Courseiva

Fortinet NSE 7 Advanced Security NSE7 (NSE7) — Questions 676–718

718 questions total · 10pages · All types, answers revealed

Page 9

Page 10 of 10

676
Multi-Selectmedium

An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)

Select 2 answers
A.A firewall policy with IPS enabled
B.A FortiGuard category subscription
C.An automation stitch trigger set to 'IPS Event'
D.A static route to the source IP
E.An automation stitch action set to 'Quarantine'
AnswersC, E

The IPS Event trigger is what detects the high-severity signature hit and fires the stitch; without it, no automation runs. It supplies the event context, including the offending source IP, that the paired action needs to block traffic automatically.

Why this answer

Option C is correct because an automation stitch must have a trigger that fires on the relevant log event, and setting the trigger to 'IPS Event' (specifically matching high-severity IPS logs) is what initiates the automated response when the IPS sensor detects the threat. Option E is correct because the stitch also needs an action that performs the blocking; the 'Quarantine' action adds the offending source IP to the quarantine list so FortiGate drops subsequent traffic from it. Together, the IPS Event trigger and the Quarantine action form the automation stitch that automatically blocks the source IP.

Option A is not required by the question because, while IPS must be enabled somewhere for events to occur, the question asks specifically about the automation components needed to block the source, not the base policy configuration. Option B is incorrect because FortiGuard category subscription relates to web filtering/security rating services, not to triggering IPS-based quarantine. Option D is incorrect because a static route to the source IP is unrelated to dynamically blocking a detected attacker.

Exam trap

The trap here is that candidates often assume enabling IPS on a firewall policy (Option A) is sufficient for automatic blocking, but FortiGate requires an explicit automation stitch to convert detection into an automated quarantine action.

677
MCQmedium

An administrator receives an error when trying to create a ZTNA proxy rule: 'The ZTNA proxy rule requires a valid application mapping.' What does this indicate?

A.The FortiClient EMS is not reachable
B.The application mapping object is not defined
C.The SSL certificate is missing
D.The firewall policy is not in place
AnswerB

A ZTNA proxy rule requires an application mapping object to define the protected application's FQDN, port, and certificate. Without that mapping, the rule has no target to proxy, so FortiGate rejects creation until the mapping is defined and referenced.

Why this answer

A ZTNA proxy rule maps an external FQDN/port to an internal application. The error means the application mapping (which defines the internal server) is missing or misconfigured.

678
MCQmedium

A company is implementing Zero Trust Network Access using Fortinet's ZTNA solution. They have deployed a FortiGate as the ZTNA gateway and are using FortiClient as the ZTNA agent. Users report that they can initiate ZTNA connections but the connections drop after a few minutes. The FortiGate logs show that the ZTNA session is being terminated due to a endpoint compliance check failure. Which action should the administrator take to resolve this issue?

A.Review and adjust the endpoint compliance rules in FortiClient EMS.
B.Disable endpoint compliance checks on the FortiGate.
C.Increase the session timeout on the FortiGate ZTNA gateway.
D.Change the authentication method from certificate to LDAP.
AnswerA

Endpoint compliance checks are evaluated by FortiClient EMS, which tags endpoints and signals the FortiGate ZTNA gateway; the gateway terminates sessions when a tag is revoked. Adjusting the compliance rules in EMS resolves the failing check that causes the recurring session teardown.

Why this answer

The FortiGate logs explicitly indicate that the ZTNA session is being terminated due to an endpoint compliance check failure. This means the FortiGate is enforcing compliance rules defined in FortiClient EMS, and when the endpoint fails those checks (e.g., missing antivirus updates, firewall disabled), the session is dropped. Reviewing and adjusting the compliance rules in EMS allows the administrator to align the requirements with the actual endpoint posture or correct the misconfiguration causing the failure.

Exam trap

The trap here is that candidates may confuse session timeout (a timer-based disconnect) with compliance enforcement (a policy-based disconnect), leading them to incorrectly choose option C instead of recognizing that the log message directly points to a compliance rule issue in EMS.

How to eliminate wrong answers

Option B is wrong because disabling endpoint compliance checks on the FortiGate would bypass the Zero Trust principle entirely, leaving the network vulnerable to non-compliant endpoints, and does not address the root cause of why compliance checks are failing. Option C is wrong because increasing the session timeout would not prevent the session from being terminated due to a compliance check failure; the timeout controls idle session duration, not compliance enforcement. Option D is wrong because changing the authentication method from certificate to LDAP does not affect endpoint compliance checks; ZTNA session termination due to compliance failure is independent of the authentication method used.

679
MCQhard

A FortiGate cluster (A-P) has a session that is not synchronizing to the secondary unit. The administrator runs 'diagnose sys ha session-sync status' and sees that the session count is different between primary and secondary. Which is the most likely cause?

A.The session is using a custom application control profile that prevents synchronization.
B.The HA heartbeat interface is down.
C.The secondary unit has insufficient memory to accept new sessions.
D.The session was created by a local-in traffic (e.g., management traffic) which is not synchronized.
AnswerD

Local-in traffic terminates on the FortiGate itself, so those sessions are never replicated to the secondary unit. This explains the count mismatch without indicating an HA failure, since session synchronisation only covers transit traffic passing through the cluster.

Why this answer

FortiGate A-P clusters synchronize sessions via the HA heartbeat interface, but local-in traffic (e.g., management sessions like HTTPS, SSH, or SNMP) is never synchronized because it is destined to the cluster IP itself and is inherently unit-specific. The 'diagnose sys ha session-sync status' command shows a session count mismatch because the primary unit has local-in sessions that the secondary does not replicate, making D the correct answer.

Exam trap

The trap here is that candidates assume all sessions are synchronized by default, but FortiGate explicitly excludes local-in traffic (management sessions) from HA synchronization, so a session count difference is normal and expected for those sessions.

How to eliminate wrong answers

Option A is wrong because application control profiles do not affect session synchronization; they are inspection profiles applied to traffic policies, and session synchronization is controlled by HA settings and session type, not by security profiles. Option B is wrong because if the HA heartbeat interface were down, the cluster would not be able to maintain a synchronized state at all, and the secondary would likely be isolated or the cluster would split-brain; the question states the cluster is operational with a session count difference, not a total sync failure. Option C is wrong because insufficient memory on the secondary would cause it to reject new sessions or fail to synchronize, but the symptom would be a growing session count mismatch over time, not a persistent difference for a specific session; moreover, the secondary would still attempt synchronization and log memory pressure, not simply skip a session silently.

680
MCQmedium

A FortiGate administrator has configured a firewall policy with a web filter profile that uses a FortiGuard category action to block 'Malware' websites. Users report that they can still access some known malicious sites that are categorized as 'Malware'. The administrator verifies that the FortiGuard service is reachable and the license is valid. What is the most likely cause?

A.The 'Malware' category is set to 'Monitor' instead of 'Block' in the web filter profile.
B.The FortiGate is using flow-based inspection, which does not support category-based blocking.
C.The static URL filter is allowing the malicious sites before the category action is evaluated.
D.The web filter profile is not applied to the correct firewall policy or traffic direction.
AnswerA

If the FortiGuard category action for 'Malware' is set to Monitor, traffic to those sites is allowed but logged. This would explain why some known malicious sites are accessible despite the administrator's intention to block them. The category action must be explicitly set to Block to enforce blocking, making this the most likely cause.

Why this answer

The FortiGuard category action for 'Malware' must be set to Block to prevent access to sites in that category. If it is set to Monitor, the sites are allowed and only logged. Since the administrator confirmed FortiGuard connectivity and licensing, the most likely cause is that the category action is not set to Block.

Exam trap

The trap here is overlooking the category action setting and assuming a connectivity or inspection mode issue when the action is simply set to Monitor.

681
MCQeasy

A FortiGate administrator wants to quickly identify which process is consuming the most CPU on the device. Which CLI command should be used?

A.diagnose hardware sysinfo memory
B.diagnose sys top
C.diagnose debug application crashlog read
D.get system performance status
AnswerB

diagnose sys top lists running processes sorted by CPU consumption, refreshed live, so the administrator immediately sees which process is heaviest. This directly satisfies the stem's goal of quickly identifying the top CPU consumer on the FortiGate.

Why this answer

'diagnose sys top' displays a real-time list of running processes sorted by CPU usage, allowing the administrator to quickly identify the most CPU-intensive process. This command is the standard FortiGate CLI tool for live process-level CPU monitoring, similar to the Linux 'top' command.

Exam trap

The trap here is that candidates often confuse 'get system performance status' (which shows aggregate CPU percentage) with the process-level detail needed, leading them to choose option D instead of the correct process-specific command.

How to eliminate wrong answers

Option A is wrong because 'diagnose hardware sysinfo memory' shows memory usage statistics, not CPU consumption by process. Option C is wrong because 'diagnose debug application crashlog read' is used to view crash logs for debugging application failures, not for real-time CPU monitoring. Option D is wrong because 'get system performance status' provides a high-level summary of system resource usage (CPU, memory, sessions) but does not break down CPU usage by individual process.

682
MCQhard

A FortiGate in an HA cluster with VDOMs enabled experiences a failover. After the failover, traffic that was passing before is now being dropped. The configuration is synchronized between the primary and secondary units. What is the most likely reason?

A.The new primary has a different VDOM configuration
B.The firewall policies are not synchronized
C.Session synchronization is not enabled between HA members
D.VDOM link interfaces are down on the new primary
AnswerC

Without session synchronization, the secondary FortiGate lacks the connection table for established flows, so after failover it drops packets belonging to existing sessions. Configuration synchronisation alone does not replicate session state, explaining why previously passing traffic now fails.

Why this answer

The most likely reason is that session synchronization is not enabled between HA members. When a failover occurs, the new primary FortiGate does not have the existing session table entries from the original primary, so it treats incoming packets as new connections and may drop them if they do not match a firewall policy's initial handshake state. Even though the configuration is synchronized, session information is not shared unless session synchronization is explicitly configured, causing traffic to be dropped after failover.

Exam trap

The trap here is that candidates assume synchronized configuration includes session state, but FortiGate HA separates configuration sync from session sync, and session synchronization must be enabled as a separate setting under the HA configuration.

How to eliminate wrong answers

Option A is wrong because VDOM configuration is synchronized between HA members, so the new primary has the same VDOM configuration as the old primary. Option B is wrong because the question states that the configuration is synchronized, which includes firewall policies, so they are identical on both units. Option D is wrong because VDOM link interfaces are part of the synchronized configuration and would be in the same state on the new primary; if they were down, the issue would be a configuration or physical problem, not a failover-specific behavior.

683
MCQmedium

An administrator configures a VDOM link between VDOMs A and B. In VDOM A, the VDOM link interface is assigned IP 10.10.10.1/24, and in VDOM B, it is assigned 10.10.10.2/24. A firewall policy on VDOM A allows traffic from a subnet in VDOM A to a subnet in VDOM B. However, traffic fails. The admin checks the routing table in VDOM A and sees a route to the destination subnet via 10.10.10.2. What is the most likely cause?

A.No firewall policy in VDOM B to allow traffic from the VDOM link
B.The VDOM link is not administratively up in VDOM B
C.Inter-VDOM routing is disabled globally
D.The subnet in VDOM B is not defined as an address object in VDOM A's policy
AnswerA

Routing in VDOM-A correctly points to 10.10.10.2, so forwarding succeeds across the link. The drop occurs because VDOM-B has no firewall policy permitting traffic entering its VDOM link interface, so its implicit deny blocks the packets.

Why this answer

In a VDOM link configuration, traffic must be permitted by firewall policies on both VDOMs. Even though VDOM A has a policy allowing traffic to the destination subnet and a valid route via 10.10.10.2, VDOM B must have a policy that allows traffic from the VDOM link interface to reach the destination subnet. Without this policy, VDOM B will drop the packets, causing the traffic failure.

Exam trap

The trap here is that candidates assume a single policy on the source VDOM is sufficient, overlooking that the destination VDOM also requires a policy to permit the traffic, which is a common misconfiguration in multi-VDOM setups.

How to eliminate wrong answers

Option B is wrong because if the VDOM link interface were administratively down in VDOM B, the route in VDOM A would not be present or the link would show as down; the admin sees a valid route via 10.10.10.2, indicating the link is up. Option C is wrong because inter-VDOM routing is enabled by default when VDOMs are configured; disabling it globally would prevent any VDOM-to-VDOM traffic, but the route and policy in VDOM A suggest it is enabled. Option D is wrong because the subnet in VDOM B does not need to be defined as an address object in VDOM A's policy; the policy in VDOM A can reference the destination subnet by IP or address object, and the route confirms the destination is reachable via the VDOM link.

684
MCQmedium

An administrator configures a VDOM on a FortiGate and assigns two interfaces (port1, port2) to it. The administrator wants to route traffic between two different subnets within the same VDOM. Which configuration is required?

A.Configure a VDOM link
B.Create a policy with inter-VDOM link
C.Enable inter-VDOM routing
D.Configure static or dynamic routing
AnswerD

Interfaces in the same VDOM are directly connected at layer 3, but the FortiGate still needs routes to forward traffic between the two subnets. Static or dynamic routing populates the routing table, satisfying the stem's requirement to route between subnets within one VDOM.

Why this answer

Routing between two subnets within the same VDOM is standard intra-VDOM routing. Since both interfaces (port1, port2) belong to the same VDOM, no inter-VDOM constructs are needed; the FortiGate simply requires a route (static or dynamic) to forward packets between the subnets. A firewall policy allowing the traffic is also necessary, but the question specifically asks for the routing configuration.

Exam trap

The trap here is that candidates confuse intra-VDOM routing (within the same VDOM) with inter-VDOM routing (between VDOMs) and incorrectly assume that a VDOM link or inter-VDOM routing must be enabled, when in fact standard routing is sufficient.

How to eliminate wrong answers

Option A is wrong because a VDOM link is used to connect two different VDOMs, not to route between subnets within the same VDOM. Option B is wrong because a policy with inter-VDOM link is a firewall rule that references a VDOM link, again for inter-VDOM traffic, not intra-VDOM routing. Option C is wrong because inter-VDOM routing is a global setting that enables routing between VDOMs; it is irrelevant when both interfaces reside in the same VDOM.

685
MCQmedium

An administrator is configuring a FortiGate with multiple VDOMs. The administrator needs to allow a VDOM to use a shared physical interface with another VDOM. Which feature should be used?

A.Transparent mode
B.Management VDOM
C.VLAN subinterface
D.VDOM link
AnswerC

To share a physical interface between multiple VDOMs, you can create VLAN subinterfaces on the physical interface and assign each VLAN subinterface to a different VDOM. This allows multiple VDOMs to use the same physical interface while maintaining separation at Layer 2. Each VDOM sees its own VLAN subinterface as a distinct interface.

Why this answer

To share a physical interface among multiple VDOMs, create VLAN subinterfaces on the physical interface and assign each subinterface to a different VDOM. This provides logical separation while using the same physical port. VLANs allow the FortiGate to tag traffic and direct it to the appropriate VDOM, enabling efficient use of physical interfaces in multi-VDOM deployments.

Exam trap

The trap here is confusing VDOM links, which are for inter-VDOM communication, with VLAN subinterfaces, which are used to share a physical interface among VDOMs.

686
MCQeasy

Which of the following is a requirement for FortiGate to act as a SAML Identity Provider (IdP) for ZTNA?

A.A public IP address on the WAN interface
B.A configured user database and SAML IdP settings
C.Integration with FortiClient EMS
D.An SSL certificate from a public CA
AnswerB

Acting as a SAML IdP requires a local user database to authenticate users against, plus the SAML IdP settings defining entity ID, endpoints and signing certificate. Both are prerequisites for issuing assertions to ZTNA service providers.

Why this answer

For a FortiGate to act as a SAML Identity Provider for ZTNA, it must have a configured user database (local or remote) and SAML IdP settings enabled, because SAML requires an identity source and IdP metadata to issue assertions. The FortiGate then generates IdP metadata that the SAML SP (such as FortiClient EMS or a ZTNA client) consumes. Without a user store and IdP configuration, no SAML assertions can be produced.

Exam trap

NSE7 often tests the confusion between IdP-side requirements and SP-side or transport-side requirements; the trap is selecting a plausible-sounding but non-essential item like a public IP or public CA certificate instead of the core identity and SAML configuration.

How to eliminate wrong answers

Option A is wrong because a public IP on the WAN interface is not required for the FortiGate to function as a SAML IdP; IdP functionality is about identity assertion, not WAN reachability, and internal or private addressing can work depending on topology. Option C is wrong because FortiClient EMS integration is relevant to ZTNA endpoint posture and SP-side configuration, not a prerequisite for the FortiGate to act as the SAML IdP itself. Option D is wrong because a public CA certificate is not mandatory for SAML IdP operation; a self-signed or internal CA certificate can be used as long as the SP trusts it, and SAML signing/encryption relies on the configured certificate, not specifically a public CA one.

687
MCQmedium

A FortiGate administrator is deploying ZTNA for remote users who connect through FortiClient. The administrator wants to enforce device compliance based on the FortiClient EMS tags. The FortiGate is already integrated with FortiClient EMS. Which configuration step is required to use EMS tags in a ZTNA policy?

A.Enable ZTNA on the SSL VPN portal and map EMS tags to user groups.
B.Configure a ZTNA server and add the EMS tags as a source in the firewall policy.
C.Create a ZTNA rule and specify the EMS tags as a device posture check.
D.Define an address object for the EMS server and use it in a firewall policy.
AnswerC

In ZTNA, device posture is enforced through ZTNA rules that reference EMS tags. The FortiGate retrieves tags from FortiClient EMS and uses them in the ZTNA rule to allow or deny access based on device compliance. This is the correct method to enforce EMS-based compliance for ZTNA.

Why this answer

ZTNA rules on FortiGate can enforce device compliance by referencing EMS tags as device posture checks. The FortiGate queries FortiClient EMS for tags and applies them in the ZTNA rule to permit or deny access. This ensures that only compliant devices can reach protected resources.

The other options either misplace EMS tags in firewall policies or confuse ZTNA with SSL VPN.

Exam trap

The trap here is assuming that EMS tags are used directly in firewall policies or SSL VPN portals, rather than being referenced in ZTNA rules as device posture checks.

688
Multi-Selectmedium

An administrator is configuring a FortiGate to inspect SMTP traffic for spam and viruses. The traffic must be decrypted to inspect the content. Which THREE elements are required for this configuration? (Choose three.)

Select 3 answers
A.A spam filter profile applied to the firewall policy
B.A web filter profile applied to the firewall policy
C.An antivirus profile applied to the firewall policy
D.An application control profile applied to the firewall policy
E.A firewall policy that allows SMTP traffic and has SSL inspection enabled
AnswersA, C, E

Spam filtering is needed to identify and block spam.

Why this answer

A spam filter profile is required to inspect SMTP traffic for spam. FortiGate uses this profile to apply anti-spam techniques such as DNSBL, SURBL, and heuristic analysis on the email content after decryption. Without it, spam detection cannot occur.

Exam trap

The trap here is that candidates often assume a web filter profile can inspect email traffic because it handles content filtering, but web filters are strictly for HTTP/HTTPS protocols and cannot process SMTP MIME data.

689
MCQmedium

An administrator is troubleshooting BGP with SD-WAN. They have configured BGP on the FortiGate and the SD-WAN rule uses 'best quality' strategy. However, failover does not happen when a WAN link goes down. The BGP session is still up. What is the most likely reason?

A.The performance SLA is not configured to track the BGP next hop.
B.The SD-WAN rule is configured with 'set update-static-route disable'.
C.The BGP session is using eBGP multihop.
D.The load balancing algorithm is set to 'volume'.
AnswerA

For SD-WAN to detect link failure, the performance SLA must monitor the actual path to the BGP next hop or internet. BGP session may remain up via an alternate path, but the link may be degraded.

Why this answer

The 'best quality' SD-WAN strategy selects the best path based on performance SLA metrics. Without a performance SLA monitoring the BGP next hop, the FortiGate cannot detect that the link has failed from a BGP perspective, so it will not trigger a failover even if the physical interface goes down. The BGP session remains up because it is still receiving keepalives, but the SD-WAN rule does not consider the link unusable without SLA tracking.

Exam trap

The trap here is that candidates assume BGP session state alone determines link usability, but FortiGate SD-WAN requires explicit performance SLA monitoring of the BGP next hop to trigger failover in a 'best quality' strategy.

How to eliminate wrong answers

Option B is wrong because 'set update-static-route disable' only prevents the FortiGate from installing BGP routes into the static route table; it does not affect SD-WAN failover behavior. Option C is wrong because eBGP multihop allows BGP sessions across multiple hops but does not prevent failover when a link goes down; the issue is SLA tracking, not BGP hop count. Option D is wrong because the load balancing algorithm set to 'volume' affects how traffic is distributed among multiple paths, not whether failover occurs when a link fails.

690
MCQmedium

An NSE7 administrator is configuring a FortiGate to use the built-in intrusion prevention system (IPS) to detect and block exploits targeting a custom web application. The administrator wants to ensure that the IPS engine inspects all HTTP traffic, including encrypted sessions, without impacting performance. Which FortiGate feature should be enabled to allow IPS inspection of SSL/TLS traffic?

A.Hardware acceleration with NP6 processors
B.Flow-based inspection mode
C.Deep packet inspection (DPI) with SSL inspection profile
D.Virtual domain (VDOM) segmentation
AnswerC

Enabling deep packet inspection with an SSL inspection profile allows the FortiGate to decrypt SSL/TLS traffic so the IPS engine can inspect the plaintext for malicious patterns. Without SSL inspection, encrypted traffic bypasses IPS. This is the correct approach for inspecting encrypted HTTP sessions while maintaining security.

Why this answer

To inspect encrypted HTTP traffic with IPS, the FortiGate must decrypt SSL/TLS sessions. This is achieved by applying an SSL inspection profile alongside deep packet inspection. The other options either improve performance or segment traffic but do not provide the necessary decryption to expose malicious content to the IPS engine.

Exam trap

The trap here is assuming that enabling IPS automatically inspects encrypted traffic without configuring SSL inspection.

691
MCQmedium

A FortiGate running FortiOS 7.4 is configured with a firewall policy that references an IPS sensor. The sensor uses a custom signature to detect a recently discovered exploit. Users report that the exploit traffic is not being blocked even though the signature is enabled. The administrator confirms the traffic matches the signature and that the policy is in flow-based inspection mode. Which action should the administrator take to ensure the IPS sensor can block the exploit?

A.Set the IPS sensor action for the signature to 'block'.
B.Enable 'Block malicious URLs' in the web filter profile.
C.Add the signature to a custom application control signature.
D.Change the firewall policy inspection mode to proxy-based.
AnswerA

In FortiOS, an IPS sensor can have multiple filters and signatures, each with an action such as pass, block, or reset. If the signature action is set to 'pass' or 'monitor', traffic will not be blocked even if the signature matches. The administrator must explicitly set the action to 'block' for that signature to drop matching packets. This is the most direct fix for the described symptom.

Why this answer

An IPS sensor in FortiOS can contain multiple signatures and filters, each with an action that determines whether matching traffic is allowed, monitored, or blocked. If the action is not set to block, the sensor will not drop packets even when a signature matches. The administrator must verify the action for the specific signature and set it to block to achieve the desired protection.

Exam trap

The trap here is assuming that enabling a signature automatically blocks matching traffic, when the action must be explicitly set to block.

692
MCQmedium

A FortiGate administrator is implementing ZTNA in reverse-proxy mode to protect an internal web application. Remote users authenticate through FortiClient with EMS tags, and the administrator wants to enforce that only users with a valid certificate and a compliant endpoint can access the application. After configuring the ZTNA server and access proxy, the administrator notices that users without the certificate are still able to reach the application. What is the most likely cause?

A.The FortiClient EMS tags are not being synchronized, so the FortiGate cannot evaluate endpoint compliance.
B.The access proxy rule is missing a client-certificate requirement, so it allows any user who matches the source criteria.
C.The ZTNA server is configured in transparent mode, which bypasses client certificate checks.
D.The ZTNA server is configured to use HTTP instead of HTTPS, so client certificates are not validated.
AnswerB

In FortiGate ZTNA reverse-proxy mode, the access proxy rule defines the authentication and authorization conditions. If the rule does not explicitly require a client certificate, users without one can still pass if they meet other criteria. The administrator must edit the access proxy rule to require a valid client certificate. This is the most likely cause because the symptom is selective bypass of certificate enforcement while other authentication still works.

Why this answer

In ZTNA reverse-proxy mode, the access proxy rule is the enforcement point for authentication and authorization. If the rule does not explicitly require a client certificate, users without one can still access the application as long as they meet other conditions. The administrator must edit the access proxy rule to add a client-certificate requirement.

This ensures that only users presenting a valid certificate are allowed, closing the bypass.

Exam trap

The trap here is assuming that enabling ZTNA automatically enforces client certificates, when in fact the access proxy rule must explicitly require them.

693
MCQmedium

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that the VDOMs can use overlapping IP addresses on their respective interfaces. Which setting must be enabled to allow this?

A.Assign the interfaces to different zones within the same VDOM to allow overlapping IPs.
B.Enable 'allow-subnet-overlap' in each VDOM that requires overlapping subnets.
C.Configure the interfaces to use different VDOM link IP addresses to avoid overlap.
D.Enable 'allow-subnet-overlap' globally in the system settings, which applies to all VDOMs.
AnswerB

The 'allow-subnet-overlap' setting is specifically designed to permit the same subnet to be used on interfaces in different VDOMs. It must be enabled in each VDOM where overlapping addresses are needed. Without it, the FortiGate rejects the configuration because it considers the subnets conflicting.

Why this answer

To use overlapping IP addresses in different VDOMs, you must enable 'allow-subnet-overlap' in each VDOM that requires it. This setting allows the FortiGate to accept the same subnet on interfaces in different VDOMs. It is configured within each VDOM's system settings, not globally.

This is useful in multi-tenant environments where customers may use the same private IP ranges.

Exam trap

The trap here is thinking that overlapping subnets are allowed by default or can be enabled globally, when in fact each VDOM must have the setting enabled individually.

694
MCQmedium

A FortiGate administrator wants to use SAML SSO to authenticate VPN users. The FortiGate will act as the service provider (SP) and an external identity provider (IdP) will be used. Which of the following must be configured on the FortiGate to enable SAML authentication for SSL VPN?

A.A RADIUS server pointing to the IdP and an authentication rule.
B.An LDAP server with the IdP's certificate and a matching policy.
C.A user group with SAML authentication method and an SSL VPN portal referencing that group.
D.A local user with SAML attributes and a firewall policy referencing that user.
AnswerC

SAML SSO requires a user group configured with the SAML authentication method, plus an SSL VPN portal that references it. The group binds the IdP assertion to FortiGate policy, and the portal determines what authenticated users may access.

Why this answer

To enable SAML SSO for SSL VPN on FortiGate, the administrator must configure a user group with the SAML authentication method that references the external IdP, and then reference that group in the SSL VPN portal settings. This establishes the trust relationship where FortiGate acts as the SP and redirects authentication to the IdP. Without the user group and portal binding, SAML authentication cannot be applied to VPN users.

Exam trap

NSE7 often tests the specific FortiGate objects required for SAML SSO, and candidates frequently confuse SAML with RADIUS or LDAP, or assume a local user object is sufficient.

How to eliminate wrong answers

Option A is wrong because RADIUS is a different authentication protocol and is not used for SAML SSO; pointing a RADIUS server to an IdP does not implement SAML. Option B is wrong because LDAP is a directory protocol, not a SAML federation protocol, and importing an IdP certificate alone does not configure SAML authentication. Option D is wrong because SAML authentication is not configured on a local user object; it requires a user group with the SAML method and proper portal or policy references.

695
MCQeasy

Which Fortinet product provides endpoint detection and response (EDR) capabilities, including automated threat containment?

A.FortiClient
B.FortiEDR
C.FortiSandbox
D.FortiGuard
AnswerB

FortiEDR delivers endpoint detection and response with automated threat containment, satisfying the stem's requirement for both EDR and automated containment. Its behavioural analysis and real-time remediation isolate compromised endpoints without manual intervention, unlike FortiSandbox (detonation only) or FortiSIEM (log correlation), which lack native endpoint containment.

Why this answer

FortiEDR is the correct answer because it is Fortinet's dedicated endpoint detection and response solution that provides real-time behavioral analysis, automated threat containment, and forensic investigation capabilities. Unlike traditional antivirus, FortiEDR uses machine learning and pre-execution analysis to detect and block advanced threats, and it can automatically isolate compromised endpoints from the network to prevent lateral movement.

Exam trap

The trap here is that candidates often confuse FortiClient's basic endpoint protection features (like antivirus and web filtering) with the advanced EDR capabilities that are exclusive to FortiEDR, especially since FortiClient can be managed by FortiEDR but does not itself provide automated threat containment.

How to eliminate wrong answers

Option A (FortiClient) is wrong because FortiClient is a unified endpoint agent that provides VPN, web filtering, and basic antivirus, but it does not include full EDR capabilities such as automated threat containment or deep forensic analysis; it relies on FortiEDR or FortiSandbox for advanced detection. Option C (FortiSandbox) is wrong because FortiSandbox is a network-based sandboxing appliance that detonates suspicious files and URLs in a virtual environment to identify zero-day threats, but it does not run on endpoints or provide endpoint-level automated containment. Option D (FortiGuard) is wrong because FortiGuard is Fortinet's global threat intelligence and security services subscription (including antivirus signatures, web filtering categories, and IP reputation), not a product that performs endpoint detection or response actions.

696
MCQmedium

A network administrator is configuring inter-VDOM routing between two VDOMs: VDOM-A and VDOM-B. The administrator creates a inter-VDOM link and adds routes pointing to the link. However, traffic from VDOM-A to VDOM-B fails. What is the most likely missing configuration?

A.Both VDOMs must be in transparent mode
B.A firewall policy must be created in each VDOM to permit traffic across the inter-VDOM link
C.The inter-VDOM link must be in the same VDOM
D.The management VDOM must be enabled
AnswerB

Inter-VDOM links carry traffic between VDOMs, but FortiGate still evaluates security policies on each side. Without a firewall policy in VDOM-A and VDOM-B permitting traffic across the link, the implicit deny drops packets, so routes alone are insufficient.

Why this answer

In FortiGate, inter-VDOM routing requires firewall policies in each VDOM to explicitly permit traffic across the inter-VDOM link. Without these policies, the FortiGate drops the traffic even if routes are correctly configured, because the inter-VDOM link behaves like a virtual interface that requires policy-based access control.

Exam trap

The trap here is that candidates assume routing alone is sufficient for inter-VDOM communication, overlooking FortiGate's requirement for explicit firewall policies to permit traffic across VDOM boundaries, similar to how policies are needed between physical interfaces.

How to eliminate wrong answers

Option A is wrong because inter-VDOM routing works in both transparent and NAT/route modes; both VDOMs do not need to be in transparent mode. Option C is wrong because the inter-VDOM link is a cross-VDOM connection, not a single-VDOM interface; placing it in the same VDOM would defeat the purpose of inter-VDOM routing. Option D is wrong because the management VDOM is only required for administrative access and has no bearing on inter-VDOM traffic forwarding.

697
MCQmedium

A company is deploying FortiClient ATP to protect endpoints. They want to block ransomware behavior in real time. Which FortiClient feature should be enabled?

A.Real-Time Protection
B.Vulnerability Scan
C.Web Filtering
D.Application Firewall
AnswerA

Real-Time Protection continuously monitors file and process activity on the endpoint, blocking malicious behaviour such as ransomware encryption as it occurs. This satisfies the requirement to block ransomware behaviour in real time rather than only detecting it after execution.

Why this answer

Real-Time Protection is the FortiClient feature that uses behavioral analysis and machine learning to detect and block ransomware-like activities, such as mass file encryption or unauthorized file modifications, as they occur. This feature monitors process behavior in real time, leveraging FortiSandbox threat intelligence and local heuristics to stop ransomware before it can cause damage.

Exam trap

The trap here is that candidates often confuse Real-Time Protection with Web Filtering or Application Firewall, assuming that blocking the ransomware download or controlling app traffic is sufficient, but Fortinet specifically tests that behavioral blocking at the endpoint level is required for real-time ransomware defense.

How to eliminate wrong answers

Option B (Vulnerability Scan) is wrong because it only identifies missing patches and security misconfigurations on endpoints, but does not actively monitor or block ransomware behavior in real time. Option C (Web Filtering) is wrong because it controls access to malicious URLs and categories, preventing downloads of ransomware payloads, but it does not detect or stop ransomware behavior once it is executing on the endpoint. Option D (Application Firewall) is wrong because it controls network traffic based on application signatures and policies, but it does not analyze process behavior or file system changes to block ransomware encryption actions.

698
MCQeasy

A FortiGate is configured with SD-WAN using load balancing algorithm 'source-dest-ip'. What is the primary characteristic of this algorithm?

A.Traffic is sent to the member with the highest bandwidth.
B.Traffic is sent to the member with the lowest cost metric.
C.Traffic is distributed evenly across all SD-WAN members regardless of source or destination.
D.All traffic from the same source IP to the same destination IP uses the same SD-WAN member.
AnswerD

Source-dest-ip hashes the source and destination IP pair, so every session sharing that pair maps to one SD-WAN member. This delivers consistent path selection and session stickiness, unlike per-packet or round-robin algorithms that would spread those sessions across members.

Why this answer

The 'source-dest-ip' load balancing algorithm in SD-WAN uses a hash of both the source IP and destination IP to deterministically select an SD-WAN member. This ensures that all packets belonging to the same flow (same source-destination pair) are consistently forwarded over the same member, preserving per-flow stickiness and avoiding out-of-order delivery.

Exam trap

The trap here is that candidates often confuse 'source-dest-ip' with 'round-robin' or 'bandwidth-based' algorithms, assuming it distributes traffic evenly, when in fact it prioritizes per-flow stickiness over load distribution.

How to eliminate wrong answers

Option A is wrong because the 'source-dest-ip' algorithm does not consider bandwidth; bandwidth-based load balancing is a separate feature (e.g., 'spillover' or 'max-bandwidth' settings). Option B is wrong because cost metric is used in route selection (e.g., via SD-WAN rules or static routes), not in the load balancing algorithm itself; 'source-dest-ip' hashes IPs, not cost. Option C is wrong because it describes round-robin or session-based load balancing, not 'source-dest-ip'; the latter is not evenly distributed across members but rather per-flow consistent.

699
MCQmedium

In FortiManager, what is the purpose of header and footer policies in a policy package?

A.To create policy groups for better organization
B.To apply policies only during specific times of the day
C.To ensure specific policies are always placed at the top (header) or bottom (footer) of the policy list
D.To separate IPv4 and IPv6 policies
AnswerC

Header and footer policies anchor specified rules at the very top or bottom of the package's policy list, regardless of subsequent insertions. This guarantees critical allow or deny rules retain precedence, satisfying the requirement to keep particular policies permanently positioned.

Why this answer

Header and footer policies in FortiManager are special policy types that enforce a fixed position within the policy list. Header policies are always placed at the top (before all other policies), and footer policies are always placed at the bottom (after all other policies). This ensures that critical security rules, such as default-deny or global allow rules, remain in their intended position regardless of policy package changes or reordering operations.

Exam trap

The trap here is that candidates confuse header/footer policies with policy ordering or scheduling, assuming they are just a way to organize or time-limit policies, rather than understanding they enforce a fixed position in the policy list.

How to eliminate wrong answers

Option A is wrong because header and footer policies are not used for organizational grouping; policy groups (or policy sections) are created using policy packages or policy folders, not header/footer policies. Option B is wrong because time-based policy enforcement is handled by schedule objects within individual policy rules, not by the header/footer policy mechanism. Option D is wrong because IPv4 and IPv6 policies are separated by policy type (IPv4 vs IPv6) within the policy package, not by header/footer policies.

700
MCQmedium

An administrator needs to apply different routing policies for traffic based on source IP address, overriding the normal routing table. Which feature should be configured?

A.Prefix list
B.SD-WAN rule
C.Route map
D.Policy-based routing
AnswerD

Policy-based routing matches packets against administrator-defined criteria such as source IP address and forwards them via a specified next hop, bypassing the standard destination-based routing table. This directly satisfies the requirement to override normal routing decisions based on source address.

Why this answer

Policy-based routing (PBR) is the correct feature because it allows an administrator to override the normal routing table lookup based on criteria such as source IP address. Unlike static or dynamic routing, PBR uses route maps to match traffic (e.g., source IP) and apply a specific next-hop or interface, enabling granular traffic steering independent of the destination-based routing table.

Exam trap

The trap here is that candidates often confuse route maps (a policy tool) with policy-based routing (the feature that uses route maps to override forwarding), leading them to select 'Route map' instead of 'Policy-based routing' as the feature name.

How to eliminate wrong answers

Option A is wrong because a prefix list is used to match IP prefixes in routing protocols (e.g., BGP) or route redistribution, not to override routing decisions based on source IP. Option B is wrong because SD-WAN rules are designed for application-aware traffic steering and link load balancing in an SD-WAN fabric, not for overriding the routing table based solely on source IP in a traditional routing context. Option C is wrong because a route map is a tool used to manipulate routing information (e.g., set attributes, filter routes) during redistribution or policy application, but it does not itself override the routing table; it must be applied with PBR to achieve source-based forwarding.

701
MCQeasy

A network administrator is deploying FortiGate to protect against unknown malware. They want to use machine learning to detect and block malicious files without relying on signatures. Which antivirus scanning technique should be enabled to achieve this?

A.Heuristic scanning
B.Signature-based detection
C.Machine learning-based malware detection
D.Sandbox analysis
AnswerC

Machine learning-based malware detection uses trained models to identify malicious characteristics in files, enabling detection of unknown malware without signatures. FortiGate's antivirus profile includes this as an option, often labeled as 'AI-based' or 'Machine Learning' detection. It is designed to catch zero-day threats and is the correct choice for the scenario.

Why this answer

Machine learning-based malware detection uses artificial intelligence models to analyze file features and identify malicious patterns, allowing FortiGate to block unknown malware without relying on signatures. This is the only option that directly matches the requirement for machine learning. Other techniques like signatures, heuristics, or sandboxing are different approaches and do not provide the same capability.

Exam trap

The trap here is equating heuristic scanning or sandboxing with machine learning, when they are distinct technologies with different detection methodologies.

702
MCQmedium

A FortiGate is configured with two SD-WAN members: port1 (WAN1) and port2 (WAN2). An SD-WAN rule routes traffic from the internal subnet 10.0.1.0/24 to the internet using the 'volume' load-balancing algorithm. The rule is configured with a volume ratio of 70:30 for port1:port2. After some time, the administrator notices that port1 is handling approximately 90% of the traffic volume, while port2 handles only 10%. What is the most likely cause of this imbalance?

A.The volume algorithm uses the configured volume ratio only when both members are alive and meet the SLA; if port2 is dead, all traffic goes to port1.
B.The volume algorithm distributes traffic based on the configured ratio, but the ratio is applied to the number of sessions, not the volume of data.
C.The volume algorithm uses the configured ratio only as a target, but it also considers the current bandwidth usage; if port1 has higher bandwidth, it may receive more traffic.
D.The volume algorithm may not achieve the exact ratio if there are long-lived sessions that are not re-evaluated; existing sessions remain on their original member, causing an imbalance over time.
AnswerD

The volume algorithm distributes new sessions based on the current volume ratio, but existing sessions are not rebalanced. If many long-lived sessions (e.g., large downloads) are established on port1, they continue to use port1, skewing the overall volume. New sessions may be assigned to port2 to compensate, but if the long-lived sessions dominate, the ratio can deviate significantly from the configured target.

Why this answer

The volume algorithm aims to distribute traffic volume according to the configured ratio, but it does not rebalance existing sessions. Long-lived sessions can cause a persistent imbalance because they remain on their original member. The algorithm only affects new session assignments, so if a few large flows are pinned to one member, the overall volume can deviate from the target ratio.

Exam trap

The trap here is assuming that the volume algorithm dynamically moves existing sessions to maintain the ratio, when it only affects new sessions.

703
MCQhard

An administrator runs 'diagnose debug application sslvpn -1' and sees repeated 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate'. The SSL-VPN is configured to require client certificates. What is the cause?

A.The client is not sending a client certificate
B.The SSL-VPN server certificate is expired
C.The SSL-VPN tunnel mode is misconfigured
D.The CA certificate is not imported on FortiGate
AnswerA

The TLS alert fires during the client certificate request phase, meaning the peer returned no certificate at all. Since the SSL-VPN profile enforces client certificate authentication, the handshake cannot proceed without one, so the connecting client simply has no certificate installed or configured to present.

Why this answer

The error 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate' occurs during the TLS handshake when the server requests a client certificate and the client fails to provide one. Since the SSL-VPN is configured to require client certificates, the FortiGate expects the client to present a valid certificate; if none is sent, the handshake fails with this specific OpenSSL error. This directly indicates that the client is not sending a client certificate, making option A correct.

Exam trap

The trap here is that candidates may confuse a client certificate not being sent with a CA certificate not being imported on the FortiGate, but the error message explicitly points to the absence of a certificate from the client, not a validation failure after receipt.

How to eliminate wrong answers

Option B is wrong because an expired SSL-VPN server certificate would produce a different error, such as 'certificate expired' or 'certificate verify failed', not a 'peer did not return a certificate' message. Option C is wrong because tunnel mode misconfiguration (e.g., using tunnel mode instead of web mode) affects how traffic is encapsulated, not the TLS client certificate exchange; the error is specific to the SSL handshake layer. Option D is wrong because the CA certificate not being imported on the FortiGate would prevent validation of the client certificate if one were sent, but the error clearly states the peer did not return a certificate at all, indicating the client failed to send one, not that validation failed.

704
MCQeasy

Which two commands display the current session count on a FortiGate?

A.get system performance status
B.diagnose sys session stat
C.show system session
D.diagnose hardware sysinfo session
AnswerA, B

The get system performance status command reports overall health counters, including the current session count alongside CPU, memory and uptime figures. It satisfies the stem by displaying the live session total directly from the FortiGate CLI without diagnostic-level inspection.

Why this answer

Both 'get system performance status' and 'diagnose sys session stat' display the current session count on a FortiGate. 'get system performance status' provides a real-time snapshot including active sessions, while 'diagnose sys session stat' shows session table statistics such as total and used sessions. Therefore, both commands are valid answers to the question.

Exam trap

Candidates often think only 'get system performance status' shows session count, but 'diagnose sys session stat' also provides session statistics including count. The trap is that both commands are valid, making this a multi-select question.

How to eliminate wrong answers

Option B is wrong because 'diagnose sys session stat' displays detailed statistics about session table usage (e.g., total sessions, hash table collisions) but does not directly show the current active session count in a single line; it requires parsing of output. Option C is wrong because 'show system session' is not a valid FortiGate CLI command; the correct syntax for viewing session details is 'diagnose sys session list' or 'get system session' (though the latter is not standard). Option D is wrong because 'diagnose hardware sysinfo session' is not a valid command; the correct command for hardware-related session info is 'diagnose hardware sysinfo' (which shows CPU/memory info) but does not include session count.

705
MCQmedium

A FortiGate administrator is configuring ZTNA to provide secure access to an internal application. The application is hosted on a server with IP 10.0.1.100 and port 8080. The administrator creates a ZTNA rule on the FortiGate as an access proxy. What is the correct configuration for the ZTNA rule's 'Application Access' entry?

A.External port: 0, Mapped port: 8080, Destination: 10.0.1.100
B.External port: 8080, Mapped port: 443, Destination: 10.0.1.100
C.External port: 443, Mapped port: 443, Destination: 10.0.1.100
D.External port: 443, Mapped port: 8080, Destination: 10.0.1.100
AnswerD

The access proxy terminates client TLS on 443 and forwards to the real service. Mapping external port 443 to destination 10.0.1.100 on port 8080 lets the ZTNA rule reach the internal application listening on 8080 while clients connect on the standard HTTPS port.

Why this answer

For ZTNA access proxy, the external port is the port clients connect to (typically 443 for HTTPS), and the mapped port is the internal server port (8080). The destination is the internal server IP. Therefore, option D is correct: external port 443, mapped port 8080, destination 10.0.1.100.

706
MCQhard

An administrator has a FortiGate with VDOMs 'VDOM-A' and 'VDOM-B' connected by an inter-VDOM link. Users in VDOM-A can reach a web server in VDOM-B, but return traffic from the server to clients is being dropped. The administrator has already created policies in both directions. Which action should the administrator take to resolve the dropped return traffic?

A.Enable asymmetric routing on both VDOMs with 'config system settings' and 'set asymmetric-route enable'
B.Add a static route in VDOM-B that points the client subnet to the inter-VDOM link interface as next-hop
C.Increase the TCP session timeout in VDOM-B so return packets are not aged out before arrival
D.Configure a firewall policy in VDOM-B with NAT enabled to translate the server address to the inter-VDOM link address
AnswerB

For return traffic to leave VDOM-B toward clients in VDOM-A, VDOM-B needs a route for the client subnet whose next-hop is the inter-VDOM link interface. Without that route, the server's replies have no path back and are dropped. Policies in both directions are necessary but not sufficient; routing must also exist in each VDOM, and this step supplies the missing route in VDOM-B.

Why this answer

Inter-VDOM links require routing in both directions. Even with policies in both VDOMs, VDOM-B must have a route for the client subnet pointing to the inter-VDOM link interface so the server's replies can return. Missing that route is the classic cause of one-way inter-VDOM traffic, and adding it restores bidirectional communication.

Exam trap

The trap here is focusing on policies and NAT when the real cause is a missing return route in the second VDOM, since inter-VDOM links need routing configured independently on each side.

707
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is established but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees 'no matching policy for this IPsec SA'. What is the most likely cause?

A.The phase2 selectors do not match between peers
B.There is no firewall policy allowing traffic from the local network to the remote network via the VPN tunnel interface
C.The pre-shared key is mismatched
D.The tunnel interface is administratively down
AnswerB

The log indicates the IKE SA negotiated selectors but no firewall policy permits that traffic. FortiGate requires an explicit policy matching source, destination and the VPN tunnel interface; without it, packets are dropped before entering the tunnel.

Why this answer

The log message 'no matching policy for this IPsec SA' on a FortiGate means the IKE/IPsec SA was negotiated successfully but no firewall policy matches the traffic that needs to traverse the tunnel. In FortiOS, a firewall policy with the tunnel interface as the outgoing interface (and matching source/destination) is required for traffic to be encrypted and forwarded. Without it, the tunnel stays up but no data flows.

Exam trap

The trap is conflating IKE negotiation failures (PSK mismatch, phase2 selector mismatch) with traffic-forwarding failures — candidates see 'IPsec SA' in the log and assume the SA itself is broken, when the message actually points to a missing firewall policy, not a VPN parameter problem.

How to eliminate wrong answers

Option A is wrong because mismatched phase2 selectors would cause the IKE negotiation to fail with a 'no proposal chosen' or 'phase2 mismatch' error, not a 'no matching policy' message — and the tunnel would not establish at all. Option C is wrong because a mismatched pre-shared key causes phase1 to fail with 'PSK mismatch' or 'authentication failed', preventing the tunnel from coming up entirely. Option D is wrong because an administratively down tunnel interface would show the interface as down in 'diagnose vpn tunnel list' and would not produce the specific 'no matching policy for this IPsec SA' log line.

708
MCQeasy

A network administrator is deploying a FortiGate in transparent mode to replace an existing layer 2 switch. Which statement about transparent mode is true?

A.All interfaces operate at layer 2, and the FortiGate forwards traffic based on MAC addresses
B.Transparent mode only supports static routing
C.Transparent mode requires VDOMs to be enabled
D.The FortiGate acts as a router and requires IP addresses on its interfaces
AnswerA

Transparent mode places all interfaces at layer 2, so the FortiGate forwards frames by MAC address rather than routing between IP subnets. This lets it drop into an existing layer 2 switch position without readdressing the network.

Why this answer

In transparent mode, the FortiGate operates as a layer 2 bridge, forwarding traffic based on MAC addresses without performing routing. All interfaces are in the same broadcast domain, and the FortiGate inspects traffic at layers 3–7 while remaining transparent to the network. This allows it to replace a layer 2 switch while adding firewall functionality.

Exam trap

The trap is that candidates assume transparent mode disables all firewall inspection, but FortiGate in transparent mode still performs full security inspection at layers 3–7 while forwarding based on MAC addresses. Additionally, some think no IP address is needed, but a management IP is required for administrative access.

How to eliminate wrong answers

Option B is wrong because transparent mode supports both static and dynamic routing (e.g., OSPF, BGP) when VDOMs are enabled, though it is often used without routing. Option C is wrong because VDOMs are not required for transparent mode; they are an optional feature for multi-tenancy or administrative separation. Option D is wrong because the FortiGate in transparent mode does not act as a router; its management IP is used for administrative access only, and traffic forwarding is based on MAC addresses, not IP addresses.

709
MCQeasy

A FortiGate administrator wants to ensure that only devices with an up-to-date antivirus and OS patch level can access a sensitive application published via ZTNA. Which ZTNA component should the administrator configure to enforce this requirement?

A.ZTNA proxy configuration
B.ZTNA tags with posture checks
C.SSL VPN portal settings
D.Firewall policy with application control
AnswerB

ZTNA tags with posture checks let FortiClient EMS evaluate endpoint antivirus and OS patch status, then assign tags that the access proxy rule matches. This enforces the stated requirement that only up-to-date devices reach the sensitive application.

Why this answer

ZTNA tags with posture checks allow the FortiGate to verify endpoint compliance (e.g., antivirus version, OS patch level) before granting access to a ZTNA-published application. The FortiGate collects posture data from the FortiClient endpoint and compares it against configured compliance rules; only devices that meet the requirements receive the appropriate ZTNA tag and are allowed through the ZTNA proxy.

Exam trap

The trap here is that candidates often confuse the ZTNA proxy configuration (which handles traffic forwarding and authentication) with the tag-based posture enforcement mechanism, assuming that the proxy itself can enforce endpoint compliance without the separate tag and posture check system.

How to eliminate wrong answers

Option A is wrong because the ZTNA proxy configuration defines the access proxy settings (e.g., application mapping, authentication) but does not itself enforce endpoint posture checks; it relies on tags to determine access. Option C is wrong because SSL VPN portal settings are used for traditional SSL VPN access, not for ZTNA, and do not support posture-based tagging or endpoint compliance verification. Option D is wrong because a firewall policy with application control can inspect traffic and block applications, but it cannot perform endpoint posture checks (e.g., antivirus or OS patch level) required for ZTNA compliance enforcement.

710
MCQmedium

A FortiGate administrator is troubleshooting a ZTNA deployment. Users report that they can access the ZTNA application, but the EMS tags are not being enforced. The administrator verifies that the FortiGate is connected to FortiClient EMS and that the EMS tags exist. What is the most likely cause?

A.The FortiClient EMS tags are not synchronized with the FortiGate.
B.The ZTNA server configuration is missing the application mapping.
C.The firewall policy allowing ZTNA traffic does not have UTM profiles applied.
D.The ZTNA rule does not include a device posture check for the EMS tags.
AnswerD

If the ZTNA rule lacks a device posture check that references EMS tags, then tags are not enforced. The rule may allow access based solely on user authentication. This is the most likely cause because the FortiGate is connected to EMS and tags exist, but the rule is not configured to use them. This is the correct answer.

Why this answer

EMS tag enforcement in ZTNA requires a device posture check in the ZTNA rule. If the rule does not reference EMS tags, they are ignored. The administrator confirmed EMS connectivity and tag existence, so the missing posture check is the likely cause.

Other options either would prevent access entirely or are unrelated to tag enforcement.

Exam trap

The trap here is assuming that EMS tag enforcement is automatic once EMS is connected, when actually the ZTNA rule must explicitly include a posture check for the tags.

711
MCQhard

A FortiGate administrator has configured an antivirus profile with sandbox inspection and applied it to a firewall policy. Users report that downloads of executable files are delayed significantly, but eventually complete. The administrator wants to reduce the delay while still blocking malicious files before they reach the endpoint. Which change should the administrator make?

A.Switch the sandbox profile from Inline mode to Analyze mode.
B.Configure the sandbox profile to use a smaller file size limit for inline inspection.
C.Enable the 'Block malicious files' option in the antivirus profile.
D.Add the FortiSandbox IP address to the trusted hosts list on the FortiGate.
AnswerB

Inline sandbox inspection holds files until a verdict is returned, which can cause delays for large files. By setting a smaller file size limit for inline inspection, files above that limit are handled differently, reducing the time users wait. This allows the administrator to balance security and performance while still blocking malicious files within the size threshold.

Why this answer

Inline sandbox inspection holds files until FortiSandbox returns a verdict, which can cause noticeable delays for large files. Setting a smaller file size limit for inline inspection means only smaller files are held, reducing user wait time while still blocking malicious files within that limit. Switching to Analyze mode would remove pre-delivery blocking, and the other options do not address the latency.

Exam trap

The trap here is thinking that switching to Analyze mode is the only way to reduce delay, when adjusting the inline file size limit can preserve pre-delivery blocking for smaller files while cutting wait times.

712
MCQmedium

A FortiManager administrator wants to push a policy package that includes both global header/footer policies and VDOM-specific policies. Which statement about header/footer policies is correct?

A.Header/footer policies are only available when using per-device mapping
B.Header/footer policies can only be configured directly on the FortiGate, not via FortiManager
C.Header/footer policies are automatically generated and cannot be manually edited
D.Header policies are inserted before the VDOM's own policies; footer policies are appended after
AnswerD

Header and footer policies sit outside the VDOM's own rule sequence, so FortiManager pushes them as a wrapper: header rules are evaluated first, then the VDOM-specific policies, then footer rules. This satisfies the scenario's requirement to combine global and per-VDOM policies in one package without merging them into each VDOM's policy list.

Why this answer

In FortiManager, when a policy package includes both global header/footer policies and VDOM-specific policies, the header policies are inserted before the VDOM's own policies in the policy table, while footer policies are appended after them. This ensures that header policies are evaluated first for traffic matching, and footer policies serve as a catch-all or default set of rules at the end of the VDOM policy list.

Exam trap

The trap here is that candidates often assume header/footer policies are only for per-device mapping or must be configured locally on the FortiGate, but FortiManager fully supports creating and managing them centrally for consistent policy enforcement across VDOMs.

How to eliminate wrong answers

Option A is wrong because header/footer policies are available with both per-device mapping and policy package installation, not exclusively with per-device mapping. Option B is wrong because header/footer policies can be configured directly on FortiManager under the global policy package and then pushed to managed FortiGates, not only on the FortiGate itself. Option C is wrong because header/footer policies are manually created and edited by the administrator in FortiManager, not automatically generated; they are user-defined policies that provide a consistent set of rules across multiple VDOMs.

713
MCQmedium

An administrator wants to add custom fields to device objects in FortiManager to track location and contact info. Which feature should be used?

A.Meta fields
B.System templates
C.Custom reports
D.Dynamic mapping
AnswerA

Meta fields extend FortiManager device objects with custom attributes such as location and contact information, storing them alongside standard object data. This directly satisfies the administrator's requirement to track additional fields without altering the underlying device schema.

Why this answer

Meta fields in FortiManager allow administrators to define custom attributes (e.g., location, contact info) that can be attached to device objects. These fields are stored in the FortiManager database and can be used for filtering, reporting, and policy mapping, providing a flexible way to enrich device metadata without modifying the device configuration itself.

Exam trap

The trap here is that candidates confuse 'meta fields' with 'system templates' because both involve customization, but system templates apply configuration settings to devices, whereas meta fields add descriptive metadata without altering device configurations.

How to eliminate wrong answers

Option B is wrong because system templates are used to standardize configuration settings (e.g., SNMP, admin profiles) across devices, not to add custom fields to device objects. Option C is wrong because custom reports are used to generate tailored views of log and event data, not to define metadata fields on device objects. Option D is wrong because dynamic mapping is a feature for automatically assigning devices to ADOMs or groups based on criteria like IP address or hostname, not for adding custom fields.

714
MCQhard

A FortiGate is configured with two WAN members in an SD-WAN zone. The performance SLA monitors latency to a probe server. The rule uses 'best quality' strategy. After some time, one member fails the SLA. Which action does the FortiGate take for existing sessions that were using that member?

A.All sessions are dropped and the member is removed from the zone
B.Existing sessions are re-evaluated and may be moved based on policy
C.Existing sessions are immediately moved to another member
D.Existing sessions continue on the failed member until they timeout
AnswerD

SD-WAN's best quality strategy affects only member selection for new sessions. Sessions already pinned to a member that later fails its SLA remain there until they close or time out, since FortiGate does not forcibly rebalance established flows.

Why this answer

When a WAN member fails the performance SLA in an SD-WAN 'best quality' strategy, FortiGate does not disrupt existing sessions that were already using that member. Instead, those sessions continue on the failed member until they naturally timeout or are torn down, because the SD-WAN rule only influences the path selection for new sessions. This behavior is by design to avoid breaking active connections due to transient SLA fluctuations.

Exam trap

The trap here is that candidates often assume SD-WAN 'best quality' strategy dynamically re-routes all traffic, including existing sessions, when an SLA fails, but FortiGate only applies path selection changes to new sessions to maintain session stability.

How to eliminate wrong answers

Option A is wrong because FortiGate does not drop all sessions or remove the member from the zone solely due to SLA failure; the member remains available for new sessions if it is the only path or if other rules permit. Option B is wrong because existing sessions are not re-evaluated or moved based on policy; only new session path selection is affected by SLA status. Option C is wrong because immediate session movement would cause disruption and is not supported; FortiGate relies on session timeout or application-specific mechanisms (like DNS or TCP retransmission) to naturally migrate traffic.

715
MCQhard

An administrator is troubleshooting an issue where a FortiGate is not forwarding traffic between two internal subnets. The administrator runs 'diagnose debug flow' and sees that packets are entering the FortiGate but are dropped with the message 'reverse path check fail, drop'. What is the MOST likely cause?

A.The FortiGate's routing table does not have a route to the destination subnet.
B.Asymmetric routing: the return path for the traffic is through a different interface than the FortiGate expects.
C.A firewall policy is missing to allow traffic between the two subnets.
D.The two subnets are in the same zone, and intra-zone traffic is denied by default.
AnswerB

The reverse path check verifies that the return packet would be routed back through the same interface it arrived on. If the return route points to a different interface, the check fails and the packet is dropped. This is common in networks with multiple paths, such as when a router between subnets sends traffic through one FortiGate but the return path goes through another.

Why this answer

The 'reverse path check fail' drop indicates that the FortiGate received a packet on an interface but the route back to the source would use a different interface. This is characteristic of asymmetric routing. The FortiGate performs a reverse path forwarding check to prevent spoofing and ensure symmetric routing.

To resolve, the administrator can either fix the routing to be symmetric or disable the reverse path check on the interface, though that reduces security.

Exam trap

The trap here is confusing reverse path check failures with policy or routing table misses, when the message specifically points to asymmetric routing.

716
MCQmedium

When troubleshooting an IPsec VPN phase 1 failure, you run 'diagnose vpn ike config' and see that the remote gateway IP address is incorrect. Which command is used to correct the peer IP configuration?

A.set psksecret <secret>
B.execute vpn tunnel down <tunnel>
C.config vpn ipsec phase1-interface edit <name> set remote-gw <ip>
D.set certificate <name>
AnswerC

Editing the phase1-interface object and setting remote-gw directly corrects the peer address that phase 1 negotiation uses, satisfying the stem's requirement to fix the incorrect remote gateway IP. The `diagnose vpn ike config` output reflects this value, so amending it here resolves the mismatch causing the failure.

Why this answer

The 'config vpn ipsec phase1-interface' command allows you to edit the phase1 configuration, and the 'set remote-gw <ip>' command directly corrects the peer IP address. This is the standard FortiGate CLI method to update the remote gateway IP for an IPsec VPN phase1 interface, which is essential for establishing the IKE session.

Exam trap

The trap here is that candidates may confuse operational commands (like 'execute vpn tunnel down') with configuration commands, or mistake authentication settings (PSK or certificate) for peer addressing, leading them to select options that do not actually change the remote gateway IP.

How to eliminate wrong answers

Option A is wrong because 'set psksecret <secret>' configures the pre-shared key, not the remote gateway IP address; it addresses authentication, not peer reachability. Option B is wrong because 'execute vpn tunnel down <tunnel>' only tears down an existing tunnel, but does not modify the configuration; it is a troubleshooting command, not a correction command. Option D is wrong because 'set certificate <name>' assigns a certificate for authentication, which is unrelated to correcting the peer IP address.

717
MCQeasy

A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?

A.Set the authentication method to 'signature'.
B.Set the proposal to include DH groups 14 or higher.
C.Configure 'local-gw' with the certificate's CN.
D.Enable 'peer-id-option' and set it to 'any'.
AnswerA

Setting the phase1 authentication method to 'signature' replaces pre-shared key authentication with digital certificate exchange, satisfying the requirement for PKI-based IKEv2 authentication. FortiGate then validates peer certificates against the configured CA, using RSA or ECDSA signatures during the IKEv2 exchange rather than a shared secret.

Why this answer

In FortiOS IPsec phase1 configuration, the 'authentication-method' parameter controls how the peers authenticate during IKEv2. Setting it to 'signature' instructs the FortiGate to use digital signatures (RSA or ECDSA) with X.509 certificates instead of pre-shared keys. This is the mandatory change to enable certificate-based authentication; other parameters like 'certificate' and 'remote-certificate' are then used to specify the actual certificates.

Exam trap

NSE7 often tests the confusion between authentication method and other phase1 parameters like DH groups or peer ID options, causing candidates to overlook that 'authentication-method' must be explicitly set to 'signature' to enable certificate-based authentication.

How to eliminate wrong answers

Option B is wrong because DH groups are used for key exchange (PFS) and do not control the authentication method; they are independent of certificate vs. PSK authentication. Option C is wrong because 'local-gw' specifies the local gateway IP address for the IPsec tunnel, not a certificate CN; the certificate is selected via the 'certificate' parameter.

Option D is wrong because 'peer-id-option' controls how the peer ID is validated (e.g., from certificate subject), but it does not enable certificate authentication itself; the authentication method must still be set to 'signature'.

718
MCQmedium

A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?

A.Enable DHCP relay on the FortiSwitch VLAN
B.Configure a VLAN on the FortiSwitch under the switch controller and assign it to a port
C.Use the config system interface to create a VLAN on the FortiGate and tag it on the trunk
D.Create a VLAN subinterface on the FortiGate's port that connects to the FortiSwitch
AnswerB

FortiLink-managed switches are configured through the FortiGate's switch controller. Creating the VLAN there and assigning it to a physical FortiSwitch port pushes the VLAN definition and membership down to the switch, which is the required step for user traffic separation.

Why this answer

When integrating a FortiSwitch managed by a FortiGate, VLANs for user traffic must be created under the switch controller on the FortiGate. This allows the FortiGate to push the VLAN configuration to the FortiSwitch, including assigning the VLAN to a specific port or port group. Option B correctly describes this process, as the switch controller manages the FortiSwitch as an extension of the FortiGate, not as a standalone device.

Exam trap

The trap here is that candidates confuse creating a VLAN on the FortiGate's own interfaces (using 'config system interface') with configuring a VLAN on a managed FortiSwitch, which requires the switch controller context.

How to eliminate wrong answers

Option A is wrong because DHCP relay is a separate feature that can be enabled on a VLAN interface, but it is not a required configuration for creating a VLAN on a FortiSwitch; the question asks for the required configuration to set up the VLAN itself. Option C is wrong because 'config system interface' is used to create VLAN interfaces on the FortiGate itself, not on a managed FortiSwitch; FortiSwitch VLANs are managed through the switch controller, not system interfaces. Option D is wrong because creating a VLAN subinterface on the FortiGate's physical port is used for router-on-a-stick or inter-VLAN routing on the FortiGate, but it does not configure the VLAN on the FortiSwitch; the FortiSwitch must be explicitly configured via the switch controller to carry that VLAN.

Page 9

Page 10 of 10

All pages