate permissions
D.Enable admin-role override in the VDOM settings
AnswerC

Assigning the administrator's VDOM field to CustomerA scopes their login session to that VDOM alone, so they cannot view or configure the management VDOM or any other. The accompanying profile then governs which actions are permitted within CustomerA, satisfying the requirement for isolated per-VDOM administration.

Why this answer

To restrict a VDOM administrator to manage only their own VDOM, you must create a new administrator account and explicitly set the 'VDOM' field to that VDOM (e.g., 'CustomerA') and assign a profile with the necessary permissions. This ensures the admin's scope is limited to that VDOM, preventing access to the management VDOM or other VDOMs.

Exam trap

The trap here is confusing IP-based access control (trusthost) with VDOM-based administrative scoping, leading candidates to select Option A instead of understanding that VDOM assignment is the correct method to isolate admin privileges to a single VDOM.

How to eliminate wrong answers

Option A is wrong because the 'trusthost' setting restricts the source IP address from which an admin can log in, not the VDOM scope; it does not limit the admin to managing only CustomerA. Option B is wrong because administrative domains (ADOMs) are a FortiManager concept for multi-device management, not a FortiGate VDOM isolation feature; the question is about local VDOM administration on a single FortiGate. Option D is wrong because 'admin-role override' is not a standard FortiGate VDOM setting; the correct mechanism is to assign the admin to a specific VDOM via the 'config system admin' command with the 'vdom' parameter.

12
MCQeasy

What is the primary function of FortiAnalyzer's FortiView feature?

A.Centralized device configuration management
B.Scheduling and generating compliance reports
C.Real-time traffic monitoring and visualization
D.Automated remediation of security incidents
AnswerC

FortiView aggregates logs from managed FortiGate devices into dashboards and drill-down views, delivering real-time traffic monitoring and visualisation. This directly satisfies the stem's requirement for the primary function, since FortiView's purpose is presenting live and historical traffic, threat and application data graphically rather than performing configuration or policy enforcement.

Why this answer

FortiView on FortiAnalyzer provides real-time traffic monitoring and visualization by aggregating logs from FortiGate devices and displaying them in graphical dashboards. It allows administrators to instantly view top talkers, applications, threats, and other network activity without needing to run manual queries, making it the primary function for live traffic analysis.

Exam trap

The trap here is that candidates confuse FortiView's real-time monitoring with FortiManager's centralized management or FortiAnalyzer's reporting capabilities, leading them to pick Option A or B instead of recognizing that FortiView is explicitly designed for live traffic visualization.

How to eliminate wrong answers

Option A is wrong because centralized device configuration management is handled by FortiManager, not FortiAnalyzer; FortiAnalyzer focuses on log management and reporting, not pushing configuration changes. Option B is wrong because while FortiAnalyzer can generate compliance reports, that is a secondary feature of the Reports module, not the primary function of FortiView, which is specifically for real-time monitoring and visualization. Option D is wrong because automated remediation of security incidents is a function of FortiSOAR or FortiGate's automation stitches, not FortiAnalyzer's FortiView, which is read-only and does not execute actions.

13
Multi-Selecthard

An organization uses FortiAnalyzer for centralized logging. The security team wants to use playbooks to automate responses to detected incidents. Which THREE components are essential for a playbook to function?

Select 3 answers
A.Trigger
B.A report schedule
C.Conditions
D.A dashboard visualization
E.Actions
AnswersA, C, E

A playbook needs a trigger to initiate execution when a matching event or incident is detected. Without this starting condition, no automated response tasks can run, making the trigger an essential component of playbook functionality.

Why this answer

In FortiAnalyzer playbooks, the essential building blocks are the trigger, conditions, and actions. Option A (Trigger) is correct because a playbook must have an event source that initiates execution, such as a new log, incident, or event detected by FortiAnalyzer. Option C (Conditions) is correct because conditions define the matching logic or filters that determine whether the playbook should run and which path it follows.

Option E (Actions) is correct because actions specify the automated response steps the playbook performs, such as sending notifications, running CLI scripts, or creating incidents. Option B (A report schedule) is not required, since reports are separate scheduled outputs and do not drive playbook execution. Option D (A dashboard visualization) is not required, because dashboards are for display and monitoring, not for the functional logic of a playbook.

Exam trap

The trap here is that candidates often confuse 'report schedule' or 'dashboard visualization' as necessary components because they are common FortiAnalyzer features, but they are not part of the core playbook execution triad of trigger, conditions, and actions.

14
MCQmedium

A FortiGate administrator needs to integrate with FortiNAC to enforce network access control for wired and wireless devices. The administrator wants FortiNAC to dynamically assign VLANs based on the device's security posture. Which FortiNAC feature enables this?

A.DHCP fingerprinting
B.NAC policies
C.RADIUS accounting
D.SNMP traps
AnswerB

NAC policies are the rule engine that evaluates a device's security posture and host attributes, then applies the matching VLAN assignment to the switch port or wireless SSID. This satisfies the requirement for dynamic, posture-based VLAN assignment rather than static port configuration.

Why this answer

NAC policies define rules for device classification and VLAN assignment based on posture assessment results.

15
MCQhard

An administrator is troubleshooting an SD-WAN scenario where traffic from a branch office to a critical SaaS application is experiencing high latency. The SD-WAN rule uses the best quality SLA strategy. The administrator runs 'diagnose sys sdwan neighbor' and sees that both WAN links have SLA compliance above 90%. However, traffic still uses the slower link. The administrator then runs 'diagnose sys sdwan health-check list' and notices that the health-check server IP is different from the SaaS application's server IP. What is the MOST likely reason the traffic is not using the best-performing link?

A.The health-check server's IP does not match the application's destination IP, so SLA measurements are not representative
B.The SD-WAN rule is configured with 'set load-balance-mode' instead of 'best-quality'
C.The health-check server is not reachable from the faster link
D.The SD-WAN rule has a manual routing override configured
AnswerA

SLA probes measure latency to the health-check server, not the SaaS endpoint. When those IPs differ, the best quality strategy selects a link based on unrepresentative measurements, so the genuinely faster path to the application may be ignored.

Why this answer

The SD-WAN rule uses the best quality SLA strategy, which selects the link with the best SLA metrics (latency, jitter, packet loss) for the traffic. However, if the health-check server IP does not match the SaaS application's destination IP, the SLA measurements are not representative of the actual path to the application. The SD-WAN device measures performance to the health-check server, not the application server, so the link that appears best for the health-check may be worse for the actual application traffic, causing the slower link to be selected.

Exam trap

The trap here is that candidates assume high SLA compliance on both links means the best link will always be selected, but they overlook that the health-check target must match the application destination for SLA measurements to be relevant.

How to eliminate wrong answers

Option B is wrong because the question states the SD-WAN rule uses the best quality SLA strategy, so 'set load-balance-mode' is not configured; if it were, traffic would be distributed based on load balancing, not SLA quality. Option C is wrong because if the health-check server were not reachable from the faster link, the SLA would show non-compliance for that link, but the output shows both links have SLA compliance above 90%. Option D is wrong because a manual routing override would bypass SD-WAN policy entirely, but the administrator is observing SD-WAN behavior (traffic using a slower link despite SLA compliance), and the diagnostic commands confirm SD-WAN is active.

16
MCQeasy

Which FortiClient ATP feature provides protection against zero-day malware by monitoring process behavior and blocking suspicious activities at the endpoint?

A.FortiClient Web Filtering
B.FortiClient Cloud Sandbox
C.FortiClient Exploit Prevention
D.FortiClient Vulnerability Scan
AnswerC

FortiClient Exploit Prevention monitors process behaviour at the endpoint, blocking suspicious activity such as memory corruption and anomalous execution patterns. This behavioural, signature-independent approach satisfies the zero-day constraint, since unknown malware has no existing signature. It detects exploitation attempts in real time and terminates the offending process before payload execution.

Why this answer

FortiClient Exploit Prevention is correct because it uses real-time behavioral monitoring of process activities—such as API calls, memory access patterns, and code injection attempts—to detect and block zero-day malware that has no known signature. Unlike signature-based detection, this feature identifies malicious behavior at runtime, making it effective against previously unseen threats.

Exam trap

The trap here is that candidates often confuse cloud sandboxing (Option B) with endpoint behavioral protection, but FortiClient Cloud Sandbox is a separate, file-based analysis feature that does not provide real-time process monitoring on the endpoint.

How to eliminate wrong answers

Option A is wrong because FortiClient Web Filtering controls access to URLs and categorizes web traffic based on reputation and category, but it does not monitor process behavior or block suspicious activities at the endpoint. Option B is wrong because FortiClient Cloud Sandbox submits suspicious files to a cloud-based sandbox for dynamic analysis, which is a reactive, offline detection method rather than real-time behavioral monitoring on the endpoint. Option D is wrong because FortiClient Vulnerability Scan checks for missing patches and configuration weaknesses, but it does not monitor or block process-level behavior in real time.

17
MCQmedium

An administrator configures a new ADOM in FortiManager for a set of FortiGates. The administrator wants to assign meta fields to devices in this ADOM. Where should the meta fields be defined?

A.Policy & Objects -> Object configurations
B.Device Manager -> ADOM settings
C.System settings -> Admin
D.Global database objects
AnswerB

Meta fields are ADOM-scoped objects, defined under Device Manager's ADOM settings so every device in that ADOM can be tagged consistently. Defining them here satisfies the requirement to assign meta fields to devices within the new ADOM.

Why this answer

Meta fields in FortiManager are defined at the ADOM level under Device Manager -> ADOM settings. This ensures that the custom fields are available for all devices within that specific ADOM, allowing consistent metadata assignment across managed FortiGates. Defining them elsewhere, such as in global database objects, would apply them globally rather than per-ADOM, which is not the administrator's intent.

Exam trap

The trap here is that candidates may confuse ADOM-specific settings with global database objects, assuming meta fields must be defined globally for consistency, but FortiManager requires them to be defined at the ADOM level to maintain isolation between administrative domains.

How to eliminate wrong answers

Option A is wrong because 'Policy & Objects -> Object configurations' is used for managing firewall policies and shared objects, not for defining device-level meta fields. Option C is wrong because 'System settings -> Admin' deals with administrative access and user permissions, not device metadata configuration. Option D is wrong because 'Global database objects' are shared across all ADOMs and would apply meta fields globally, whereas the requirement is to assign meta fields specifically to devices in a single ADOM.

18
Multi-Selectmedium

A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Disable logging for botnet events to reduce log volume.
B.Create a firewall address for each known C2 server and manually add them to a deny policy.
C.Enable IPS signatures for known C2 protocols and set the action to monitor only.
D.Configure a DNS filter profile with FortiGuard category filtering and block malicious categories.
E.Enable the botnet database in the antivirus profile and set the action to block.
AnswersD, E

DNS filtering with FortiGuard category filtering can block DNS resolutions for known malicious domains, preventing hosts from reaching C2 servers by domain name. This complements IP-based botnet blocking and helps stop C2 that uses domain names. It is an effective action for identifying and blocking C2 communication at the DNS layer.

Why this answer

To detect and block C2 traffic, the administrator should enable the botnet database with a block action in the antivirus profile and configure DNS filtering to block malicious categories. These two actions provide both IP-based and domain-based blocking of C2 communication, and they leverage FortiGuard threat intelligence. Together they help identify infected hosts and prevent them from reaching C2 infrastructure.

Exam trap

The trap here is selecting monitor-only IPS or manual deny policies instead of using the automated, intelligence-driven botnet database and DNS filtering that are designed for C2 blocking.

19
MCQhard

A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?

A.Firewall policy on FortiGate
B.Device control policy
C.Application control policy
D.Playbook with network isolation action
AnswerD

FortiEDR playbooks allow automated responses to threats. A playbook can include a network isolation action that blocks all network traffic except communication with the FortiEDR management server. This ensures the endpoint is contained while still allowing updates and remediation. This feature meets both requirements: automatic isolation and continued management connectivity. It is the correct choice for automated containment.

Why this answer

FortiEDR playbooks enable automated response actions, including network isolation. The isolation action blocks all network traffic except to the FortiEDR management server, allowing the endpoint to remain managed and receive remediation instructions. This satisfies the requirement of automatic isolation while preserving management connectivity.

Other options like application control, device control, or FortiGate policies do not provide the same integrated, automated endpoint isolation capability.

Exam trap

The trap here is confusing network isolation with simply blocking malicious traffic, and assuming that external firewall policies are needed instead of FortiEDR's built-in playbook actions.

20
Multi-Selecthard

A FortiGate admin configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The admin wants traffic from VDOM-A to reach a server in VDOM-B. Which three configuration steps are required? (Choose three.)

Select 3 answers
A.Enable NAT on the VDOM link interface
B.Configure static routes pointing to the VDOM link interface on both VDOMs
C.Configure a firewall policy on VDOM-A allowing traffic to the VDOM link interface
D.Disable ARP on the VDOM link interfaces
E.Create a VDOM link and assign an interface to each VDOM
AnswersB, C, E

Each VDOM maintains its own routing table, so both VDOM-A and VDOM-B need static routes whose gateway is the VDOM link interface to reach the peer's subnets. Without these routes, traffic has no path across the link and forwarding fails.

Why this answer

Option E is correct because a VDOM link must first be created and its two ends (interfaces) assigned to VDOM-A and VDOM-B, which provides the physical/logical path for inter-VDOM traffic. Option B is correct because each VDOM needs a static route whose destination is the remote subnet and whose gateway/interface is the local VDOM link interface, so traffic is forwarded across the link. Option C is correct because FortiGate security policies are required to permit traffic between interfaces, so VDOM-A needs a policy allowing traffic from its source interface to the VDOM link interface.

Option A is not required because NAT is not needed for inter-VDOM routing when addressing is preserved; NAT could even break return-path routing. Option D is not required because ARP must remain enabled on the VDOM link interfaces for next-hop resolution.

Exam trap

The trap here is that candidates often assume VDOM links automatically route traffic between VDOMs, but they forget that each VDOM maintains its own independent routing table, so explicit static routes are mandatory for inter-VDOM communication.

21
MCQmedium

An administrator wants to use FortiExtender to provide LTE WAN connectivity. After connecting the FortiExtender to the FortiGate, the LTE interface is not showing up. What is the first troubleshooting step?

A.Run 'execute lte test' command
B.Configure an SD-WAN rule for LTE traffic
C.Verify the FortiExtender is connected to the correct port and powered on
D.Check the signal strength of the LTE connection
AnswerC

Before any FortiGate-side discovery or CAPWAP configuration can succeed, the FortiExtender must be physically cabled to the correct FortiGate port and receiving power; without link and power the LTE interface never appears, so this is the first check.

Why this answer

The first troubleshooting step is to verify the physical connection and power status of the FortiExtender. If the FortiExtender is not connected to the correct port (typically a USB or PoE port) or is not powered on, the FortiGate will not detect the LTE interface at all, making any software-level checks premature.

Exam trap

The trap here is that candidates jump to software-level troubleshooting (like running diagnostic commands or checking signal strength) without first confirming the basic physical connectivity and power status of the FortiExtender.

How to eliminate wrong answers

Option A is wrong because 'execute lte test' is a diagnostic command that requires the LTE interface to already be present and operational; running it before verifying physical connectivity will fail or return irrelevant errors. Option B is wrong because configuring an SD-WAN rule for LTE traffic assumes the LTE interface is already recognized and available, which is not the case here. Option D is wrong because checking signal strength presupposes that the LTE interface is up and has established a connection to the cellular network, which cannot happen if the FortiExtender is not physically connected or powered.

22
MCQeasy

A network administrator runs 'get system ha status' on a FortiGate HA cluster and sees that only one unit shows as primary. The secondary unit shows as 'standalone' with no HA peer detected. What is the MOST likely cause of this issue?

A.The cluster serial numbers do not match
B.The heartbeat interface is down or misconfigured
C.The HA group ID is different on each unit
D.The HA priority on the secondary unit is set to 0
AnswerB

A secondary showing standalone means it never received HA heartbeat packets, so the cluster never formed. Heartbeat interfaces must be correctly cabled and configured on both units; if that link is down or mismatched, the peer is undetectable, producing exactly this split state.

Why this answer

When a secondary unit shows as 'standalone' with no HA peer detected, it indicates that the heartbeat communication between the two FortiGate units has failed. The most common cause is that the heartbeat interface is down, misconfigured, or not physically connected, preventing the units from discovering each other as HA peers. Without a functioning heartbeat link, the secondary unit cannot join the cluster and remains in standalone mode.

Exam trap

The trap here is that candidates often confuse 'no HA peer detected' with configuration mismatches like serial numbers or group IDs, but those mismatches still allow peer detection and generate specific error messages, whereas a failed heartbeat link results in a complete lack of peer visibility.

How to eliminate wrong answers

Option A is wrong because mismatched serial numbers would cause the units to reject each other as valid HA members, but the secondary unit would still detect the peer and show an error or 'mismatch' status, not 'standalone'. Option C is wrong because a different HA group ID would prevent the units from forming a cluster, but the secondary unit would still see the peer and report a group ID mismatch, not a 'no HA peer detected' state. Option D is wrong because setting the HA priority to 0 on the secondary unit would not prevent it from detecting the primary; it would simply make the secondary unit ineligible to become primary, but it would still join the cluster and show as a secondary member.

23
MCQeasy

An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is accessed via HTTPS. Which component must be configured on the FortiGate to act as a reverse proxy for the application?

A.FortiClient EMS
B.SSL-VPN portal
C.ZTNA proxy
D.ZTNA inline CASB
AnswerC

The ZTNA proxy on the FortiGate terminates the HTTPS session and acts as a reverse proxy, inspecting and forwarding traffic to the internal application. This satisfies the requirement for brokered access without exposing the app directly.

Why this answer

The ZTNA proxy is the FortiGate component that acts as a reverse proxy for HTTPS applications in a ZTNA deployment. It terminates the client's TLS connection, authenticates the user via FortiClient EMS tags or certificates, and then proxies the request to the internal application, enforcing zero trust access policies. This is distinct from SSL-VPN, which provides network-level access rather than application-level reverse proxy.

Exam trap

NSE7 often tests the distinction between ZTNA proxy and SSL-VPN, as candidates may confuse network-level access with application-level reverse proxy functionality.

How to eliminate wrong answers

Option A is wrong because FortiClient EMS is the endpoint management server that provides ZTNA tags and compliance status, not the reverse proxy itself. Option B is wrong because SSL-VPN portal provides remote network access via a tunnel, not application-level reverse proxy for ZTNA. Option D is wrong because ZTNA inline CASB is used for SaaS application visibility and control, not for proxying internal HTTPS applications as a reverse proxy.

24
MCQmedium

An administrator configures BGP route advertisement but the routes are not being sent to the neighbor. The BGP session is established. What is the MOST likely cause?

A.The BGP administrative distance is set too high
B.The BGP neighbor has the wrong update-source interface
C.The route is filtered by a route-map
D.The 'network' statement is missing for the desired prefix
AnswerD

In BGP, the 'network' statement is what injects a prefix from the routing table into BGP for advertisement. Without it, no matching route is originated, so the established session carries no updates for that prefix to the neighbour.

Why this answer

The BGP session is established, so Layer 3 connectivity and TCP port 179 are working. The most common reason for routes not being advertised to a neighbor is that the 'network' statement is missing for the desired prefix. In BGP, the 'network' command does not advertise the prefix unless it matches an exact route in the IP routing table; without it, BGP has no prefix to send, even if the session is up.

Exam trap

The trap here is that candidates often assume a BGP session being established guarantees route advertisement, but BGP requires explicit 'network' statements or redistribution to inject prefixes, and the session state only indicates TCP connectivity and BGP open message exchange.

How to eliminate wrong answers

Option A is wrong because BGP administrative distance (e.g., 20 for eBGP, 200 for iBGP) affects route preference in the routing table, not the advertisement of routes to a neighbor. Option B is wrong because the update-source interface only affects the source IP of BGP packets; if the session is already established, the update-source is correctly configured, so it cannot be the cause of missing route advertisements. Option C is wrong because while a route-map can filter routes, the question states the session is established and routes are not being sent; a missing 'network' statement is a more fundamental and likely cause than a route-map, which would require explicit configuration to block routes.

25
Multi-Selectmedium

An administrator is troubleshooting high CPU usage on a FortiGate. The administrator suspects that a specific process is causing the issue. Which TWO commands should the administrator use to identify the top CPU-consuming processes? (Choose two.)

Select 2 answers
A.get system performance status
B.diagnose sys top-summary
C.diagnose sys session list
D.diagnose sys top
E.diagnose hardware sysinfo memory
AnswersB, D

The 'diagnose sys top-summary' command provides a summary of CPU usage by process, showing the top consumers in a concise format. It is ideal for quickly identifying which processes are using the most CPU without the interactive display of 'diagnose sys top'. This command is specifically designed for performance troubleshooting.

Why this answer

To identify the top CPU-consuming processes, the administrator should use commands that provide per-process CPU usage. 'diagnose sys top' offers an interactive real-time view, while 'diagnose sys top-summary' provides a concise summary. Both are effective for pinpointing the process responsible for high CPU.

Exam trap

The trap here is assuming that general system performance commands like 'get system performance status' provide per-process CPU details, when they only give overall statistics.

26
MCQeasy

A network administrator wants to delegate management of a specific VDOM to a junior administrator. The junior should be able to modify firewall policies and objects within that VDOM but not change system settings or other VDOMs. Which administrative access configuration meets this requirement?

A.Place the VDOM in transparent mode to allow full access
B.Create a RADIUS user that is assigned to the VDOM group
C.Use the management VDOM feature to assign the junior admin to the VDOM
D.Create a local user with an admin profile that has permissions for that VDOM only
AnswerD

A local user bound to an admin profile scoped to a single VDOM grants read-write access to that VDOM's firewall policies and objects, while denying system settings and other VDOMs. This satisfies least-privilege delegation exactly as the stem requires.

Why this answer

FortiGate allows you to create a local user with an admin profile that has permissions scoped to a specific VDOM. By assigning the junior administrator to that VDOM-only profile, they can modify firewall policies and objects within that VDOM but cannot change system settings or access other VDOMs. This is the standard method for delegating VDOM-specific administrative access without granting global or multi-VDOM privileges.

Exam trap

The trap here is that candidates often confuse the management VDOM feature (which only handles management traffic routing) with VDOM-specific admin profiles, or assume that transparent mode or RADIUS group assignment inherently restricts permissions, when in fact only a properly scoped admin profile can enforce VDOM-level access control.

How to eliminate wrong answers

Option A is wrong because placing a VDOM in transparent mode changes its operational mode (layer 2 forwarding) and does not restrict administrative access; it still allows full access to the VDOM's configuration if the admin has appropriate permissions. Option B is wrong because a RADIUS user assigned to a VDOM group only controls authentication and group membership, not the specific permissions within a VDOM; the admin profile assigned to the user determines the actual access scope, and RADIUS alone does not restrict to a single VDOM. Option C is wrong because the management VDOM feature is used to centralize management traffic (e.g., SNMP, syslog) and does not delegate administrative permissions; it does not restrict a junior admin to a specific VDOM.

27
Multi-Selecthard

A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)

Select 2 answers
A.Enable 'Use External IP Block List' in the antivirus profile.
B.Set the threat feed refresh interval to 0 to disable automatic updates.
C.Configure the threat feed as an external connector of type 'IP Address'.
D.Apply the threat feed connector to the SSL inspection profile.
E.Create a firewall policy that references the dynamic address object created from the threat feed.
AnswersC, E

In FortiOS, threat feeds are configured as external connectors. For IP address feeds, the type must be 'IP Address' so that the FortiGate can parse the feed and create a dynamic address object. This object can then be referenced in firewall policies to block or allow traffic. Without the correct connector type, the feed may not be usable as an address object, and the FortiGate will not enforce policies based on the feed.

Why this answer

To use a custom threat feed for blocking, the administrator must configure an external connector of type 'IP Address' and then reference the resulting dynamic address object in a firewall policy with a deny action. The refresh interval should be set to a non-zero value for automatic updates. Other options such as antivirus block lists or SSL inspection profiles are not involved in this integration.

Exam trap

The trap here is thinking that enabling an antivirus block list option or applying the connector to SSL inspection is required, when the feed is actually enforced through a dynamic address object in a firewall policy.

28
MCQeasy

What is the purpose of FortiAnalyzer in a Fortinet security fabric?

A.To provide sandboxing and advanced threat protection
B.To act as a network firewall and IPS
C.To collect and analyze logs, generate reports, and provide visibility into security events
D.To manage and deploy configurations to FortiGates
AnswerC

FortiAnalyzer aggregates logs from FortiGate and fabric devices, then correlates them into reports and dashboards, satisfying the requirement for centralised visibility into security events. Unlike FortiManager, which handles configuration and policy deployment, FortiAnalyzer's role is analytics and retention, delivering the log analysis and reporting the stem asks about.

Why this answer

FortiAnalyzer is the centralized logging and analytics platform within the Fortinet Security Fabric. It aggregates logs from FortiGate and other Fabric devices, correlates events, generates compliance reports, and provides a single-pane-of-glass view for security monitoring and forensic analysis. This directly supports visibility and reporting, not real-time threat prevention or configuration management.

Exam trap

The trap here is confusing FortiAnalyzer with FortiManager, as both are central management tools, but FortiAnalyzer focuses on log collection and reporting, while FortiManager handles configuration deployment and policy management.

How to eliminate wrong answers

Option A is wrong because sandboxing and advanced threat protection are functions of FortiSandbox, not FortiAnalyzer; FortiAnalyzer can integrate with FortiSandbox for log correlation but does not perform sandboxing itself. Option B is wrong because network firewall and IPS are core functions of FortiGate, not FortiAnalyzer; FortiAnalyzer is a log collector and analyzer, not an inline security device. Option D is wrong because managing and deploying configurations to FortiGates is the role of FortiManager, which uses the FortiGate API and policy packages; FortiAnalyzer has no configuration deployment capabilities.

29
MCQmedium

An administrator configures a FortiGate with VDOMs and notices that the 'config vdom' command lists multiple VDOMs, but only one VDOM is shown in the 'show full-configuration' output. What is the most likely reason?

A.The administrator is in the context of a specific VDOM
B.The VDOMs are not properly synchronized
C.The VDOMs are not assigned any interfaces
D.The FortiGate is in transparent mode
AnswerA

Entering a VDOM context scopes subsequent commands to that VDOM only, so 'show full-configuration' displays just the current VDOM's configuration. The 'config vdom' listing still enumerates all defined VDOMs, explaining why multiple appear there but only one appears in the full output.

Why this answer

The 'config vdom' command lists all VDOMs configured on the FortiGate because it operates in the global context. However, 'show full-configuration' only displays the configuration of the current VDOM context. If the administrator is inside a specific VDOM (e.g., after executing 'config vdom' and 'edit <vdom-name>'), the output is scoped to that VDOM, not the global configuration.

This is a fundamental behavior of VDOM-based CLI navigation in FortiOS.

Exam trap

The trap here is that candidates assume 'config vdom' lists all VDOMs because they are all active, but they forget that 'show full-configuration' output is context-dependent and only reflects the current VDOM or global scope, not the entire device configuration.

How to eliminate wrong answers

Option B is wrong because VDOM synchronization is not relevant to CLI output scoping; synchronization affects configuration replication between HA members, not the visibility of VDOMs in 'show full-configuration'. Option C is wrong because unassigned interfaces do not prevent a VDOM from appearing in 'show full-configuration'; a VDOM without interfaces still has its own configuration block. Option D is wrong because transparent mode is a separate operational mode that does not affect VDOM listing or configuration display; a FortiGate in transparent mode can still have multiple VDOMs and the same CLI scoping rules apply.

30
MCQhard

An administrator is troubleshooting an SD-WAN setup where a specific application's traffic is not being steered according to the configured SD-WAN rule. The rule uses a performance SLA and the 'lowest-cost' strategy. The administrator runs 'diagnose sys sdwan health-check' and sees that both members are alive and meeting the SLA. However, traffic still goes over the higher-cost member. What is the most likely cause?

A.The SD-WAN rule is not matching the traffic because the source or destination criteria are incorrect.
B.The higher-cost member is configured with a lower priority value, causing it to be preferred.
C.The performance SLA is not assigned to the SD-WAN zone.
D.The 'lowest-cost' strategy is not supported for application-based rules.
AnswerA

If the SD-WAN rule does not match the traffic, the default routing or another rule will be used, which may select the higher-cost member. Even though the health-check shows both members alive, the rule must match the traffic to enforce the 'lowest-cost' selection. Incorrect match criteria are a common cause of unexpected routing.

Why this answer

When traffic does not follow the SD-WAN rule despite healthy members, the most likely cause is that the rule is not matching the traffic. This can happen if the source, destination, application, or other match criteria are misconfigured. Without a match, the FortiGate falls back to the routing table or other rules, potentially using the higher-cost member.

Administrators should verify rule match criteria and session details.

Exam trap

The trap here is assuming that healthy members guarantee rule enforcement, overlooking that the rule must first match the traffic.

31
MCQmedium

A network admin configures OSPF on a FortiGate with multiple areas, including one area that is not directly connected to the backbone (Area 0). To ensure that routes from that area are advertised into other areas, which OSPF feature must be properly configured?

A.OSPF route redistribution
B.OSPF passive interface
C.OSPF virtual-link
D.OSPF network type
AnswerC

An area lacking a direct link to Area 0 must reach the backbone through a virtual link, which tunnels OSPF adjacency across a transit area. This makes the disconnected area appear attached to Area 0, allowing its routes to be advertised into other areas.

Why this answer

OSPF virtual-links are used to connect a non-backbone area to the backbone area through a transit area. This ensures that the area has a logical path to the backbone, allowing ABRs to generate Type 3 summary LSAs and advertise routes between areas. Without proper virtual-link configuration, routes from an area not directly connected to the backbone cannot be advertised to other areas.

Exam trap

The trap is that candidates may think OSPF route redistribution is needed for inter-area routes, but OSPF internally uses ABRs to automatically generate Type 3 LSAs. Virtual-links are a specific feature to connect isolated areas to the backbone, which is necessary for inter-area routing in such topologies.

How to eliminate wrong answers

Option B (OSPF passive interface) is wrong because it prevents OSPF hello packets from being sent on an interface, suppressing neighbor discovery and route exchange, but it does not control inter-area route advertisement. Option C (OSPF virtual-link) is wrong because it is used to connect a non-backbone area to the backbone area through a transit area when a direct physical connection is missing, not to advertise routes between areas. Option D (OSPF network type) is wrong because it determines how OSPF operates on a given interface (e.g., broadcast, point-to-point) and affects neighbor formation and LSA flooding, but it does not enable inter-area route propagation.

32
MCQeasy

An administrator needs to monitor the FortiGate's CPU usage in real-time from the CLI. Which command should be used?

A.diagnose debug application httpsd
B.diagnose hardware sysinfo memory
C.get system performance status
D.diagnose sys top
AnswerD

`diagnose sys top` launches an interactive, continuously refreshing process monitor directly in the CLI, listing per-process CPU and memory consumption. This satisfies the stem's real-time requirement, unlike snapshot commands such as `get system performance status`, which report averaged or instantaneous values without live refresh.

Why this answer

'diagnose sys top' is the FortiGate CLI command that provides a real-time, top-like display of CPU usage per process, including process IDs and CPU consumption percentages. This command is specifically designed for live performance monitoring and troubleshooting from the CLI, unlike static snapshots or debug outputs.

Exam trap

The trap here is that candidates often confuse 'get system performance status' (a static snapshot) with a real-time monitoring tool, or they mistakenly think debug commands like 'diagnose debug application' are used for performance metrics instead of debugging specific daemon logs.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug application httpsd' enables debug logging for the HTTPS daemon, not CPU monitoring; it outputs verbose HTTP-related debug messages. Option B is wrong because 'diagnose hardware sysinfo memory' displays memory usage statistics (total, used, free), not CPU usage. Option C is wrong because 'get system performance status' shows a static summary of CPU, memory, and session utilization at the moment of execution, but it does not provide the real-time, continuously updating process-level view that 'diagnose sys top' offers.

33
MCQeasy

Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?

A.SPF
B.DKIM
C.FortiMail
D.DMARC
AnswerD

DMARC consumes aggregate and forensic reports from receiving mail servers, letting administrators see which sources send mail claiming their domain. This satisfies the requirement to identify unauthorised use of the domain by revealing failing alignment and authentication results.

Why this answer

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the correct answer because it specifically uses aggregate and forensic reports (DMARC reports) to provide administrators with visibility into how their email domain is being used, including unauthorized or spoofed emails. These reports are generated by receiving mail servers and sent back to the domain owner, detailing authentication results from SPF and DKIM checks, which helps identify and mitigate domain abuse.

Exam trap

The trap here is that candidates confuse DMARC's reporting and policy enforcement features with the underlying authentication mechanisms (SPF and DKIM), thinking those protocols alone provide visibility into unauthorized use, when in fact only DMARC defines the reporting format and feedback loop.

How to eliminate wrong answers

Option A (SPF) is wrong because SPF only defines which IP addresses are authorized to send mail for a domain via DNS TXT records, but it does not generate reports or provide visibility into unauthorized use. Option B (DKIM) is wrong because DKIM provides a cryptographic signature to verify email integrity and sender authenticity, but it does not produce reports on domain usage or abuse. Option C (FortiMail) is wrong because FortiMail is a secure email gateway product that can implement DMARC policies and process reports, but it is not the technology that uses DMARC reports itself; DMARC is the standard that defines the reporting mechanism.

34
MCQeasy

Which SD-WAN load balancing algorithm is best for ensuring that all traffic from a specific source-destination pair uses the same WAN link?

A.Spillover
B.Source-dest IP
C.Volume
D.Lowest-cost
AnswerB

Source-destination IP hashing maps each unique source-destination pair to a fixed WAN link, so every flow between that pair traverses the same path. This satisfies the stem's requirement for per-pair link stickiness, unlike round-robin or weighted algorithms, which distribute flows independently and would scatter a pair's traffic across multiple links.

Why this answer

Source-dest IP (B) is the correct algorithm because it uses a hash of both the source and destination IP addresses to deterministically select a WAN link. This ensures that all packets belonging to the same flow (same source-destination pair) are consistently forwarded over the same link, preserving packet order and avoiding reordering issues.

Exam trap

The trap here is that candidates often confuse 'Spillover' with a load-balancing algorithm, but Spillover is actually a bandwidth-based failover or overflow mechanism, not a deterministic per-flow hashing method.

How to eliminate wrong answers

Option A (Spillover) is wrong because it is a traffic-steering method that shifts traffic to another link only after a configured bandwidth threshold is exceeded, not a load-balancing algorithm that ensures per-flow stickiness. Option C (Volume) is wrong because it balances traffic based on the volume of data sent over each link, which can cause flows to be split across multiple links and break source-destination pair consistency. Option D (Lowest-cost) is wrong because it selects the link with the lowest cost metric (e.g., based on link quality or administrative weight), which does not guarantee that all traffic from a specific source-destination pair will use the same link; cost-based decisions can change dynamically.

35
MCQmedium

An administrator wants to group firewall objects by department (e.g., Sales, Engineering) and easily filter them in FortiManager policy packages. Which feature should be used?

A.Tags in FortiGate
B.ADOM overrides
C.Meta fields
D.Policy package folders
AnswerC

Meta fields attach custom key-value pairs to firewall objects, letting administrators tag objects by department and filter them within FortiManager policy packages. This directly satisfies the requirement to group and filter objects by department such as Sales or Engineering.

Why this answer

Meta fields in FortiManager allow administrators to define custom attributes (e.g., Department) for firewall objects. These fields can then be used to group and filter objects within policy packages, enabling efficient management by department without requiring separate ADOMs or VDOMs.

Exam trap

The trap here is that candidates may confuse meta fields with FortiGate tags, but tags are device-local and not available for filtering in FortiManager policy packages, whereas meta fields are a FortiManager-specific feature designed for cross-device object grouping.

How to eliminate wrong answers

Option A is wrong because Tags in FortiGate are local to the FortiGate device and are not synchronized to FortiManager for filtering in policy packages; they are used for object categorization on the device itself. Option B is wrong because ADOM overrides are used to manage configuration differences across ADOMs, not to group or filter objects by custom attributes like department. Option D is wrong because Policy package folders organize policy packages themselves, not individual firewall objects within a package.

36
MCQeasy

An administrator wants to enforce that only devices with antivirus software installed and up-to-date can access the corporate network. Which FortiGate feature should be used?

A.Application control profile
B.ZTNA tags and posture checks
C.IPsec VPN with pre-shared key
D.Web filtering profile
AnswerB

ZTNA posture checks inspect endpoint attributes such as antivirus presence and signature currency, then apply tags to compliant devices. FortiGate enforces access policy against those tags, so only endpoints meeting the antivirus and up-to-date requirement reach the corporate network.

Why this answer

FortiGate uses ZTNA device posture checks via FortiClient EMS to enforce endpoint compliance, such as antivirus status.

37
MCQeasy

An administrator needs to verify if a FortiGate is receiving BGP routes from a peer. Which command should the admin run to see the BGP routing table?

A.get router info routing-table bgp
B.show ip bgp
C.diagnose ip router bgp table
D.get router info bgp table
AnswerD

The get router info bgp table command displays the BGP routing table, showing prefixes learned from each peer and their attributes. This directly confirms whether routes are being received from the neighbour, satisfying the stem's requirement to verify inbound BGP advertisements.

Why this answer

'get router info bgp table' is the exact FortiOS CLI command to display the BGP routing table, showing all BGP-learned routes and their attributes. This command is specific to FortiGate's proprietary CLI syntax, which differs from Cisco IOS or generic Linux networking commands. The administrator needs this output to verify received BGP prefixes from a peer.

Exam trap

The trap here is that candidates familiar with Cisco IOS might instinctively choose 'show ip bgp' (Option B) or misremember FortiGate syntax as similar to Cisco's 'show ip bgp table', but FortiGate uses a distinct CLI structure where 'get router info bgp table' is the correct command for viewing the BGP table.

How to eliminate wrong answers

Option A is wrong because 'get router info routing-table bgp' is not a valid FortiOS command; the correct syntax for viewing the routing table filtered by BGP is 'get router info routing-table bgp' on FortiGate, but this shows the actual routing table (RIB) entries, not the raw BGP table (Adj-RIB-In). Option B is wrong because 'show ip bgp' is a Cisco IOS command, not a FortiGate command; FortiGate uses 'get' instead of 'show' and has different syntax. Option C is wrong because 'diagnose ip router bgp table' is not a valid FortiOS command; the 'diagnose' commands are for debugging and do not include a 'table' subcommand for BGP.

38
MCQmedium

An administrator wants to integrate FortiGate with an external threat intelligence feed to block known malicious IP addresses automatically. Which object should be used to consume the feed?

A.External Threat Intelligence Feed
B.IP Pool
C.Address Group
D.Security Profile Group
AnswerA

An External Threat Intelligence Feed object consumes a remote feed of malicious IP addresses and prefixes, which can then be referenced by firewall policies to block that traffic automatically. It satisfies the requirement to ingest and act on an external feed.

Why this answer

The External Threat Intelligence Feed object in FortiGate is specifically designed to consume external threat intelligence feeds (e.g., STIX/TAXII, CSV, or plain text lists) and automatically update a dynamic address object with indicators of compromise (IoCs) such as malicious IP addresses. This enables automated blocking of known malicious sources without manual intervention, making it the correct choice for integrating an external feed.

Exam trap

The trap here is that candidates often confuse the External Threat Intelligence Feed with an Address Group, thinking they can manually add IPs from a feed into a group, but FortiGate requires the dedicated feed object to automate the ingestion and dynamic updates.

How to eliminate wrong answers

Option B (IP Pool) is wrong because an IP Pool is used for source NAT (SNAT) to translate private IPs to public IPs, not for consuming threat intelligence feeds. Option C (Address Group) is wrong because an Address Group is a static or dynamic grouping of address objects used in firewall policies, but it cannot directly consume an external threat feed; it would require a separate feed object to populate it. Option D (Security Profile Group) is wrong because a Security Profile Group is a container for security profiles (e.g., antivirus, IPS, web filter) applied to policies, not a mechanism to ingest external threat data.

39
MCQeasy

A FortiGate is configured with multiple virtual routers (VRFs). The administrator wants to allow communication between two VRFs using a firewall policy. Which type of interface is required for the policy?

A.VDOM link
B.VLAN subinterface
C.Loopback interface
D.Virtual-wire pair
AnswerA

VDOM links are used to connect VDOMs or VRFs; firewall policies can be applied to allow traffic between VRFs.

Why this answer

A VDOM link is a virtual interface that connects two VDOMs (Virtual Domains) and inherently supports routing between different VRFs (Virtual Routing and Forwarding instances) within a FortiGate. When a firewall policy is applied to a VDOM link, it can control traffic flowing between the two VRFs, as the link itself is a Layer 3 interface that belongs to both VDOMs and can be assigned to different VRFs on each side. This is the only interface type that natively allows inter-VRF communication with firewall policy enforcement.

Exam trap

The trap here is that candidates often confuse VDOM links with VLAN subinterfaces, assuming that VLAN tagging alone can separate VRFs, but VLAN subinterfaces cannot cross VRF boundaries without additional routing constructs like route leaking, which is not handled by a firewall policy directly.

How to eliminate wrong answers

Option B (VLAN subinterface) is wrong because VLAN subinterfaces operate within a single VRF and cannot directly route traffic between different VRFs; they are used for segmenting traffic within the same VRF or VDOM. Option C (Loopback interface) is wrong because loopback interfaces are virtual interfaces used for management, routing protocol stability, or as tunnel endpoints, and they cannot be used to forward traffic between VRFs via a firewall policy. Option D (Virtual-wire pair) is wrong because virtual-wire pairs are transparent Layer 2 interfaces that bridge traffic without routing, and they do not support VRF separation or inter-VRF firewall policies.

40
MCQeasy

Which FortiManager feature allows an administrator to view the exact CLI commands that will be pushed to a managed FortiGate before installation?

A.Policy Check
B.Revision History
C.Device Manager Dashboard
D.Install Preview
AnswerD

Install Preview renders the exact CLI configuration FortiManager will push to the managed FortiGate, letting the administrator inspect commands before committing. Policy Package revision history and install wizard show prior or summary states, but only Install Preview exposes the precise command set for pre-installation review.

Why this answer

Install Preview is the correct answer because it allows an administrator to review the exact CLI commands that FortiManager will push to a managed FortiGate during the next installation. This feature provides a pre-installation view of the configuration changes, enabling verification before committing changes to the device.

Exam trap

The trap here is that candidates may confuse Install Preview with Revision History, thinking that viewing past configurations is the same as previewing pending changes, but Revision History only shows saved snapshots, not the upcoming installation script.

How to eliminate wrong answers

Option A is wrong because Policy Check is used to validate policy consistency and conflicts across FortiGates, not to preview CLI commands. Option B is wrong because Revision History stores previous configuration backups and allows rollback, but does not show the pending CLI commands for the next installation. Option C is wrong because the Device Manager Dashboard provides a summary view of device status and configuration, but does not display the exact CLI commands that will be pushed.

41
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGate devices. The tunnel is established, but traffic is not passing. Which configuration should the administrator check first?

A.Firewall policies
B.NAT traversal configuration
C.Static routes
D.Phase1 parameters
AnswerA

Firewall policies govern whether traffic is permitted through the tunnel; an established IPsec tunnel with no passing traffic typically indicates missing or misordered policies blocking the interesting traffic. FortiGate requires explicit policies permitting traffic between the VPN interfaces, so checking these first addresses the stem's constraint of a tunnel that is up but not forwarding data.

Why this answer

When an IPsec VPN tunnel is established but traffic does not pass, the most common cause is missing or misconfigured firewall policies. Even with correct Phase 1 and Phase 2 settings, the FortiGate will not forward traffic between the tunnel interface and the destination network unless an explicit firewall policy permits it. This is because FortiGate uses a stateful inspection model where all traffic must be allowed by a policy, regardless of the VPN being up.

Exam trap

The trap here is that candidates assume a working Phase 1 and Phase 2 automatically allows traffic, but FortiGate requires explicit firewall policies to permit traffic through the tunnel, unlike some other vendors where the VPN configuration itself implies a permit.

How to eliminate wrong answers

Option B (NAT traversal configuration) is wrong because NAT traversal is only relevant when there is a NAT device between the VPN peers; if the tunnel is already established, NAT-T is likely working or not needed, and it does not block traffic flow. Option C (Static routes) is wrong because while routes are necessary for traffic to reach the tunnel interface, the tunnel being established indicates that routing is likely correct; the issue is that even with correct routes, traffic is dropped at the policy layer. Option D (Phase1 parameters) is wrong because if Phase 1 parameters were mismatched, the tunnel would not establish at all; the fact that the tunnel is up means Phase 1 negotiation succeeded.

42
MCQhard

In a FortiManager deployment with global ADOM enabled, an administrator creates a firewall policy in the global ADOM. What is the effect of this policy on the per-ADOM devices?

A.The policy is used only if no per-ADOM policy exists with the same name
B.The policy is applied only to devices in the same ADOM as the global ADOM
C.The policy is ignored unless explicitly assigned to each ADOM
D.The policy is installed as a header policy on all managed FortiGates
AnswerD

Global ADOM policies are pushed to every managed FortiGate as header policies, positioned above each device's local policies in the policy package. This satisfies the scenario's requirement that a single global-ADOM firewall policy affects all per-ADOM devices without duplicating configuration, since header policies are evaluated first during traffic matching.

Why this answer

In FortiManager, when global ADOM is enabled, policies created in the global ADOM are automatically installed as header policies on all managed FortiGates across all ADOMs. Header policies are evaluated before per-ADOM policies, allowing global enforcement of rules. This ensures consistent security posture across the entire managed estate.

Exam trap

NSE7 often tests the misconception that global ADOM policies are optional or require manual assignment, when they are actually automatically installed as header policies on all devices.

How to eliminate wrong answers

Option A is wrong because global policies are not fallbacks; they are always applied as header policies, regardless of per-ADOM policies. Option B is wrong because global ADOM policies apply to all ADOMs, not just the one they are created in. Option C is wrong because global policies do not require explicit assignment; they are automatically pushed to all devices.

43
Multi-Selectmedium

An administrator is troubleshooting why a new firewall policy on a managed FortiGate is not taking effect. The policy was created in FortiManager and installed successfully. Which TWO steps should the administrator verify to identify the issue? (Select TWO.)

Select 2 answers
A.Reboot the FortiGate
B.Review the FortiGate's routing table
C.Check if the policy is disabled
D.Check the policy order in the policy list
E.Verify the FortiGate's HA status
AnswersC, D

A policy installed successfully can still be inactive if its status is disabled. Verifying the enabled/disabled state on the managed FortiGate confirms whether the policy is actually evaluated, directly explaining why it produces no effect.

Why this answer

Option C is correct because a policy that exists in FortiManager and installs successfully can still be administratively disabled on the managed FortiGate, in which case it will never match traffic; the administrator should confirm the policy's status is enabled. Option D is correct because firewall policies are evaluated top-down and the first matching policy wins, so if a broader or conflicting policy appears above the new policy in the policy list, the new policy will never be hit; verifying its position in the order is essential. Option A is not appropriate because rebooting the FortiGate does not resolve a policy configuration or ordering problem and would only cause unnecessary downtime.

Option B is not the right focus because routing determines whether traffic reaches the FortiGate and which interface/next-hop is used, but the scenario states the policy itself is not taking effect, not that traffic is failing to route. Option E is not relevant because HA status affects failover and session synchronization, not whether a specific installed policy matches traffic.

Exam trap

The trap here is that candidates often assume a successful installation guarantees the policy is active, overlooking the disabled state or the impact of policy order on traffic matching.

44
MCQmedium

An admin wants to create a custom IPS signature to detect a specific exploit that sends a string 'EXPLOIT' in the HTTP Host header. Which signature syntax is correct?

A.F-SBID( --name "HTTP_EXPLOIT" --protocol http --header Host --content "EXPLOIT" )
B.F-SBID( --name "HTTP_EXPLOIT" --service HTTP --header Host --content "EXPLOIT" )
C.F-SBID( --name "HTTP_EXPLOIT" --protocol tcp --header Host --content "EXPLOIT" )
D.F-SBID( --name "HTTP_EXPLOIT" --protocol http --header Host --content "EXPLOIT" )
AnswerD

This follows correct F-SBID syntax with protocol http and header Host.

Why this answer

The FortiGate custom IPS signature syntax requires the `--protocol http` flag to specify the application-layer protocol for HTTP inspection, and `--header Host` to target the HTTP Host header field. The `--content` parameter then defines the string 'EXPLOIT' to match within that header, enabling precise detection of the exploit.

Exam trap

The trap here is that candidates often confuse `--protocol tcp` with `--protocol http`, not realizing that HTTP header inspection requires the application-layer protocol keyword to enable the HTTP parser, even though HTTP traffic uses TCP as its transport.

How to eliminate wrong answers

Option A is wrong because it uses `--protocol http` (correct) but the syntax is identical to D and listed as incorrect in the question context; however, the actual error is that A is a duplicate of D and the question marks D as correct, so A is considered wrong due to the answer key. Option B is wrong because it uses `--service HTTP` instead of `--protocol http`; the `--service` flag is not a valid parameter in FortiGate IPS signatures for specifying the protocol layer, and the correct keyword is `--protocol`. Option C is wrong because it uses `--protocol tcp`, which specifies the transport-layer protocol rather than the application-layer HTTP protocol; while HTTP runs over TCP, the signature must use `--protocol http` to enable HTTP header parsing and the `--header` directive.

45
Multi-Selecthard

A security team is configuring FortiMail for email security. They want to ensure that incoming emails are authenticated using SPF, DKIM, and DMARC, and that emails failing authentication are quarantined. Which THREE settings must be configured in FortiMail? (Choose three.)

Select 3 answers
A.Enable DKIM verification in the anti-spam policy
B.Enable TLS encryption for incoming SMTP
C.Enable DMARC verification and set the action for DMARC failure to quarantine
D.Enable SPF verification in the anti-spam policy
E.Configure a recipient verification policy
AnswersA, C, D

DKIM verification must be enabled to verify DKIM signatures.

Why this answer

DKIM verification must be explicitly enabled in the anti-spam policy to allow FortiMail to validate the DKIM signature on incoming emails. Without this setting, DKIM authentication is not performed, and the email's DKIM status will not be evaluated.

Exam trap

The trap here is that candidates often confuse transport security (TLS) with email authentication protocols, mistakenly thinking TLS is required for SPF/DKIM/DMARC enforcement, when in fact TLS is optional and unrelated to the authentication chain.

46
MCQhard

An administrator is troubleshooting a ZTNA issue where users are able to authenticate but the application access is still blocked. The ZTNA status on FortiClient shows 'Connected' but the application does not load. What is the MOST likely cause?

A.The user's FortiClient does not have the required ZTNA tags assigned
B.The ZTNA application is not configured with HTTPS
C.The FortiClient EMS server is not reachable from the FortiGate
D.The FortiGate is not configured with the correct ZTNA application gateway
AnswerA

Authentication alone does not grant access; the ZTNA proxy rule matches on device tags, so a missing required tag causes the policy to deny the session despite FortiClient showing 'Connected'. Assigning the correct tag to the client restores the match and unblocks the application.

Why this answer

When users can authenticate and the ZTNA status shows 'Connected' on FortiClient, but the application still fails to load, the most likely cause is that the client lacks the required ZTNA tags. ZTNA tags are used by the FortiGate to enforce access policies; without the correct tags, the FortiGate will block the application traffic even though the tunnel is established. This scenario indicates a tag assignment or synchronization issue between FortiClient and EMS.

Exam trap

The trap here is that candidates assume a 'Connected' ZTNA status means full application access is granted, overlooking that ZTNA tags are the critical enforcer of granular access control beyond just tunnel establishment.

How to eliminate wrong answers

Option B is wrong because ZTNA applications can use any TCP-based protocol (e.g., HTTPS, SSH, RDP); HTTPS is not mandatory, and the issue is not protocol-specific. Option C is wrong because if the FortiClient EMS server were unreachable from the FortiGate, the ZTNA status would not show 'Connected' — the tunnel would fail to establish. Option D is wrong because if the FortiGate were not configured with the correct ZTNA application gateway, the user would not be able to authenticate or see a 'Connected' status; the gateway configuration is a prerequisite for the tunnel to form.

47
MCQmedium

A multi-area OSPF network includes a FortiGate as an ABR. The administrator needs to redistribute a static route into OSPF. Which command is required on the FortiGate to achieve this?

A.config router ospf config redistribute edit 'static' set status enable end
B.config router prefix-list edit 'static' set action permit end
C.config router policy set src 0.0.0.0/0 set dst 0.0.0.0/0 end
D.config router static set redistribute ospf enable end
AnswerA

The FortiGate redistributes static routes only when explicitly enabled under 'config router ospf' then 'config redistribute'. Editing the 'static' entry and setting status enable activates redistribution, injecting the static route into OSPF as an ASBR or ABR.

Why this answer

To redistribute a static route into OSPF on a FortiGate, you must enter the OSPF configuration context, navigate to the 'redistribute' subcommand, select the 'static' route type, and set its status to 'enable'. This is the standard method for enabling route redistribution from one routing protocol (or static routes) into OSPF, as defined in the FortiGate CLI reference.

Exam trap

The trap here is that candidates often confuse redistribution configuration with route filtering or policy routing, mistakenly thinking a prefix-list (Option B) or policy-based routing (Option C) is needed, or they incorrectly assume static routes have a 'redistribute' knob (Option D) instead of configuring it under the OSPF process.

How to eliminate wrong answers

Option B is wrong because a prefix-list is used for filtering route advertisements (e.g., in route maps or distribute lists), not for enabling redistribution; it does not inject static routes into OSPF. Option C is wrong because 'config router policy' configures policy-based routing (PBR) to override the routing table for specific traffic, not OSPF redistribution. Option D is wrong because 'config router static' does not have a 'set redistribute ospf enable' command; redistribution is configured under the OSPF process, not under static routes.

48
MCQmedium

An administrator sees the following log entry: 'id=13593 msg="CDR: File attachment sanitized"' Which feature generated this log?

A.Content Disarm and Reconstruction
B.FortiSandbox
C.Machine Learning Engine
D.Outbreak Prevention
AnswerA

CDR strips active content from files and rebuilds them, so the "sanitized" message confirms Content Disarm and Reconstruction generated the entry. The log's id=13593 and explicit "CDR" prefix map directly to that feature, satisfying the stem's requirement to identify the source of this sanitisation event.

Why this answer

The log entry 'CDR: File attachment sanitized' is generated by Content Disarm and Reconstruction (CDR). CDR works by removing active content (e.g., macros, scripts, embedded objects) from files and rebuilding them into a safe, sanitized version. This is distinct from sandboxing or machine learning, as CDR does not rely on detection but instead proactively neutralizes threats by reconstructing the file.

Exam trap

The trap here is that candidates confuse the 'sanitized' action with sandboxing or ML-based detection, but CDR is a distinct proactive technology that does not rely on detection—it always sanitizes regardless of threat verdict.

How to eliminate wrong answers

Option B is wrong because FortiSandbox generates logs related to file submission, verdict (malicious/clean), and behavioral analysis, not 'CDR: File attachment sanitized' which is specific to the CDR engine. Option C is wrong because the Machine Learning Engine produces logs for ML-based detection events (e.g., 'ML: File detected as malicious'), not for file sanitization which is a static transformation process. Option D is wrong because Outbreak Prevention is a FortiGuard service that provides real-time threat intelligence and signatures, not a feature that performs file sanitization; its logs would reference outbreak alerts or signature updates, not CDR actions.

49
MCQmedium

An administrator wants to integrate a FortiExtender with a FortiGate to provide cellular WAN connectivity. Which configuration step is required on the FortiGate to use the FortiExtender as an SD-WAN member?

A.Enable BGP on the FortiExtender interface
B.Create a firewall policy allowing traffic from the FortiExtender
C.Add the FortiExtender's interface to the SD-WAN zone
D.Configure a static route pointing to the FortiExtender
AnswerC

SD-WAN selects members from interfaces assigned to the SD-WAN zone. Adding the FortiExtender's interface to that zone makes it eligible for SD-WAN rules and health checks, enabling cellular WAN participation in load balancing and failover.

Why this answer

To use a FortiExtender as an SD-WAN member, the FortiExtender's physical or logical interface must be added to the SD-WAN zone on the FortiGate. This allows the FortiGate to apply SD-WAN rules, load balancing, and SLA-based path selection to traffic traversing the cellular WAN link. Without this step, the interface remains a standard WAN interface and cannot participate in SD-WAN policies.

Exam trap

The trap here is that candidates often confuse the need for a firewall policy or static route with the SD-WAN membership requirement, but the FortiGate treats the FortiExtender interface as a local interface, so only adding it to the SD-WAN zone is necessary for SD-WAN participation.

How to eliminate wrong answers

Option A is wrong because BGP is not required on the FortiExtender interface for SD-WAN membership; SD-WAN operates at the interface level and does not mandate dynamic routing protocols. Option B is wrong because a firewall policy is needed for traffic to pass through the FortiExtender interface, but it is not a prerequisite for adding the interface to the SD-WAN zone; the SD-WAN membership is configured independently of firewall policies. Option D is wrong because a static route pointing to the FortiExtender is not required; the FortiExtender appears as a directly connected interface on the FortiGate, and SD-WAN uses the interface itself, not a next-hop route.

50
MCQhard

An administrator has a FortiGate with multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 are connected via an inter-VDOM link. The administrator wants to apply security profiles to traffic passing between the VDOMs. However, when checking the policy list in VDOM-1, no policy is shown for traffic destined to VDOM-2. What is the most likely reason?

A.The inter-VDOM link interfaces have not been assigned to a zone, so policies cannot reference them.
B.Inter-VDOM link traffic is not subject to firewall policies by default.
C.The administrator must create a policy in each VDOM that allows traffic from the inter-VDOM link interface to the destination interface.
D.The administrator is looking at the wrong VDOM; policies for inter-VDOM traffic are only visible in the root VDOM.
AnswerC

To allow and inspect traffic between VDOMs, you must create firewall policies in both VDOMs. For traffic from VDOM-1 to VDOM-2, a policy is needed in VDOM-1 (from internal to inter-VDOM link) and another in VDOM-2 (from inter-VDOM link to internal). Without these policies, traffic is dropped and no policy is shown because none exists yet.

Why this answer

Inter-VDOM traffic requires explicit firewall policies in both the source and destination VDOMs. The administrator must create a policy in VDOM-1 allowing traffic from the internal interface to the inter-VDOM link, and a corresponding policy in VDOM-2 from the inter-VDOM link to the internal interface. Without these, traffic is not allowed and no policy exists.

Exam trap

The trap here is assuming that inter-VDOM traffic is automatically allowed or that policies are only needed in one VDOM, when in fact policies are required in both VDOMs for traffic to pass and be inspected.

51
MCQmedium

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM so that it can be used for that VDOM's traffic. Which configuration step is required?

A.In the global configuration, edit the physical interface and set the VDOM to the desired VDOM.
B.Create a VLAN subinterface on the physical interface and assign the VLAN to the VDOM.
C.Use the 'set vdom' command under the interface configuration in the root VDOM.
D.In the VDOM configuration, add the physical interface to the VDOM's interface list.
AnswerA

To assign a physical interface to a VDOM, you must edit the interface in the global configuration (or within the VDOM, depending on the model) and set its VDOM attribute. This moves the interface from the root VDOM to the specified VDOM, making it available for that VDOM's policies and routing. This is the standard procedure.

Why this answer

Assigning a physical interface to a VDOM requires editing the interface in the global configuration and setting its VDOM attribute. This moves the interface to the target VDOM, where it can be used for that VDOM's traffic. Other methods like VLANs or VDOM-specific interface lists do not achieve the same result.

Exam trap

The trap here is confusing VLAN subinterfaces, which allow sharing a physical interface, with assigning the entire physical interface to a single VDOM.

52
MCQeasy

An administrator is deploying a FortiGate in multi-VDOM mode for a managed services provider. Each customer must have an isolated logical firewall with its own interfaces, policies, and administrators, and the provider wants to limit each customer administrator to only their own VDOM. Which configuration accomplishes this?

A.Use global firewall policies and global address objects shared across all customers
B.Enable virtual clustering and assign each customer to a different HA group within the cluster
C.Configure transparent mode on the FortiGate so each customer subnet is bridged independently
D.Create one VDOM per customer, assign interfaces to each VDOM, and create an administrative profile that grants access only to that customer's VDOM
AnswerD

Multi-VDOM mode plus per-VDOM administrative profiles is the standard way to give each customer an isolated logical firewall. Interfaces assigned to a VDOM cannot be used by other VDOMs, policies are per-VDOM, and an administrative profile scoped to a single VDOM restricts visibility and changes. This combination delivers the isolation and delegated administration the provider requires.

Why this answer

Multi-VDOM mode lets a single FortiGate host multiple logical firewalls, each with dedicated interfaces, policies, and routing. Pairing each customer VDOM with an administrative profile scoped to that VDOM gives the provider both traffic isolation and delegated, restricted management, which is the core MSSP deployment pattern on FortiGate.

Exam trap

The trap here is assuming transparent mode or virtual clustering alone provides tenant isolation, when actual separation and delegated administration come from per-VDOM configuration plus scoped administrative profiles.

53
MCQmedium

An administrator has a FortiGate in multi-VDOM mode. VDOM-1 is assigned to the marketing team and VDOM-2 to the finance team. The administrator wants both VDOMs to be able to reach a shared DNS server at 10.10.10.53 that sits behind the root VDOM's wan1 interface, without giving either team access to the other's traffic. Which configuration accomplishes this?

A.Configure a static route in VDOM-1 and VDOM-2 with the destination 10.10.10.53/32 and the outgoing interface set to wan1, then add a firewall policy in each VDOM allowing DNS outbound.
B.Assign wan1 as a secondary IP on VDOM-1 and VDOM-2 so both VDOMs share the same physical interface, then add a policy route on root that forwards DNS traffic to 10.10.10.53.
C.Create a VDOM link between root and VDOM-1 and another between root and VDOM-2, then add static routes in VDOM-1 and VDOM-2 pointing to the root side of their respective VDOM links, and configure firewall policies on root to allow DNS to 10.10.10.53.
D.Enable inter-VDOM routing globally and create a single VDOM link shared by VDOM-1, VDOM-2, and root, then place all three VDOMs in the same OSPF area to exchange routes to 10.10.10.53.
AnswerC

A VDOM link is a virtual point-to-point interface pair that provides Layer 3 connectivity between two VDOMs. Each team VDOM routes toward the root side of its own link, and the root VDOM applies policies permitting only DNS to the shared server. Because each VDOM has a distinct link, traffic between VDOM-1 and VDOM-2 cannot traverse directly, satisfying isolation.

Why this answer

Inter-VDOM links create a private point-to-point Layer 3 path between exactly two VDOMs. By giving each team VDOM its own link to the root VDOM and controlling traffic with root-side policies, the administrator provides selective shared-service access while preventing any direct path between the two teams. Sharing one physical interface or one VDOM link across three VDOMs is not supported and would compromise isolation.

Exam trap

The trap here is assuming a single VDOM link or a shared physical interface can serve several VDOMs, when a VDOM link is only ever a two-VDOM point-to-point pair.

54
MCQeasy

Which load balancing algorithm in SD-WAN distributes new sessions based on the source and destination IP addresses, ensuring that all sessions from a given source-destination pair go to the same member?

A.Lowest cost
B.Volume
C.Source-dest IP
D.Sessions
AnswerC

Hashing on the source-destination IP pair means every new session between the same two hosts resolves to one member, preserving session stickiness without per-session rebalancing. This satisfies the requirement that all sessions from a given source-destination pair use the same SD-WAN member.

Why this answer

The Source-dest IP algorithm in Fortinet SD-WAN uses a hash of the source and destination IP addresses to determine the outbound member for each new session. This ensures that all sessions between the same source-destination pair are consistently forwarded to the same WAN member, preserving flow affinity without requiring session-based state tracking.

Exam trap

The trap here is that candidates often confuse 'Source-dest IP' with 'Sessions' because both involve distribution, but Sessions uses round-robin and does not guarantee source-destination affinity, while Source-dest IP uses a hash to ensure consistent member selection for the same pair.

How to eliminate wrong answers

Option A is wrong because Lowest cost selects the member with the lowest measured cost (e.g., latency or jitter) for each new session, which does not guarantee that sessions from the same source-destination pair go to the same member. Option B is wrong because Volume distributes sessions based on the current traffic volume on each member, aiming to balance load rather than enforce source-destination affinity. Option D is wrong because Sessions distributes sessions in a round-robin fashion across members, which can send sessions from the same source-destination pair to different members.

55
MCQeasy

In FortiAnalyzer, which tool provides real-time traffic monitoring and allows drilling down into details such as top talkers, applications, and threats?

A.Reports
B.Incidents
C.FortiView
D.Log Viewer
AnswerC

FortiView is FortiAnalyzer's real-time monitoring console, presenting drill-down dashboards for top talkers, applications, and threats. It queries live log data, letting analysts pivot from aggregate views into specific sessions and detections, which matches the requirement for real-time traffic monitoring with detailed drill-down.

Why this answer

FortiView in FortiAnalyzer provides real-time traffic monitoring with drill-down capabilities into top talkers, applications, and threats. It aggregates data from FortiGate logs and presents it in an interactive dashboard, allowing administrators to identify and investigate network anomalies instantly without generating reports.

Exam trap

The trap here is that candidates confuse the Log Viewer's ability to display logs in real time with FortiView's purpose-built aggregation and drill-down features, leading them to select Log Viewer instead of FortiView.

How to eliminate wrong answers

Option A is wrong because Reports in FortiAnalyzer are scheduled or on-demand summaries of historical data, not real-time monitoring tools. Option B is wrong because Incidents are correlated event groupings for security analysis, not a tool for live traffic inspection. Option D is wrong because Log Viewer displays raw log entries in a tabular format without real-time aggregation or drill-down into top talkers, applications, or threats.

56
MCQeasy

A FortiGate administrator is deploying ZTNA to protect an internal application. Users connect with FortiClient, which establishes a tunnel to the FortiGate. The administrator wants the FortiGate to verify the user's identity and device posture before allowing access to the application. Which FortiGate feature performs this verification as part of the ZTNA access proxy?

A.A firewall policy with NAT enabled to hide the internal application address.
B.A virtual IP (VIP) object that maps an external address to the application server.
C.IPsec phase2 selectors that restrict traffic to the application subnet.
D.ZTNA access proxy with authentication and posture check configured on the ZTNA server.
AnswerD

The ZTNA access proxy terminates the client tunnel and enforces authentication and posture checks before forwarding traffic to the protected application. It is the component that validates the user's identity and device compliance as part of the ZTNA server configuration. This directly performs the verification the administrator requires for access to the internal application.

Why this answer

ZTNA enforcement happens at the access proxy, which is configured on the ZTNA server and performs authentication plus posture checks before allowing traffic to the internal application. It replaces traditional NAT-based publishing with identity- and compliance-aware access. Phase2 selectors, NAT, and VIP objects operate at the network layer and cannot verify user identity or device posture.

Exam trap

The trap here is equating traditional NAT or VIP publishing with ZTNA, when only the ZTNA access proxy validates identity and posture before granting application access.

57
Multi-Selectmedium

An administrator is deploying ZTNA with FortiClient EMS to secure access to a corporate web application. Which THREE components are required for a successful ZTNA deployment? (Choose three.)

Select 3 answers
A.FortiSandbox for threat analysis
B.FortiClient EMS server
C.FortiClient installed on endpoint devices
D.FortiGate configured as ZTNA access proxy
E.FortiAnalyzer for logging
AnswersB, C, D

FortiClient EMS is the management plane that issues and maintains endpoint ZTNA tags, and it synchronises those tags to the FortiGate. Without this server, the FortiGate access proxy has no authoritative source of device posture, so tag-based policy enforcement cannot occur.

Why this answer

FortiClient EMS server (B) is required because it acts as the central management and policy authority for ZTNA, handling endpoint registration, tagging, and synchronization of ZTNA configuration to FortiGates and FortiClients. FortiClient installed on endpoint devices (C) is required because it provides the endpoint identity, posture information, and ZTNA client functionality needed to establish secure tunnels to the access proxy. A FortiGate configured as ZTNA access proxy (D) is required because it enforces ZTNA policies and brokers access between endpoints and the protected corporate web application.

FortiSandbox (A) is not required for ZTNA deployment; it provides sandboxing/threat analysis and is not a core ZTNA component. FortiAnalyzer (E) is also not required; it provides logging, reporting, and analytics but ZTNA can function without it.

Exam trap

The trap here is that candidates often assume FortiSandbox or FortiAnalyzer are mandatory for ZTNA, but FortiSandbox is only needed for file inspection in advanced threat scenarios and FortiAnalyzer is purely for logging, neither of which are core to the ZTNA control plane.

58
MCQhard

A FortiGate has an IPsec VPN with a remote peer that uses IKEv2. The administrator wants to ensure that child SA rekeying uses PFS (Perfect Forward Secrecy) with Diffie-Hellman group 14. Which CLI command should the administrator configure on the FortiGate's phase 2 proposal?

A.set auto-negotiate enable; set dh-group 14
B.set pfs enable; set dhgrp 14
C.set proposal aes256-sha256 dh-group 14
D.set pfs enable; set dh-group 14
AnswerB

Phase 2 handles child SA rekeying, so PFS is negotiated there. Enabling pfs plus dhgrp 14 forces a fresh Diffie-Hellman exchange using group 14 on each rekey, delivering the forward secrecy the administrator requires for the IPsec tunnel.

Why this answer

On a FortiGate IPsec phase 2 proposal, PFS is enabled with 'set pfs enable' and the Diffie-Hellman group is specified with 'set dhgrp 14' (note the abbreviated keyword 'dhgrp', not 'dh-group'). This ensures that child SA rekeying performs a fresh DH exchange using group 14 (2048-bit MODP), providing Perfect Forward Secrecy. The 'auto-negotiate' and 'proposal' keywords belong to different configuration contexts and do not control PFS.

Exam trap

NSE7 often tests the exact FortiGate CLI keyword 'dhgrp' versus the generic 'dh-group' used by other vendors — candidates who memorize generic IPsec terminology instead of FortiOS-specific syntax pick the wrong option.

How to eliminate wrong answers

Option A is wrong because 'set auto-negotiate enable' is not the correct keyword for enabling PFS in a FortiGate phase 2 proposal, and 'dh-group' is not the FortiGate CLI keyword — the correct keyword is 'dhgrp'. Option C is wrong because 'set proposal aes256-sha256 dh-group 14' mixes phase 1 proposal syntax with a non-existent 'dh-group' keyword; the phase 2 proposal uses 'set proposal' for encryption/authentication but PFS is controlled separately. Option D is wrong because while 'set pfs enable' is correct, 'set dh-group 14' uses the wrong keyword — FortiGate uses 'dhgrp' (no hyphen) in phase 2.

59
MCQhard

A FortiGate is configured with an IPsec VPN that uses certificate-based authentication. The VPN fails to establish. The administrator checks the phase1 debug and sees the message: 'no suitable certificate found'. What is the most likely cause?

A.The peer's certificate is not trusted
B.The certificate revocation list (CRL) is outdated
C.The CA certificate is missing
D.The local certificate is not imported or does not match the certificate name
AnswerD

Certificate-based IPsec requires a local certificate whose subject or name matches the phase1 configuration. If it is absent from the FortiGate keystore, or its name differs from the one referenced in phase1, IKE cannot present a valid identity, producing the 'no suitable certificate found' error.

Why this answer

The 'no suitable certificate found' error in IPsec phase1 debug indicates that the FortiGate cannot locate a local certificate that matches the peer's expected certificate name (often the peer's ID or the configured local certificate name). This typically occurs when the local certificate is not imported or the certificate's Common Name (CN) or Subject Alternative Name (SAN) does not match the configured local ID or peer's expected identifier. Without a matching local certificate, the IKE exchange cannot proceed to authenticate the FortiGate to the remote peer.

Exam trap

The trap here is that candidates often confuse 'no suitable certificate found' with trust or revocation issues, but the error specifically points to a missing or mismatched local certificate, not problems with the peer's certificate or CA chain.

How to eliminate wrong answers

Option A is wrong because 'no suitable certificate found' refers to the local certificate not being found or matching, not the peer's certificate trust; a lack of trust in the peer's certificate would produce a different error like 'certificate validation failed' or 'untrusted certificate'. Option B is wrong because an outdated CRL would cause a certificate validation failure (e.g., 'certificate revoked' or 'CRL not checked'), not a failure to find a suitable local certificate. Option C is wrong because a missing CA certificate would prevent validation of the peer's certificate, resulting in a trust-related error, not the 'no suitable certificate found' message which is about the local certificate selection.

60
Multi-Selecthard

A FortiGate administrator is investigating a slow network performance issue. The administrator suspects that session table limits are being reached. Which TWO metrics should be monitored to confirm this? (Choose two.)

Select 2 answers
A.Interface bandwidth utilization
B.Session fail rate
C.Current session count
D.CPU usage
E.Memory usage
AnswersB, C

Session fail rate counts new sessions rejected because the session table is full. A rising fail rate directly evidences that the configured session limit is being reached, confirming the suspected cause of the slow network performance.

Why this answer

The session fail rate (B) directly indicates when the FortiGate is unable to establish new sessions because the session table is full, which is a clear symptom of hitting session table limits. The current session count (C) shows how many sessions are active; when this approaches the maximum session limit (e.g., 2 million on a FortiGate-600E), it confirms the table is near capacity. Monitoring both metrics together provides definitive evidence of session table exhaustion.

Exam trap

The NSE7 exam often tests the misconception that high CPU or memory usage directly indicates session table limits, but the trap here is that session table exhaustion is specifically confirmed by session fail rate and current session count, not by general resource utilization metrics.

61
MCQeasy

A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?

A.Sandbox Inspection
B.Machine Learning (ML) Malware Detection
C.FortiGuard Outbreak Prevention
D.Content Disarm and Reconstruction
AnswerB

The Machine Learning Malware Detection setting in the antivirus profile uses machine learning models to analyze file characteristics and behavior to identify and block unknown malware. This is exactly what the administrator needs to protect against unknown threats without relying solely on signatures. It is a built-in FortiGate feature available in the antivirus profile.

Why this answer

The Machine Learning Malware Detection setting in the FortiGate antivirus profile uses machine learning algorithms to detect and block unknown malware based on file characteristics and behavior. This provides protection against zero-day threats without relying solely on signatures, meeting the administrator's requirement.

Exam trap

The trap here is confusing machine learning malware detection with sandboxing or outbreak prevention, which are different technologies for handling unknown threats.

62
MCQhard

A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?

A.DNS filter with botnet C&C category
B.Local threat intelligence feed with automation stitch
C.Application control with custom signature
D.FortiGuard IoT detection service
AnswerB

A local threat intelligence feed can be populated with the malicious domain, and an automation stitch can be triggered by a log event to add the domain to the feed automatically. This allows FortiGate to block future connections without manual intervention. The combination of a local threat feed and automation stitch provides the dynamic blocking required, as FortiGate can update the feed based on detected events.

Why this answer

The scenario requires automatic blocking of a newly discovered malicious domain that is not categorized by FortiGuard. A local threat intelligence feed can be updated dynamically via automation stitches triggered by log events, enabling FortiGate to block the domain and similar ones. DNS filter and application control rely on static or FortiGuard-provided intelligence, and IoT detection is unrelated.

Thus, the local threat feed with automation stitch is the correct solution.

Exam trap

The trap here is assuming that FortiGuard categories automatically include all malicious domains, overlooking the need for local threat intelligence and automation to handle zero-day or uncategorized threats.

63
MCQeasy

A network administrator wants to block known malicious IP addresses using threat intelligence feeds on FortiGate. Which feature should they use?

A.FortiGuard Web Filtering
B.External Threat Intelligence
C.Application Control
D.IP Reputation
AnswerB

External Threat Intelligence lets FortiGate ingest named feeds from external sources and apply them directly in firewall policies as source or destination objects, satisfying the requirement to block known malicious IPs. Unlike local blocklists, it dynamically refreshes indicators, so newly published malicious addresses are blocked without manual updates.

Why this answer

FortiGate's External Threat Intelligence feature allows administrators to import and consume threat intelligence feeds (e.g., STIX/TAXII, CSV, or custom URLs) to block known malicious IP addresses. This is the correct feature because it is specifically designed to ingest external threat data and apply it to firewall policies for dynamic blocking, unlike the other options which serve different purposes.

Exam trap

The trap here is that candidates often confuse IP Reputation (a built-in FortiGuard service) with External Threat Intelligence (a feature for importing custom feeds), leading them to select IP Reputation when the question explicitly mentions 'threat intelligence feeds' from external sources.

How to eliminate wrong answers

Option A is wrong because FortiGuard Web Filtering is used to control access to web categories and URLs based on FortiGuard's cloud database, not to block specific IP addresses from external threat feeds. Option C is wrong because Application Control identifies and controls application traffic (e.g., Facebook, Skype) based on signatures, not IP-based threat intelligence. Option D is wrong because IP Reputation is a built-in FortiGuard service that rates IP addresses based on FortiGuard's own threat data, not a feature to import custom external threat intelligence feeds.

64
Multi-Selectmedium

An administrator is troubleshooting an IPsec VPN tunnel that establishes phase 1 but fails to establish phase 2. The phase 2 configuration shows 'set proposal aes128-sha256' on both sides. Which TWO configuration items should the administrator verify?

Select 2 answers
A.PFS (Perfect Forward Secrecy) settings
B.The local authentication method (certificate vs pre-shared key)
C.The encryption algorithm for phase 2
D.The local and remote subnets defined in phase 2 (proxy IDs)
E.The pre-shared key
AnswersA, D

If one side has PFS enabled and the other does not, or they use different DH groups, phase 2 will fail.

Why this answer

PFS ensures that if one session key is compromised, previous and future session keys remain secure by using a Diffie-Hellman exchange in phase 2. If PFS is enabled on one side but not the other, or if the DH groups do not match, phase 2 will fail even when the encryption and authentication proposals are identical. Since the phase 2 proposal 'aes128-sha256' matches on both sides, the mismatch likely lies in PFS settings.

Exam trap

The trap here is that candidates assume matching encryption and authentication proposals guarantee phase 2 success, overlooking PFS and proxy ID mismatches which are frequently tested in NSE7 troubleshooting scenarios.

65
MCQhard

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?

A.Create a firewall policy in VDOM-B that allows incoming traffic to the VDOM link interface and a policy in VDOM-A that allows traffic from the VDOM link to the server.
B.Create a central SNAT policy in VDOM-B to translate the public IP to the server's private IP, and apply it to the VDOM link.
C.Configure a VIP on VDOM-B that maps the public IP to the server's private IP, and ensure firewall policies allow the traffic in both VDOMs.
D.Enable NAT on the VDOM link interface in VDOM-B and create a static route in VDOM-A pointing to the server.
AnswerC

A VIP (Virtual IP) on VDOM-B performs destination NAT, translating the public IP to the server's private IP. Combined with firewall policies in VDOM-B (allowing incoming traffic to the VIP) and VDOM-A (allowing traffic from the VDOM link to the server), this enables access. The VDOM link carries the translated traffic between VDOMs.

Why this answer

To allow external access to a server behind a FortiGate with multiple VDOMs, a VIP must be configured on the VDOM with the public IP to perform destination NAT. Firewall policies in both VDOMs must permit the traffic, and the VDOM link carries the translated packets. Without the VIP, the server would not receive the traffic correctly.

Exam trap

The trap here is assuming that inter-VDOM routing and firewall policies alone are sufficient, overlooking the need for destination NAT via a VIP.

66
Multi-Selecteasy

A FortiGate administrator wants to monitor performance thresholds to be alerted when the firewall is under heavy load. Which THREE metrics can be monitored using the built-in performance monitoring features (e.g., 'diagnose sys top' or SNMP)?

Select 3 answers
A.CPU utilization percentage
B.Interface speed
C.Number of concurrent sessions
D.Disk space utilization
E.Memory utilization percentage
AnswersA, C, E

CPU usage is a critical performance indicator.

Why this answer

The built-in 'diagnose sys top' command and SNMP monitoring both provide real-time CPU utilization percentage, which is a key metric for detecting heavy load on a FortiGate firewall. High CPU usage can indicate resource contention, impacting packet processing and overall performance.

Exam trap

The trap here is that candidates confuse static interface properties (like speed) with dynamic performance metrics, or mistakenly think disk space is relevant to firewall load, when in fact only CPU, memory, and session counts are directly monitored for performance thresholds.

67
Multi-Selecthard

An administrator is troubleshooting an IPsec VPN Phase 2 negotiation failure. The debug shows 'no matching phase 2 proposal' from the remote peer. Which TWO of the following are likely causes? (Choose two.)

Select 2 answers
A.The local and remote proxy IDs (subnets) are not matching
B.The pre-shared key is incorrect
C.The firewall policy does not allow UDP port 500
D.The encryption algorithm (e.g., AES256 vs AES128) does not match between peers
E.The IKE version (IKEv1 vs IKEv2) is different
AnswersA, D

Phase 2 requires matching proxy IDs to establish SAs.

Why this answer

IPsec Phase 2 negotiation requires the proxy IDs (local and remote subnets) to match exactly between peers. The 'no matching phase 2 proposal' debug message indicates the remote peer received a proposal with a subnet or traffic selector that does not match its configured proxy ID. This is a common misconfiguration when defining which traffic should be encrypted over the VPN tunnel.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 parameters, incorrectly attributing a Phase 2 'no matching proposal' error to authentication or IKE version mismatches, which actually cause Phase 1 failures.

68
MCQeasy

What is the purpose of BFD on a FortiGate?

A.To load balance traffic across multiple paths.
B.To provide fast detection of link failures.
C.To authenticate OSPF neighbors.
D.To encrypt traffic between two FortiGates.
AnswerB

BFD (Bidirectional Forwarding Detection) provides sub-second detection of link failures between forwarding engines, enabling faster convergence than routing protocol timers alone. This satisfies the stem's requirement to identify its purpose on a FortiGate, which is rapid link failure detection.

Why this answer

BFD (Bidirectional Forwarding Detection) provides sub-second failure detection for routing protocols like OSPF and BGP, independent of the routing protocol's own hello timers. On a FortiGate, BFD is used to rapidly detect link or neighbor failures, enabling faster convergence in SD-WAN and dynamic routing scenarios.

Exam trap

The trap here is that candidates confuse BFD's fast failure detection with load balancing or authentication functions, but BFD is strictly a liveness detection mechanism with no role in traffic distribution or security.

How to eliminate wrong answers

Option A is wrong because BFD does not perform load balancing; load balancing is handled by ECMP (Equal-Cost Multi-Path) or SD-WAN rules, not BFD. Option C is wrong because OSPF neighbor authentication is performed using MD5 or SHA authentication keys, not BFD; BFD only monitors link liveliness. Option D is wrong because traffic encryption between FortiGates is achieved via IPsec VPN tunnels, not BFD, which is a lightweight hello-based protocol with no encryption capabilities.

69
MCQeasy

An administrator needs to isolate customer traffic in a FortiGate deployed at a service provider. Each customer should have independent administrators and security policies. Which feature should be used?

A.VLAN interfaces
B.Policy packages
C.Administrative domains (ADOMs)
D.Virtual domains (VDOMs)
AnswerD

VDOMs partition a single FortiGate into independent virtual firewalls, each with its own administrators, policies, and routing. This satisfies the service provider requirement for isolated customer traffic with separate administrative access and security policies on one appliance.

Why this answer

Virtual domains (VDOMs) allow a single FortiGate to be partitioned into multiple independent virtual firewalls, each with its own administrators, security policies, routing tables, and interfaces. This is the correct feature for isolating customer traffic at a service provider because it provides complete administrative and policy separation per customer, which VLAN interfaces alone cannot achieve.

Exam trap

The trap here is confusing VLAN interfaces (Layer 2 segmentation) with VDOMs (full virtual firewall instances), leading candidates to choose VLANs when the question explicitly requires independent administrators and security policies.

How to eliminate wrong answers

Option A is wrong because VLAN interfaces only provide Layer 2 segmentation of traffic on a physical port; they do not create independent administrative domains or separate security policy contexts. Option B is wrong because policy packages are containers for firewall policies within a single VDOM or non-VDOM mode; they do not isolate administrators or provide independent routing and management. Option C is wrong because administrative domains (ADOMs) are a FortiManager concept for managing multiple FortiGate devices centrally, not a feature on the FortiGate itself for local isolation.

70
MCQmedium

A FortiGate admin configures an automation stitch to send an email alert when a high-severity IPS event occurs. The trigger is 'IPS Event' and the action is 'Email'. After testing, no email is sent despite events being logged. What is the most likely cause?

A.The IPS event severity threshold is set too low
B.The automation stitch is disabled
C.No SMTP server is configured in the FortiGate
D.The IPS engine is in monitor mode
AnswerC

The Email action requires a configured SMTP server to relay messages; without one, the stitch fires but delivery silently fails. Events still appear in logs because logging is independent of the automation action, matching the symptom of logged IPS events with no alert email.

Why this answer

The automation stitch requires a functional SMTP server configuration to send emails. Without an SMTP server defined under System > Settings > Email Service, the FortiGate cannot relay the alert email, even if the trigger and action are correctly configured and events are logged. This is the most common reason for email delivery failure in automation stitches.

Exam trap

The trap here is that candidates assume the automation stitch is misconfigured or the IPS engine is blocking the event, when the real issue is the underlying email infrastructure (SMTP) that the action depends on, which is a separate configuration from the stitch itself.

How to eliminate wrong answers

Option A is wrong because a low severity threshold would cause more events to match, not prevent email sending; the issue is delivery, not triggering. Option B is wrong because if the stitch were disabled, no events would be logged as triggered by the stitch, but the question states events are logged, implying the stitch is enabled and triggering. Option D is wrong because monitor mode affects IPS action (e.g., whether packets are blocked), not the generation of IPS events or the ability to send email alerts.

71
Multi-Selectmedium

A network administrator is troubleshooting a split-brain scenario in an HA cluster. Which TWO conditions can cause split-brain? (Choose two.)

Select 2 answers
A.Loss of heartbeat link between HA members
B.One unit has a higher priority
C.Firmware version mismatch
D.Mismatched HA configuration (e.g., different HA mode)
E.Session pickup is disabled
AnswersA, D

Loss of the heartbeat link severs the dedicated HA communication path, so each FortiGate independently concludes the peer has failed and transitions to primary. Both devices then hold the same IP addresses and MAC addresses, producing the duplicate-active condition the stem describes. This satisfies the split-brain cause directly.

Why this answer

Options A and D are correct. Loss of HA heartbeat communication (A) causes both units to think they are primary. Mismatched HA configuration (D) can also cause split-brain.

Option B causes failover but not split-brain. Option C is irrelevant.

72
MCQhard

An administrator manages a FortiGate 500E with multiple VDOMs. The administrator needs to configure a new VDOM named 'Partner' and ensure that the Partner VDOM can use a dedicated physical interface for WAN connectivity. The FortiGate has an unused interface 'port5'. The administrator wants to assign port5 to the Partner VDOM and configure it with an IP address. Which sequence of steps is correct?

A.In the global configuration, edit port5 and set its VDOM to 'Partner'. Then, within the Partner VDOM, configure the IP address on port5.
B.Enable 'vdom-link' on port5 and assign it to the Partner VDOM, then configure the IP address.
C.In the global configuration, create a virtual interface and bind it to port5, then assign it to the Partner VDOM.
D.Within the Partner VDOM, create a new interface and map it to port5 using the 'set interface' command.
AnswerA

To assign a physical interface to a VDOM, you must first move the interface to that VDOM in the global configuration. After the interface is in the Partner VDOM, you can then configure its IP address and other settings within that VDOM's context. This two-step process is required because interface ownership is defined at the global level.

Why this answer

Physical interfaces are assigned to VDOMs from the global configuration by editing the interface and setting its VDOM attribute. Once the interface belongs to the Partner VDOM, you can enter that VDOM and configure the IP address and other settings. This is the correct and only method to dedicate a physical interface to a VDOM.

Exam trap

The trap here is attempting to configure the interface IP address before moving it to the VDOM, or trying to create a new interface within the VDOM; physical interfaces must be moved from global first.

73
Drag & Dropmedium

Drag and drop the steps to configure a FortiGate to send logs to a FortiAnalyzer into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure a FortiGate to send logs to FortiAnalyzer is: first add the FortiAnalyzer as a log device, then configure its IP address and shared key for authentication, then choose which log types (e.g., traffic, event, etc.) to forward, optionally apply filters to refine the logs, and finally test the connectivity to verify the configuration. This order ensures that each step builds upon the previous one, avoiding errors such as trying to configure a device that hasn't been added yet or testing before all settings are in place.

74
Multi-Selecthard

A FortiGate administrator is troubleshooting a ZTNA problem where users are unable to connect to an internal application via FortiClient. FortiClient reports 'Connection refused'. The FortiGate ZTNA gateway is configured correctly. Which THREE steps should the administrator take to diagnose the issue?

Select 3 answers
A.Check the FortiGate's antivirus update status
B.Verify that FortiClient can reach the ZTNA gateway's IP and port
C.Examine the ZTNA access proxy rule to ensure the application mapping is correct
D.Reboot the FortiClient computer
E.Verify that the application server is reachable from the FortiGate (e.g., ping or telnet)
AnswersB, C, E

Reachability testing isolates transport-layer failures before deeper ZTNA inspection. Since FortiClient reports "Connection refused", the TCP handshake to the gateway's access port is likely failing — often due to routing, firewall policy, or an incorrect port. Confirming IP and port reachability satisfies the stem's requirement to diagnose connectivity before examining ZTNA tags or Microsoft Entra ID integration.

Why this answer

Option B is correct because a 'Connection refused' error from FortiClient typically indicates a TCP-level reachability problem to the ZTNA gateway, so verifying that the client can reach the gateway's IP and port (for example, with telnet or Test-NetConnection on the configured access proxy port) confirms whether the failure is at the network path or at the gateway itself. Option C is correct because the ZTNA access proxy rule defines the application mapping (external FQDN/port to the real internal server and port), and an incorrect mapping would cause the gateway to reject or misroute the connection even when the gateway is otherwise configured correctly. Option E is correct because the FortiGate must be able to reach the backend application server; if the server is down, the port is closed, or a firewall/routing issue blocks the FortiGate-to-server path, the access proxy cannot complete the connection and the client sees a refused or failed connection.

Option A is not relevant because antivirus update status does not affect ZTNA access proxy connectivity or TCP reachability. Option D is not a diagnostic step; rebooting the FortiClient computer does not isolate the cause and may only mask a transient issue.

Exam trap

The trap is selecting generic steps like rebooting or checking antivirus, which are not relevant to ZTNA connectivity issues.

75
MCQeasy

An administrator wants to load balance traffic across two WAN links by session count. Which SD-WAN load balancing algorithm should they use?

A.Sessions
B.Spillover
C.Lowest-cost
D.Volume
AnswerA

The Sessions algorithm distributes traffic by tracking active session counts per WAN link, directly satisfying the requirement to load balance by session count. Unlike weighted or spillover methods, which use bandwidth ratios or thresholds, it dynamically assigns new sessions to the link with the fewest active sessions, achieving even per-session distribution.

Why this answer

The Sessions algorithm distributes new sessions across WAN links based on the current session count, ensuring each link handles a roughly equal number of active sessions. This directly matches the administrator's requirement to load balance by session count, as it uses the session counter as the metric for link selection.

Exam trap

The trap here is that candidates often confuse 'session count' with 'volume' or 'spillover,' assuming that any load balancing algorithm that distributes traffic equally must use data volume or bandwidth thresholds, rather than recognizing that Sessions is the explicit algorithm for session-based distribution.

How to eliminate wrong answers

Option B is wrong because Spillover is not a load balancing algorithm; it is a traffic steering method that sends traffic to a primary link until its bandwidth threshold is exceeded, then spills over to backup links, which does not balance by session count. Option C is wrong because Lowest-cost selects the link with the lowest cost metric (e.g., latency, jitter, or loss) for each session, not based on session count. Option D is wrong because Volume balances traffic by the amount of data transferred (bytes) across links, not by the number of sessions.

Page 1 of 10

Page 2

All pages