Courseiva

Fortinet NSE 7 Advanced Security NSE7 (NSE7) — Questions 76–150

718 questions total · 10pages · All types, answers revealed

Page 1

Page 2 of 10

Page 3
76
Multi-Selectmedium

An admin is troubleshooting an IPsec VPN tunnel that is failing phase 2. The IKE debug shows 'no matching proposal'. Which TWO settings should the admin verify on both sides? (Choose two.)

Select 2 answers
A.Dead Peer Detection interval
B.Encryption algorithm (e.g., AES128, AES256)
C.Diffie-Hellman group for PFS
D.Pre-shared key
E.Local and remote gateway IP addresses
AnswersB, C

Phase 2 (Quick Mode) negotiates the IPsec SA using the Phase 2 proposal, so a mismatch in the encryption algorithm between peers produces exactly the "no matching proposal" error. Verifying AES128 or AES256 on both gateways ensures the Phase 2 encryption transforms align, satisfying the stem's requirement to resolve the failing negotiation.

Why this answer

In IPsec phase 2, the IKE debug message 'no matching proposal' indicates a mismatch in the security association (SA) parameters used to establish the IPsec SA. The encryption algorithm (option B) is a core component of the IPsec proposal that must match exactly on both peers. Perfect Forward Secrecy (PFS) using a Diffie-Hellman group (option C) is also negotiated during phase 2; if one side requires PFS and the other does not, or if the DH groups differ, phase 2 will fail with this error.

Exam trap

The trap here is that candidates often confuse phase 1 and phase 2 parameters, incorrectly selecting pre-shared key (option D) or gateway IPs (option E) as causes for a phase 2 proposal mismatch, when in fact only the IPsec SA parameters (encryption, authentication, PFS) are negotiated in phase 2.

77
MCQmedium

An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?

A.SD-WAN rule with manual strategy
B.Route map
C.Policy-based routing on the firewall policy
D.Performance SLA
AnswerA

A manual-strategy SD-WAN rule pins matching traffic to a chosen member, bypassing SLA-driven selection entirely. Because the requirement is source-IP-based steering that ignores performance measurements, manual strategy satisfies the "regardless of SLA results" constraint directly, unlike best-quality or lowest-cost strategies that continuously evaluate link metrics.

Why this answer

A is correct because an SD-WAN rule with a manual strategy allows the administrator to explicitly pin traffic from a specific source IP to a particular SD-WAN member interface, overriding any performance SLA-based path selection. This is achieved by configuring the rule's 'strategy' as 'manual' and specifying the preferred member, which forces all matching traffic to use that interface regardless of SLA health.

Exam trap

The trap here is that candidates confuse Performance SLA as a steering mechanism rather than a monitoring tool, or mistakenly think policy-based routing can achieve the same result within an SD-WAN context, but Fortinet's SD-WAN architecture requires the rule's strategy to be set to 'manual' for explicit member pinning.

How to eliminate wrong answers

Option B is wrong because route maps are used for route redistribution, filtering, or modifying routing attributes (e.g., metric, next-hop) in routing protocols like BGP or OSPF; they do not provide per-source-IP traffic steering within an SD-WAN zone. Option C is wrong because policy-based routing (PBR) on a firewall policy can direct traffic based on source IP, but it operates at the routing level and does not integrate with SD-WAN member selection or SLA awareness; it would bypass the SD-WAN logic entirely. Option D is wrong because a Performance SLA is a monitoring mechanism that measures link quality (e.g., latency, jitter, packet loss) and is used by SD-WAN rules with 'best quality' or 'load balancing' strategies, but it cannot force traffic to a specific member; it only provides data for dynamic path decisions.

78
Matchingmedium

Match each Fortinet component to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Next-generation firewall

Centralized management platform

Logging and reporting server

Advanced threat detection and analysis

Web application firewall

Why these pairings

FortiGate is the NGFW, FortiManager manages devices, FortiAnalyzer handles logging/analytics, and FortiClient is an endpoint agent. Common confusions involve swapping these roles.

79
MCQhard

A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?

A.Configure traffic shaping to rate limit the URL
B.Add a static URL filter with the exact URL and action 'block'
C.Enable DNS filter with botnet C2 domain blocking
D.Change the action for Malware category from 'monitor' to 'block' in the web filter profile
AnswerD

The profile currently only logs matching traffic, so FortiGate permits the malicious URL. Switching the Malware category action from monitor to block makes the firewall drop matching sessions, satisfying the requirement to stop access rather than merely record it.

Why this answer

The web filtering profile currently has the Malware category set to 'monitor all', which logs but does not block traffic. To block the URL, the action must be changed from 'monitor' to 'block' within the same web filter profile. This directly enforces the blocking action for all URLs categorized as Malware, including the known malicious URL.

Exam trap

The trap here is that candidates may think a static URL filter is required for blocking, overlooking that category-based actions in the web filter profile can directly block all URLs in a category without needing individual entries.

How to eliminate wrong answers

Option A is wrong because traffic shaping only rate-limits bandwidth and does not block URLs; it cannot enforce a block on malicious content. Option B is wrong because adding a static URL filter is unnecessary and less efficient when the category-based action can be changed; it also requires manual entry of every specific URL, which is not scalable. Option C is wrong because DNS filter with botnet C2 domain blocking targets command-and-control domains at the DNS level, not HTTP/HTTPS URL categories like Malware; it addresses a different threat vector.

80
MCQhard

A company has deployed two FortiGate-600Es in an active-passive HA cluster. The cluster is configured with three VDOMs: VDOM-A (corporate LAN), VDOM-B (guest Wi-Fi), and VDOM-C (DMZ). Each VDOM has its own set of interfaces and policies. The cluster is also configured to use FGCP with session pickup enabled. Recently, the network team noticed that after a failover event, some user sessions in VDOM-B are not being picked up, causing disruption for guest users. The session pickup feature is enabled globally. The administrator checks the configuration and finds the following settings on the primary FortiGate: - config system ha set session-pickup enable set session-pickup-connectionless enable end - config vdom edit VDOM-A config system ha set session-pickup enable end next edit VDOM-B config system ha set session-pickup disable end next edit VDOM-C config system ha set session-pickup enable end next Based on this configuration, what is the most likely reason that sessions in VDOM-B are not being picked up?

A.The HA priority of the cluster is set too low, causing session pickup to fail for VDOM-B.
B.Session pickup for connectionless protocols is not enabled, so UDP sessions in VDOM-B are not picked up.
C.Session pickup is disabled specifically for VDOM-B in the per-VDOM HA configuration.
D.The interfaces assigned to VDOM-B do not have session pickup enabled.
AnswerC

Per-VDOM HA settings override the global session-pickup configuration, so VDOM-B's explicit `set session-pickup disable` prevents its sessions from being synchronised to the secondary FortiGate during failover. The global `set session-pickup enable` cannot re-enable it, which is why only guest Wi-Fi sessions are lost.

Why this answer

The per-VDOM HA configuration for VDOM-B explicitly disables session pickup with 'set session-pickup disable'. Even though the global HA settings enable session pickup, the per-VDOM setting overrides the global setting for that VDOM. As a result, after a failover, sessions in VDOM-B are not synchronized to the standby FortiGate and are not picked up, causing disruption for guest users.

Exam trap

The trap here is that candidates assume global session pickup settings apply uniformly to all VDOMs, overlooking that per-VDOM HA settings override the global configuration, which is a common misconfiguration in multi-VDOM HA deployments.

How to eliminate wrong answers

Option A is wrong because HA priority affects which unit becomes primary, not whether session pickup functions per VDOM; session pickup is controlled by explicit enable/disable settings, not priority. Option B is wrong because 'session-pickup-connectionless' is enabled globally, which would allow UDP and other connectionless sessions to be picked up, but this global setting is overridden by the per-VDOM disable for VDOM-B. Option D is wrong because session pickup is configured at the VDOM level, not per interface; interfaces inherit the VDOM's session pickup setting, so disabling it on the VDOM prevents pickup regardless of interface configuration.

81
MCQeasy

An administrator is reviewing the HA configuration shown in the exhibit. The primary unit has failed, and the secondary unit (with priority 100) has taken over. However, the administrator notices that the secondary unit has an IP address of 10.10.10.2 on port3, but cannot ping the management gateway 10.10.10.1. What is the most likely cause?

A.The HA management interface IP is not active on the secondary
B.The hbdev configuration is incorrect
C.The override setting is preventing the secondary from taking over management
D.session-pickup is not enabled
AnswerA

The management IP is active only on the primary unit; the secondary uses the same IP after failover, but the network may not have updated.

Why this answer

When the secondary unit takes over in an HA cluster, the HA management interface IP (configured under config system ha) is only active on the primary unit by default. Even after failover, the secondary unit does not automatically activate this IP unless the 'management-interface-ip' is explicitly configured to be active on the secondary. Since the secondary unit has IP 10.10.10.2 on port3 but cannot ping the management gateway 10.10.10.1, the most likely cause is that the HA management interface IP is not active on the secondary, meaning the secondary unit is using its own port3 IP (10.10.10.2) but the gateway expects the management IP to be reachable from that subnet, which it is not.

Exam trap

The trap here is that candidates often assume the secondary unit automatically inherits all IP addresses from the primary after failover, but FortiGate HA specifically requires explicit configuration for the management interface IP to be active on the secondary.

How to eliminate wrong answers

Option B is wrong because hbdev (heartbeat device) configuration affects HA heartbeat communication between units, not the activation of the management IP on the secondary after failover. Option C is wrong because the override setting controls whether a higher-priority unit can preempt the current primary after it recovers; it does not prevent the secondary from taking over management functions after the primary fails. Option D is wrong because session-pickup is a feature for synchronizing firewall sessions between HA members; it has no impact on whether the management interface IP is active on the secondary unit.

82
Multi-Selecthard

A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)

Select 2 answers
A.Action: 'Add to Block List'
B.FortiAnalyzer log query
C.Action: 'Email Notification'
D.Trigger: 'IPS Event'
E.FortiGuard category
AnswersA, D

'Add to Block List' is the action component that performs the blocking. The stitch needs a trigger to fire and an action to execute; this action quarantines the offending source IP on FortiGate, satisfying the requirement to automatically block addresses matching the SSH Brute Force IPS signature.

Why this answer

Option A ('Add to Block List') is correct because the automation stitch must contain an action that actually enforces the block; the 'Add to Block List' action inserts the offending source IP into the FortiGate's local block list so subsequent traffic from that address is dropped. Option D ('IPS Event') is correct because the stitch needs a trigger that fires when the IPS signature for 'SSH Brute Force' is detected, and the IPS Event trigger is the mechanism that initiates the automation stitch upon an IPS log event. Together, the IPS Event trigger and the Add to Block List action form the required trigger-plus-action pair for this scenario.

Option B (FortiAnalyzer log query) is not required because automation stitches on FortiGate are triggered by local event/log conditions, not by querying FortiAnalyzer. Option C (Email Notification) is an action that would only notify someone rather than block the IP, so it does not fulfill the blocking requirement. Option E (FortiGuard category) relates to web filtering categorization and is unrelated to blocking an IP that triggered an IPS signature.

Exam trap

The trap here is that candidates often confuse optional actions like email notifications or external log queries as required components, when only the trigger and a blocking action are mandatory to create a functional automation stitch for IP blocking.

83
MCQeasy

An administrator is configuring an SD-WAN rule on a FortiGate. They want to load balance traffic across three WAN links based on the volume of traffic sent. Which load balancing algorithm should they use?

A.Source IP
B.Session count
C.Volume
D.Weighted round robin
AnswerC

The volume algorithm distributes traffic based on the amount of data sent through each link. It monitors the volume of traffic and selects the link with the least volume, helping to balance the total data transferred across links. This directly addresses the requirement to load balance based on traffic volume, making it the correct choice.

Why this answer

The volume load balancing algorithm in SD-WAN distributes traffic based on the measured volume of data sent through each link. It dynamically selects the link with the least volume, ensuring that the total traffic is balanced across available links. This is the only algorithm among the options that directly uses traffic volume as the metric, making it the correct choice for the scenario.

Exam trap

The trap here is confusing session count with volume; session count balances the number of connections, while volume balances the actual data transferred.

84
MCQmedium

A FortiGate administrator is troubleshooting a VPN tunnel that connects to a remote site. The tunnel is up, but traffic is not passing. The administrator checks the Phase 2 settings and sees that the local and remote subnets are correctly defined. What is the next step to diagnose the issue?

A.Check the firewall policies that reference the VPN interface
B.Check the routing table for the remote subnet
C.Run 'diagnose vpn ike log' to check for Phase 1 errors
D.Restart the VPN tunnel
AnswerA

Phase 2 selectors can match correctly while firewall policies referencing the VPN interface still block traffic, since policy lookup governs whether decrypted packets are permitted. Checking those policies is the logical next diagnostic step after confirming subnet definitions.

Why this answer

When the VPN tunnel is up (Phase 1 and Phase 2 are established) but traffic is not passing, the most common cause is that a firewall policy referencing the VPN interface is either missing or misconfigured. Even with correct Phase 2 selectors and routing, the FortiGate will drop traffic if no policy explicitly permits it from the source to the destination over the VPN interface. Therefore, checking the firewall policies is the logical next step.

Exam trap

The trap here is that candidates assume a working Phase 2 (tunnel up) guarantees traffic flow, but FortiGate requires an explicit firewall policy to permit traffic through the VPN interface, unlike some other vendors where a route alone is sufficient.

How to eliminate wrong answers

Option B is wrong because if the tunnel is up and Phase 2 subnets are correctly defined, the routing table for the remote subnet is typically already present (either statically or via dynamic routing); a missing route would prevent the tunnel from coming up or cause Phase 2 to fail, not just block traffic. Option C is wrong because 'diagnose vpn ike log' is used to debug Phase 1 (IKE) issues, but the tunnel is already up, indicating Phase 1 completed successfully; this command would not reveal why traffic is not passing through an established tunnel. Option D is wrong because restarting the VPN tunnel is a brute-force approach that does not diagnose the root cause; if the tunnel is up and the configuration is correct, restarting it will not resolve a missing or misconfigured firewall policy.

85
Multi-Selectmedium

An organization wants to implement multiple layers of defense against advanced persistent threats. Which three Fortinet solutions would be most effective in an ATP strategy? (Choose three.)

Select 3 answers
A.FortiMail
B.FortiSandbox
C.FortiWeb
D.FortiEDR
E.FortiDeceptor
AnswersB, D, E

FortiSandbox detects unknown malware via behavioral analysis.

Why this answer

FortiSandbox is correct because it provides dynamic analysis of suspicious files and URLs in a controlled, isolated environment, detecting zero-day and advanced malware that signature-based solutions miss. It integrates with other Fortinet security products to share threat intelligence and automate blocking, forming a critical layer in an ATP strategy by catching threats that evade initial defenses.

Exam trap

The trap here is that candidates often confuse 'security products that are part of a layered defense' with 'core ATP solutions,' leading them to select FortiMail or FortiWeb because they are common perimeter tools, while the exam specifically targets solutions that provide advanced threat detection, analysis, and response across multiple attack vectors.

86
MCQeasy

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM and ensure that the interface is dedicated to that VDOM only. Which action should the administrator take?

A.Enable the 'dedicated' option in the interface settings and select the VDOM.
B.In the interface configuration, set the VDOM field to the desired VDOM.
C.Create a VLAN interface on the physical interface and assign the VLAN interface to the desired VDOM.
D.Use the 'set vdom' command in the global configuration to move the interface to the desired VDOM.
AnswerB

Each physical interface on a FortiGate can be assigned to a single VDOM. By setting the VDOM field in the interface configuration to the desired VDOM, the interface becomes dedicated to that VDOM. It will no longer be available to other VDOMs. This is the standard method to allocate physical interfaces to VDOMs, ensuring isolation and proper traffic handling.

Why this answer

To dedicate a physical interface to a VDOM, you assign the interface to that VDOM by setting its VDOM field in the interface configuration. This removes the interface from other VDOMs and makes it exclusively available to the assigned VDOM. Other methods like VLANs are used for sharing, and there is no 'dedicated' option.

Exam trap

The trap here is confusing interface dedication with VLAN sharing, or inventing a 'dedicated' setting that does not exist.

87
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The remote gateway logs show a proposal mismatch. On FortiGate, the administrator runs 'diagnose vpn ike config' and sees 'proposal: aes128-sha1, aes256-sha256'. The remote side expects 'aes256-sha1'. What is the most likely cause?

A.The Phase 1 proposal list does not include the algorithm combination the remote gateway requires
B.The pre-shared key is incorrect
C.The Phase 2 selectors are misconfigured
D.The IKE version is set to 1 but remote uses 2
AnswerA

Phase 1 negotiation selects a matching proposal from both peers' lists. The remote expects aes256-sha1, which is absent from the local list containing only aes128-sha1 and aes256-sha256, so no common combination exists and the tunnel fails.

Why this answer

The 'diagnose vpn ike config' output shows the FortiGate's Phase 1 proposal list includes 'aes128-sha1' and 'aes256-sha256', but the remote gateway expects 'aes256-sha1'. Since neither of the local proposals matches the remote's required combination, the IKE negotiation fails with a 'proposal mismatch' error. The administrator must add 'aes256-sha1' to the Phase 1 proposal list on the FortiGate to align with the remote gateway's expectation.

Exam trap

The trap here is that candidates often confuse a proposal mismatch with a pre-shared key or IKE version issue, but the specific error message and the 'diagnose vpn ike config' output directly point to an algorithm mismatch in Phase 1, not authentication or version negotiation.

How to eliminate wrong answers

Option B is wrong because a pre-shared key mismatch typically results in an authentication failure, not a proposal mismatch; the logs would show 'authentication failed' or 'invalid cookie' rather than a proposal error. Option C is wrong because Phase 2 selectors (traffic selectors) are negotiated after Phase 1 is established, so a Phase 2 misconfiguration would cause the tunnel to fail later, not prevent Phase 1 from completing. Option D is wrong because an IKE version mismatch (v1 vs v2) would produce a different error, such as 'no acceptable proposal' or 'unsupported IKE version', not a proposal mismatch on algorithms; the proposal mismatch specifically refers to encryption/hash algorithms, not the IKE version.

88
MCQhard

A FortiGate running FortiOS 7.2 has multiple VDOMs. The administrator notices that inter-VDOM routing between two VDOMs is not working. Configuration shows a firewall policy allowing the traffic, and the route table shows routes to the destination VDOM. What additional configuration is required?

A.Configure a static route with a gateway IP in the destination VDOM
B.Create a VDOM link interface pair and assign them to the respective VDOMs
C.Assign an IP address to the VLAN interface on the source VDOM
D.Enable 'inter-vdom' under config system global
AnswerB

Inter-VDOM traffic requires a VDOM link, a virtual interface pair whose ends sit in each VDOM, to carry packets between them. Routes and a permissive policy alone cannot forward traffic without this link, so the missing link explains the failure.

Why this answer

Inter-VDOM routing requires a VDOM link, which is a pair of logical interfaces (one in each VDOM) that are directly connected. Without this link, the VDOMs cannot exchange traffic even if firewall policies and routes exist, because they operate as separate virtual firewalls with isolated forwarding tables.

Exam trap

The trap here is that candidates assume a firewall policy and routes are sufficient for inter-VDOM traffic, overlooking the mandatory VDOM link interface pair that provides the actual Layer 3 adjacency between the VDOMs.

How to eliminate wrong answers

Option A is wrong because a static route with a gateway IP in the destination VDOM is not possible; the gateway must be reachable via an interface that belongs to the source VDOM, and inter-VDOM routing requires a direct link (VDOM link) rather than a next-hop in another VDOM. Option C is wrong because assigning an IP to a VLAN interface on the source VDOM does not create a path to the destination VDOM; VLAN interfaces are used for Layer 2 segmentation within a single VDOM, not for inter-VDOM connectivity. Option D is wrong because there is no 'inter-vdom' toggle under config system global; inter-VDOM routing is enabled by default when VDOMs are enabled, and the missing piece is the VDOM link interface pair, not a global setting.

89
MCQeasy

An administrator wants to monitor the session count on a FortiGate in real time. Which CLI command provides this information?

A.diagnose sys top
B.get system performance status
C.diagnose sys session stat
D.diagnose debug enable
AnswerC

diagnose sys session stat returns real-time session counts and memory usage for the session table, giving the administrator an immediate snapshot. It reads current session statistics directly, unlike log or policy commands that do not expose live session totals.

Why this answer

'diagnose sys session stat' is the specific FortiGate CLI command that displays real-time session statistics, including the total number of sessions currently tracked by the firewall. This command provides a live count of active sessions, which is exactly what the administrator needs for real-time monitoring.

Exam trap

The trap here is confusing general performance monitoring commands (like 'get system performance status') with session-specific diagnostics, leading candidates to select options that show system health but not the exact session count required.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys top' shows real-time CPU and memory usage per process, not session counts. Option B is wrong because 'get system performance status' displays overall system performance metrics like CPU load and memory usage, but does not include session count details. Option D is wrong because 'diagnose debug enable' is used to enable debug output for troubleshooting, not to display session statistics.

90
MCQeasy

A security analyst is reviewing alerts from FortiEDR and wants to automatically isolate an infected endpoint from the network when a malicious process is detected. Which FortiEDR feature should the analyst configure to achieve this?

A.Vulnerability assessment scan.
B.Playbook with a 'Network Isolation' action.
C.Forensic data collection rule.
D.Application control policy to block the process.
AnswerB

FortiEDR playbooks allow automated responses to security events. A playbook can be triggered on a malicious process detection and execute a 'Network Isolation' action, which cuts off all network communication for the endpoint except to the FortiEDR management server. This contains the threat and prevents lateral movement, matching the analyst's requirement.

Why this answer

FortiEDR playbooks are the automation engine that can trigger actions based on event conditions. Configuring a playbook with a 'Network Isolation' action ensures that when a malicious process is detected, the endpoint is immediately quarantined from the network, stopping further damage. This is the correct way to achieve automated containment.

Exam trap

The trap here is thinking that blocking a process is equivalent to isolating the endpoint; isolation requires a playbook action that cuts network access.

91
MCQhard

A FortiGate administrator configures a VDOM with a limit on the number of firewall policies. The VDOM has 200 policies, and the limit is set to 250. The administrator attempts to add a new policy but receives an error indicating the limit has been reached. What is the MOST likely reason?

A.The administrator must reboot the FortiGate for the limit to take effect
B.The limit includes IPv4, IPv6, and other policy types
C.The VDOM has reached the maximum number of objects, not policies
D.The limit is per VDOM and cannot be changed
AnswerB

FortiGate's VDOM policy limit is a combined counter covering IPv4, IPv6, multicast and other policy types, not IPv4 alone. With 200 policies already configured across those categories, the effective total has reached 250, so the next addition is rejected despite the apparent headroom.

Why this answer

The FortiGate VDOM policy limit includes all policy types—IPv4, IPv6, and others (e.g., local-in policies, authentication policies). Even if the administrator has only 200 IPv4 policies, the total count of all policy types combined may already reach the 250 limit, preventing the addition of a new policy. This is why the error occurs despite the VDOM appearing to have room under the configured limit.

Exam trap

The trap here is that candidates assume the limit applies only to IPv4 firewall policies, ignoring that FortiGate counts all policy types (IPv4, IPv6, local-in, etc.) against the same limit, leading them to choose an incorrect answer like C or D.

How to eliminate wrong answers

Option A is wrong because policy limits take effect immediately without requiring a reboot; FortiGate enforces the limit dynamically upon policy creation. Option C is wrong because the error specifically references the policy limit, not the object limit; FortiGate has separate limits for objects (e.g., addresses, services) and policies, and the error message would differ if it were an object limit issue. Option D is wrong because the limit can be changed per VDOM via the config vdom command (e.g., set firewall-policy-limit), and it is not immutable.

92
MCQhard

A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?

A.Enable the 'Scan encrypted traffic' option in the antivirus profile.
B.Enable deep inspection in the SSL inspection profile applied to the policy.
C.Change the FortiSandbox connection mode from FortiGate to inline.
D.Add the website's IP address to the FortiSandbox blocklist.
AnswerB

FortiGate can only extract and submit files from HTTPS traffic if the session is decrypted. Without SSL deep inspection, the firewall sees only encrypted bytes and cannot identify the file for sandboxing, so no submission occurs. Enabling deep inspection allows the antivirus engine to inspect the decrypted payload and forward the executable to FortiSandbox for verdict.

Why this answer

File submission to FortiSandbox requires that FortiGate can see the file content. For HTTPS downloads, this means the traffic must be decrypted using an SSL inspection profile set to deep inspection. Without decryption, the antivirus engine cannot identify or extract the file, so no submission or verdict occurs.

Enabling deep inspection on the policy resolves the issue.

Exam trap

The trap here is assuming that enabling FortiSandbox inspection in the antivirus profile is sufficient for all traffic types, ignoring that encrypted traffic must be decrypted first.

93
MCQmedium

A FortiGate has multiple VRFs configured. An administrator wants to allow traffic from VRF 1 to reach a server in VRF 2. What configuration is required?

A.Use a single VDOM and enable inter-VDOM links.
B.Place both interfaces in the same VRF.
C.Create a static route from one VRF to another.
D.Configure a VRF leak policy using route maps or policy routes.
AnswerD

VRF leak policies permit controlled route redistribution between otherwise isolated routing tables, so traffic from VRF 1 can resolve a path into VRF 2. Route maps or policy routes define which prefixes or flows are leaked, satisfying the inter-VRF reachability requirement without merging the VRFs.

Why this answer

VRF leaking is the standard method to allow traffic between different VRFs on a FortiGate. This is achieved by configuring route maps or policy routes to selectively import/export routes between VRFs, enabling inter-VRF communication without merging the VRFs or using VDOMs.

Exam trap

The trap here is that candidates confuse VRF leaking with inter-VDOM routing or assume a simple static route can bridge VRFs, but FortiGate enforces strict VRF isolation unless an explicit leak policy is configured.

How to eliminate wrong answers

Option A is wrong because inter-VDOM links are used for communication between different VDOMs, not between VRFs within the same VDOM; VRFs are a routing table segmentation feature within a single VDOM. Option B is wrong because placing both interfaces in the same VRF would defeat the purpose of VRF segmentation, merging the routing tables and removing isolation. Option C is wrong because a static route alone cannot leak traffic between VRFs; FortiGate requires explicit VRF leak configuration (e.g., route maps or policy routes) to allow inter-VRF forwarding, as static routes are VRF-scoped by default.

94
MCQhard

A FortiGate HA cluster is configured with two units in active-passive mode. The administrator needs to perform a firmware upgrade on the cluster with minimal downtime. The current firmware version is 7.2.5 and the target is 7.2.7. The cluster uses FGCP with session synchronization enabled. Which procedure should the administrator follow?

A.Upgrade only the primary unit and let the secondary synchronize automatically
B.Disable HA, upgrade both units, then re-enable HA
C.Upgrade both units at the same time by connecting to each via console
D.Upgrade the passive unit first, perform a graceful failover, then upgrade the new passive unit
AnswerD

FGCP session synchronisation lets the passive unit take over with existing sessions intact. Upgrading the passive unit first keeps the active unit forwarding traffic, then a graceful failover makes the upgraded unit active, minimising downtime while both run 7.2.7.

Why this answer

It follows the recommended upgrade procedure for an active-passive FGCP cluster with session synchronization. By upgrading the passive unit first, then performing a graceful failover (which preserves existing sessions via FGCP session sync), and finally upgrading the new passive unit, the administrator ensures that the cluster remains operational throughout the process with minimal traffic disruption. This method avoids a full cluster outage and maintains session continuity.

Exam trap

The trap here is that candidates assume firmware synchronization works like configuration synchronization, leading them to choose Option A, but FGCP does not automatically replicate firmware images between cluster members.

How to eliminate wrong answers

Option A is wrong because upgrading only the primary unit does not cause the secondary to synchronize firmware; FGCP synchronizes configuration and session state, not firmware images, so the secondary would remain on the old version and the cluster would break. Option B is wrong because disabling HA removes redundancy and causes a full traffic outage during the upgrade, which contradicts the goal of minimal downtime. Option C is wrong because upgrading both units simultaneously via console without a failover sequence would likely cause a split-brain scenario or traffic loss, as both units would reboot at the same time, dropping all sessions.

95
MCQhard

A FortiGate is the hub of an IPsec VPN and also terminates SSL VPN for remote users. The administrator wants remote users to access internal resources only after the FortiGate validates the endpoint's compliance through FortiClient EMS, and wants the validation to happen before the user is placed in a VPN address pool. Which SSL VPN configuration element enforces endpoint compliance during the connection handshake?

A.SSL VPN settings with the 'Require Client Certificate' option enabled.
B.SSL VPN host check policy that references FortiClient EMS compliance tags.
C.SSL VPN realm configured with a custom authentication timeout.
D.SSL VPN portal with split tunneling disabled.
AnswerB

A host check policy evaluates the endpoint's compliance, including FortiClient EMS tags, during the SSL VPN connection handshake before the user is assigned an address from the pool. If the endpoint fails the check, the FortiGate can deny or restrict access immediately. This directly enforces the requirement that compliance be validated before tunnel access is granted.

Why this answer

Endpoint compliance before address assignment is enforced by the SSL VPN host check policy, which can reference FortiClient EMS compliance tags and runs during the connection handshake. It blocks or restricts non-compliant endpoints before they receive a VPN address, satisfying the requirement. Certificate and portal settings affect authentication and routing but not posture evaluation.

Exam trap

The trap here is confusing strong authentication such as client certificates with endpoint posture validation, when only a host check policy can evaluate EMS compliance before address assignment.

96
MCQmedium

A FortiGate administrator has enabled FortiGuard Outbreak Prevention and selects the 'Use Outbreak Prevention Database' option. After a new outbreak is detected, the administrator verifies that the IPS signature is applied to all applicable policies. However, the administrator wants to ensure that the FortiGate dynamically updates its protection without requiring a full IPS engine update. Which FortiGuard service must be reachable for the FortiGate to receive outbreak prevention updates?

A.FortiGuard Anti-Spam service
B.FortiGuard Web Filtering service
C.FortiGuard SD-WAN service
D.FortiGuard IPS service
AnswerD

FortiGuard IPS service delivers the outbreak prevention database, including dynamic signatures and metadata for newly discovered threats. When Outbreak Prevention is enabled, the FortiGate queries the FortiGuard IPS service to obtain the latest outbreak information without waiting for a full IPS engine update. This allows rapid protection against zero-day exploits and active campaigns.

Why this answer

Outbreak Prevention on FortiGate relies on the FortiGuard IPS service to receive dynamic threat intelligence, including outbreak prevention signatures and metadata. Without connectivity to the FortiGuard IPS service, the FortiGate cannot download the latest outbreak prevention database, and the feature will not function. Other FortiGuard services do not provide this specific data.

Exam trap

The trap here is assuming that any FortiGuard subscription enables outbreak prevention, when in fact only the IPS service delivers the outbreak prevention database.

97
MCQeasy

An administrator applies the above policy but users from 10.0.1.0/24 cannot access web servers at 10.0.2.0/24. However, they can ping the servers. What is the most likely cause?

A.The service 'HTTP' does not include port 443 or the web application is using HTTPS.
B.The destination address is incorrect.
C.The schedule 'always' is not correctly configured.
D.The source interface is incorrect.
AnswerA

ICMP succeeds because ping is permitted, but the policy's HTTP service object covers only port 80. If the web application serves HTTPS on port 443, that traffic matches no allowing policy and is dropped, blocking access.

Why this answer

The policy allows HTTP traffic (port 80), but the web servers are likely using HTTPS (port 443). Since the service object 'HTTP' in FortiGate typically only includes TCP/80, HTTPS traffic is denied by default. The administrator can ping the servers because ICMP is permitted by an implicit or explicit policy, confirming that routing and connectivity are functional.

Exam trap

The trap here is that candidates assume 'HTTP' covers all web traffic, but FortiGate strictly matches the defined ports in the service object, so HTTPS (port 443) is blocked unless explicitly permitted.

How to eliminate wrong answers

Option B is wrong because the destination address 10.0.2.0/24 is correct for the web servers, and ping success confirms reachability. Option C is wrong because the schedule 'always' is a default, always-active schedule that cannot be misconfigured; if it were invalid, no traffic would pass. Option D is wrong because the source interface is correctly set to the interface connected to 10.0.1.0/24, as evidenced by successful ping traffic from that subnet.

98
MCQhard

A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?

A.FortiSandbox to FortiAnalyzer fabric connector
B.FortiSandbox to FortiGate fabric connector
C.FortiSandbox to FortiClient EMS fabric connector
D.FortiSandbox to FortiMail fabric connector
AnswerB

The fabric connector between FortiSandbox and FortiGate enables automatic sharing of verdicts. When FortiSandbox identifies a malicious file, it can send the file hash and other indicators to FortiGate, which then adds them to its local blocklist. This prevents the file from being downloaded or executed on endpoints protected by that FortiGate. This integration directly addresses the requirement to automatically block the file across the network.

Why this answer

Configuring the fabric connector between FortiSandbox and FortiGate allows automatic sharing of malicious file verdicts. FortiGate can then block the file hash, preventing download and execution on endpoints. Other fabric connectors are limited to email security, endpoint management, or logging, and do not provide the same automatic network-wide blocking.

Exam trap

The trap here is assuming that any fabric connector will automatically block the file everywhere, but only the FortiGate integration can enforce blocking at the network perimeter for all traffic.

99
MCQhard

A FortiGate administrator is deploying ZTNA to provide secure access to internal web applications. The administrator wants to ensure that only devices with up-to-date antivirus signatures are granted access. Which FortiGate component should be used to enforce this requirement?

A.SSL VPN portal with host checking.
B.ZTNA proxy rules with application mapping.
C.Firewall policies with antivirus security profiles.
D.FortiClient EMS compliance rules.
AnswerD

FortiClient EMS compliance rules allow administrators to define endpoint posture requirements, such as up-to-date antivirus signatures, and enforce them. When integrated with FortiGate ZTNA, the FortiGate can query FortiClient EMS for device compliance status and grant or deny access based on those rules. This is the correct component for enforcing endpoint compliance in a ZTNA deployment.

Why this answer

In FortiGate ZTNA, endpoint compliance is enforced through integration with FortiClient EMS. FortiClient EMS compliance rules define the required posture, such as antivirus signature version, and FortiGate queries EMS for the compliance status of the device. ZTNA rules then use this information to allow or deny access.

This ensures that only compliant devices can reach protected applications.

Exam trap

The trap here is assuming that ZTNA proxy rules or firewall antivirus profiles can enforce endpoint compliance, when in fact compliance enforcement requires FortiClient EMS integration.

100
MCQeasy

A network administrator wants to logically separate two departments on a single FortiGate. Each department must have its own firewall policies, routing table, and administrators. Which feature should be used?

A.Virtual Domains (VDOMs)
B.Policy Packages
C.Administrative Domains (ADOMs)
D.VLANs
AnswerA

VDOMs partition a single FortiGate into independent virtual firewalls, each with its own firewall policies, routing table and administrator accounts. This satisfies the requirement to separate the two departments logically while sharing the same physical appliance.

Why this answer

Virtual Domains (VDOMs) allow a single FortiGate to be partitioned into multiple independent virtual firewalls, each with its own firewall policies, routing table, and administrative access. This meets the requirement for logical separation of departments with isolated policy and routing domains.

Exam trap

The trap here is confusing VLANs with VDOMs: VLANs segment Layer 2 traffic but do not provide independent routing tables or administrative domains, so candidates often pick VLANs when the question explicitly requires separate routing and administrators.

How to eliminate wrong answers

Option B is wrong because Policy Packages are used to group firewall policies within a VDOM or a non-VDOM FortiGate, but they do not provide separate routing tables or independent administrators. Option C is wrong because Administrative Domains (ADOMs) are a FortiManager concept for managing multiple FortiGates or VDOMs, not a feature on a single FortiGate for local separation. Option D is wrong because VLANs operate at Layer 2 to segment broadcast domains and require a Layer 3 interface or VDOM to enforce separate routing tables and firewall policies; they do not inherently provide independent routing or administrative isolation.

101
MCQhard

An administrator is investigating a security incident and needs to view raw logs from a FortiAnalyzer for a specific time range. The administrator wants to ensure the logs are not aggregated or summarized. Which type of log view should be used?

A.Event Management
B.FortiView
C.Reports
D.Log View
AnswerD

Log View presents raw, unaggregated log entries for the selected time range, preserving each individual event. Other views roll records into summaries or charts, which would hide the granular detail the administrator needs during incident investigation.

Why this answer

The Log View in FortiAnalyzer displays raw, unaggregated logs exactly as received from FortiGate devices, making it the correct choice for viewing logs without summarization. Unlike other views that pre-process or summarize data, Log View provides direct access to the original log entries for a specified time range, which is essential for detailed incident investigation.

Exam trap

The trap here is that candidates confuse FortiView's real-time graphical summaries with raw log access, assuming 'Log View' is just another dashboard, when in fact FortiView aggregates data and Log View shows the original unmodified logs.

How to eliminate wrong answers

Option A is wrong because Event Management aggregates and correlates logs into events, summarizing multiple log entries into a single event record, which does not show raw logs. Option B is wrong because FortiView provides pre-processed, summarized graphical views and dashboards that aggregate data for quick analysis, not raw logs. Option C is wrong because Reports generate summarized, formatted output based on templates and scheduled aggregation, not the original unaggregated log entries.

102
MCQmedium

An administrator is deploying a FortiGate with multiple VDOMs in NAT mode. The administrator wants to ensure that traffic between VDOMs is inspected by security profiles and that inter-VDOM traffic does not bypass the firewall policy engine. Which configuration is required to achieve this?

A.Enable VDOM partitioning and assign interfaces to each VDOM.
B.Enable inter-VDOM routing and create a firewall policy between the VDOM links.
C.Enable ASIC offloading for inter-VDOM traffic to ensure inspection.
D.Configure a single firewall policy with all interfaces as source and destination.
AnswerB

Inter-VDOM links create virtual interfaces that allow traffic to be routed between VDOMs. To inspect traffic, you must create firewall policies on each VDOM that permit and inspect traffic entering and leaving the VDOM link. This ensures that security profiles are applied and traffic does not bypass the policy engine.

Why this answer

Inter-VDOM routing requires VDOM links, which are virtual interfaces that connect VDOMs. To inspect inter-VDOM traffic, firewall policies must be created on each VDOM to allow and apply security profiles to traffic traversing the VDOM link. This ensures that all inter-VDOM traffic is subject to the same security policies as external traffic, preventing bypass.

Exam trap

The trap here is assuming that enabling inter-VDOM links automatically inspects traffic; policies are still required on both VDOMs.

103
MCQmedium

An administrator runs 'diagnose sys session filter dport 443' and sees: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is a multicast session with a duration of 3600 seconds.
B.The session is a TCP session in established state that has been up for 3600 seconds and will expire in 3599 seconds.
C.The session is in SYN_SENT state and has timed out after 3600 seconds.
D.The session is a UDP session that has been active for 3600 seconds.
AnswerB

proto=6 denotes TCP, and proto_state=01 is the established state. The duration field shows the session has existed 3600 seconds, while expire=3599 gives the remaining seconds before timeout, confirming an active established TCP session nearing expiry.

Why this answer

The output shows proto=6, which is TCP, and proto_state=01, which indicates the TCP session is in an established state (TCP_ESTABLISHED). The duration=3600 means the session has been active for 3600 seconds, and expire=3599 means it will expire in 3599 seconds (i.e., the idle timeout is counting down). This is a standard TCP session in the established state, not a multicast or UDP session.

Exam trap

The trap here is that candidates confuse proto_state=01 with a SYN_SENT or timed-out state, or misinterpret proto=6 as UDP, because they do not memorize the TCP state codes or protocol numbers used in FortiOS session diagnostics.

How to eliminate wrong answers

Option A is wrong because proto=6 is TCP, not multicast; multicast sessions use UDP (proto=17) and have different state codes. Option C is wrong because proto_state=01 represents TCP_ESTABLISHED, not SYN_SENT (which would be state 02); also, the session has not timed out—it is still active with an expiry counter. Option D is wrong because proto=6 is TCP, not UDP (UDP uses proto=17), and UDP sessions do not have a TCP state machine.

104
MCQhard

An administrator configures a multi-VDOM FortiGate in transparent mode. The admin notices that the management IP is reachable from both interfaces, but traffic passing through the device is not being inspected. What is the likely issue?

A.Inter-VDOM routing is misconfigured
B.The VDOM is in transparent mode, but no firewall policy is applied to the traffic
C.The FortiGate needs a default route
D.The management IP is assigned to the wrong VDOM
AnswerB

In transparent mode a VDOM still requires firewall policies to permit and inspect traffic; without one, frames are forwarded uninspected. The reachable management IP merely confirms the VDOM is up, so the missing policy is the actual cause of traffic bypassing inspection.

Why this answer

In transparent mode, a FortiGate acts as a Layer 2 bridge, and traffic passing through the device is controlled by firewall policies, not by routing. Even though the management IP is reachable (because it is a separate IP on the bridge interface), no traffic inspection occurs unless an explicit firewall policy is configured to allow and inspect the traffic between the bridge interfaces. Option B correctly identifies that the missing firewall policy is the root cause.

Exam trap

The trap here is that candidates assume transparent mode automatically inspects all traffic or that management IP reachability implies full functionality, but in reality, a firewall policy is mandatory for traffic inspection even in Layer 2 mode.

How to eliminate wrong answers

Option A is wrong because inter-VDOM routing is not relevant in a single-VDOM transparent mode setup; the issue is about intra-VDOM traffic passing through the bridge, not between VDOMs. Option C is wrong because a default route is used for management traffic originating from the FortiGate itself, not for transit traffic passing through the device in transparent mode; transit traffic is bridged and does not require a routing table. Option D is wrong because the management IP being reachable from both interfaces indicates it is correctly assigned to the VDOM; the problem is the lack of a firewall policy to inspect transit traffic, not a misassignment of the management IP.

105
MCQhard

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The default route in VDOM-A points to a next-hop router, and VDOM-B has a static route to a subnet behind VDOM-A. Users in VDOM-B cannot reach that subnet. The administrator runs 'diagnose ip route list' in both VDOMs and sees the routes are present. What is the most likely cause?

A.The VDOM link MTU is too small for the traffic
B.The VDOM link interfaces are administratively down
C.Firewall policies are missing on the VDOMs to permit traffic between the VDOM link and the destination interfaces
D.The VDOMs are in different administrative domains (ADOMs) on FortiManager
AnswerC

Routes exist in both VDOMs, so forwarding is resolved; the VDOM link interfaces and destination interfaces still require firewall policies to permit the traffic. Inter-VDOM routing is not implicitly allowed, so absent policies silently drop packets between VDOM-A and VDOM-B.

Why this answer

Even though the routes are present in both VDOMs, inter-VDOM routing via a VDOM link requires explicit firewall policies on each VDOM to permit traffic between the VDOM link interface and the destination interface. Without these policies, the FortiGate drops the traffic at the firewall layer, even though the routing table is correct. This is a common misconfiguration because VDOM links behave like physical interfaces and are subject to firewall policy enforcement.

Exam trap

The trap here is that candidates assume that because routes are present and the VDOM link is up, traffic should flow automatically, forgetting that FortiGate enforces firewall policies even for inter-VDOM traffic.

How to eliminate wrong answers

Option A is wrong because an MTU mismatch would cause fragmentation issues or packet drops, but the routes would still be present and the administrator would typically see ICMP fragmentation-needed messages or packet loss, not a complete inability to reach the subnet. Option B is wrong because if the VDOM link interfaces were administratively down, the routes would not appear in the routing table (the interface would be down, making the next-hop unreachable), and the administrator would see the interfaces in a 'down' state. Option D is wrong because ADOMs on FortiManager are a management-plane concept that controls visibility and administrative access, not data-plane forwarding; inter-VDOM routing is handled locally on the FortiGate and is unaffected by FortiManager ADOM configuration.

106
MCQmedium

A FortiGate has multiple equal-cost routes to the same destination via two different interfaces. ECMP load balancing is enabled. What determines how traffic is distributed among the routes?

A.The interface speed
B.A hash of source and destination IP addresses
C.Round-robin per packet
D.The route metric
AnswerB

ECMP distributes traffic per flow using a hash of source and destination IP addresses, so each conversation consistently follows one path while different flows spread across the equal-cost routes. This per-flow hashing preserves packet ordering and satisfies the stem's load-balancing requirement.

Why this answer

When ECMP load balancing is enabled on a FortiGate, traffic distribution among equal-cost routes is determined by a hash algorithm that uses source and destination IP addresses (and optionally ports) to select the egress interface. This ensures that all packets belonging to the same flow are consistently forwarded via the same path, preserving packet order and avoiding reordering issues.

Exam trap

The trap here is that candidates often assume ECMP uses round-robin or interface speed weighting, but FortiGate strictly uses a hash-based algorithm to maintain flow affinity and avoid packet reordering.

How to eliminate wrong answers

Option A is wrong because interface speed does not influence ECMP load balancing; FortiGate uses a hash-based selection, not a weighted distribution based on link speed. Option C is wrong because FortiGate does not use per-packet round-robin for ECMP; such a method would cause severe packet reordering and is not implemented in FortiGate's ECMP logic. Option D is wrong because the route metric is identical for all equal-cost routes by definition; ECMP only applies when metrics are equal, so metric does not determine distribution.

107
MCQmedium

A network administrator configures an SD-WAN zone with two members (port1 and port2) and sets the load balancing algorithm to 'spillover'. The spillover threshold is set to 100 Mbps on port1. If traffic reaches 120 Mbps on port1, what happens to new sessions?

A.All traffic is dropped because the threshold exceeded
B.New sessions are sent to port2 until port1 drops below the threshold
C.Port1 continues to receive all new sessions but packets are queued
D.New sessions are distributed equally between port1 and port2
AnswerB

Spillover forwards new sessions to the second member once the primary member exceeds its threshold, while existing sessions stay on port1. At 120 Mbps, above the 100 Mbps threshold, port2 receives new sessions until port1 falls back below the limit.

Why this answer

When the spillover algorithm is configured with a threshold of 100 Mbps on port1 and traffic reaches 120 Mbps, port1 is considered saturated. The SD-WAN zone then directs all new sessions to port2 until the traffic on port1 drops below the threshold. This is the defined behavior of spillover load balancing in Fortinet SD-WAN, where traffic is shifted away from an overloaded member to maintain performance.

Exam trap

The trap here is that candidates often confuse spillover with load balancing algorithms like 'lowest latency' or 'round-robin', incorrectly assuming that traffic is dropped, queued, or evenly distributed when the threshold is exceeded, rather than understanding that spillover is a failover-like mechanism that shifts new sessions to the next available member.

How to eliminate wrong answers

Option A is wrong because spillover does not drop traffic; it redirects new sessions to another member when the threshold is exceeded. Option C is wrong because spillover does not queue packets on the overloaded port; it actively moves new sessions to an alternate member. Option D is wrong because spillover does not distribute sessions equally; it sends all new sessions to the underutilized member (port2) until the primary member's load drops below the threshold.

108
MCQhard

A FortiGate is configured with an antivirus profile that has the machine learning engine enabled. An administrator notices that some files are being detected by the ML engine but the verdict is 'probably clean'. What does this verdict indicate?

A.The file is clean and safe to pass.
B.The file is definitely malicious and should be blocked.
C.The ML engine has detected an outbreak but needs FortiGuard to confirm.
D.The ML engine has low confidence that the file is malicious; it may be a false positive.
AnswerD

The 'probably clean' verdict means the machine learning engine has low confidence that the file is malicious, flagging possible false positives. It reflects probabilistic scoring rather than a definitive malicious determination, so the file is not treated as confirmed malware.

Why this answer

The ML engine in FortiGate's antivirus profile assigns a verdict of 'probably clean' when its confidence level is low that the file is malicious. This indicates a potential false positive, meaning the file is likely benign but the engine cannot be certain. The correct action is to allow the file to pass while logging the event for further analysis, not to block it outright.

Exam trap

The trap here is that candidates confuse 'probably clean' with 'clean' or assume it requires external verification, when in fact it is a low-confidence verdict designed to avoid blocking potentially safe files.

How to eliminate wrong answers

Option A is wrong because 'probably clean' does not guarantee the file is clean; it indicates low confidence, so the file should not be unconditionally passed without scrutiny. Option B is wrong because the ML engine does not have high enough confidence to classify the file as definitely malicious; blocking it would be too aggressive and could cause false positives. Option C is wrong because the ML engine does not require FortiGuard confirmation for 'probably clean' verdicts; that mechanism is used for 'outbreak' verdicts where the engine suspects a new threat and queries FortiGuard for real-time reputation.

109
MCQeasy

Which FortiGate feature allows an administrator to define a granular policy based on the security posture of the endpoint device, such as OS version, antivirus status, and disk encryption, before granting access to a protected application?

A.Web filtering profile
B.SSL VPN portal
C.IPsec phase 1 configuration
D.ZTNA access proxy
AnswerD

ZTNA access proxy evaluates endpoint posture — OS version, antivirus state, disk encryption — before granting application access, enforcing zero-trust checks per session. It satisfies the granular, posture-based policy requirement that conventional firewall rules cannot express.

Why this answer

FortiGate ZTNA access proxy enables granular policy enforcement based on endpoint security posture, such as OS version, antivirus status, and disk encryption. It acts as a reverse proxy that evaluates ZTNA tags (derived from endpoint posture) before granting access to protected applications, aligning with zero-trust principles.

Exam trap

NSE7 often tests the distinction between ZTNA access proxy and other FortiGate features, leading candidates to confuse it with SSL VPN or web filtering for endpoint posture enforcement.

How to eliminate wrong answers

Option A is wrong because web filtering profiles control access to web content based on categories, not endpoint posture. Option B is wrong because SSL VPN portal provides remote access but does not inherently enforce endpoint posture checks for application access. Option C is wrong because IPsec phase 1 configuration is for establishing VPN tunnels, not for granular application access based on endpoint posture.

110
MCQhard

An administrator configures automation stitches on FortiManager to trigger a script when a specific event log is received. The script should block the source IP on the firewall. However, the script does not run when the event occurs. What is a likely cause?

A.The event handler filter does not match the log
B.The FortiGate is in transparent mode
C.The script is not compiled
D.The script is set to run on all managed devices
AnswerA

Automation stitches fire only when the event handler's filter matches the incoming log. If the filter criteria do not match the log's fields or values, the stitch never triggers, so the blocking script is never executed despite the event occurring.

Why this answer

Automation stitches on FortiManager rely on event handler filters to match specific log IDs or patterns. If the filter does not match the incoming event log (e.g., wrong log ID, incorrect field value, or mismatched severity), the trigger condition is never met, and the script will not execute. This is the most common misconfiguration when setting up event-driven automation.

Exam trap

The trap here is that candidates may assume the script itself has a syntax error or that transparent mode disables automation, but the real issue is almost always a filter mismatch in the event handler configuration.

How to eliminate wrong answers

Option B is wrong because FortiGate transparent mode does not prevent automation stitches from running; the script execution is independent of the firewall's operational mode. Option C is wrong because FortiManager scripts are interpreted, not compiled, so there is no compilation step required. Option D is wrong because setting the script to run on all managed devices would not prevent it from running; it would simply apply the script to every device, which could cause unintended behavior but does not block execution.

111
MCQeasy

A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?

A.Antivirus profile
B.Web Filtering profile
C.Data Leak Prevention profile
D.Email Filtering profile
AnswerD

The Email Filtering profile inspects SMTP, IMAP and POP3 traffic, blocking messages based on sender reputation and embedded malicious URLs. It satisfies the requirement to detect and block phishing emails containing malicious links, which antivirus or web filtering alone cannot fully address.

Why this answer

FortiGate's Email Filtering profile is specifically designed to inspect SMTP, POP3, and IMAP traffic for phishing indicators, including malicious URLs in email bodies and attachments. It can block or quarantine emails based on URL reputation, sender authentication (SPF/DKIM/DMARC), and content analysis, directly addressing the requirement to detect and block phishing emails with malicious links.

Exam trap

The trap here is that candidates often confuse Web Filtering (which handles web traffic) with Email Filtering (which handles email protocols), assuming URL reputation checks in web filtering can block phishing links in emails, but FortiGate requires the Email Filtering profile to inspect SMTP/IMAP/POP3 traffic and apply email-specific actions like quarantine.

How to eliminate wrong answers

Option A is wrong because the Antivirus profile scans for malware signatures in file attachments and does not analyze URLs or email-specific phishing patterns; it would miss malicious links that do not contain executable payloads. Option B is wrong because the Web Filtering profile controls HTTP/HTTPS traffic based on URL categories and reputation, but it operates on web proxy traffic, not on email protocols like SMTP, and cannot inspect or block emails before they reach the user's inbox. Option C is wrong because the Data Leak Prevention profile monitors and prevents unauthorized data exfiltration (e.g., credit card numbers, SSNs) and has no capability to detect phishing links or email-based threats.

112
MCQmedium

A FortiGate administrator notices that traffic classified as 'unknown' by the antivirus is being allowed. The administrator wants to ensure that such files are submitted to FortiSandbox for analysis and blocked until a verdict is received. Which configuration is required?

A.Create a custom IPS signature for unknown files
B.Enable FortiSandbox in the antivirus profile and set 'Action for unknown files' to 'Block'
C.Enable outbreak prevention in the antivirus profile
D.Enable FortiSandbox in the antivirus profile and set 'Action for known files' to 'Block'
AnswerB

FortiSandbox integration in the antivirus profile submits unknown files for dynamic analysis, and setting 'Action for unknown files' to Block enforces a hold until a verdict returns. This directly satisfies the requirement to submit and block unknown traffic rather than permit it.

Why this answer

When FortiSandbox is enabled in the antivirus profile and 'Action for unknown files' is set to 'Block', the FortiGate will submit files that cannot be identified by the local antivirus engine to FortiSandbox for analysis. While the file is being analyzed, it is blocked from reaching the client, ensuring that no potentially malicious content is delivered until a verdict (clean or malicious) is received. This directly addresses the administrator's requirement to block unknown files pending sandbox analysis.

Exam trap

The trap here is that candidates often confuse 'Action for unknown files' with 'Action for known files' or mistakenly think that outbreak prevention (which uses FortiGuard outbreak signatures) is sufficient to block unknown files, when in fact only the sandbox integration with the 'Block' action provides the required submission and blocking behavior.

How to eliminate wrong answers

Option A is wrong because custom IPS signatures are designed to detect and block network-level attacks based on traffic patterns, not to handle unknown files identified by the antivirus engine; IPS does not integrate with FortiSandbox for file submission. Option C is wrong because outbreak prevention in the antivirus profile uses FortiGuard outbreak alerts to block files based on known outbreak signatures, but it does not submit unknown files to FortiSandbox or block them pending analysis; it relies on pre-existing outbreak intelligence. Option D is wrong because setting 'Action for known files' to 'Block' would block files that are already identified by the antivirus engine, which is the opposite of the requirement; the administrator needs to block unknown files, not known ones.

113
MCQeasy

What does FortiGuard Outbreak Prevention use to protect against newly discovered malware outbreaks before traditional signatures are available?

A.Outbreak signatures and hash-based blocking
B.IP reputation and URL filtering
C.Heuristic analysis and emulation
D.Artificial intelligence and behavior analysis
AnswerA

Outbreak signatures are pushed ahead of conventional antivirus definitions, and hash-based blocking immediately denies files matching known malicious hashes. Together they satisfy the stem's constraint: protection against newly discovered outbreaks before traditional signatures become available.

Why this answer

FortiGuard Outbreak Prevention uses outbreak signatures and hash-based blocking to provide rapid protection against newly discovered malware outbreaks before traditional signatures are available. Outbreak signatures are lightweight, pattern-based detections that can be deployed quickly, while hash-based blocking allows immediate blocking of known malicious file hashes, even when full signature analysis is not yet complete.

Exam trap

The trap here is that candidates often confuse outbreak prevention with sandboxing or heuristic analysis, but FortiGuard Outbreak Prevention specifically relies on rapidly deployable outbreak signatures and hash-based blocking, not on behavioral or AI-based analysis.

How to eliminate wrong answers

Option B is wrong because IP reputation and URL filtering are network-layer controls that block known malicious hosts or URLs, but they do not directly detect or block malware files themselves, making them insufficient for outbreak prevention. Option C is wrong because heuristic analysis and emulation are proactive detection methods used in sandboxing or advanced threat protection, but they are not the primary mechanism for FortiGuard Outbreak Prevention, which relies on rapidly deployable signatures and hashes. Option D is wrong because artificial intelligence and behavior analysis are advanced techniques used in FortiSandbox or FortiAI, but they are not the core technology behind FortiGuard Outbreak Prevention, which focuses on immediate, signature-based blocking.

114
MCQhard

An administrator is troubleshooting an HA cluster (active-passive) where both units show 'primary' in 'get system ha status'. The cluster is not synchronizing configurations. What is the MOST likely cause?

A.The HA password is incorrect
B.The HA heartbeat interface is disconnected or misconfigured
C.The HA group ID is mismatched
D.The HA priority values are equal for both units
AnswerB

If heartbeat communication fails, each unit assumes the other is down and transitions to primary, causing a split-brain.

Why this answer

In an active-passive HA cluster, both units showing 'primary' indicates a failure in heartbeat communication. The HA heartbeat interface is used to exchange cluster state and session information; if it is disconnected or misconfigured, each unit assumes the other is down and transitions to primary, leading to a split-brain scenario. This prevents configuration synchronization because the units cannot agree on a primary-secondary role.

Exam trap

The trap here is that candidates often assume an HA password mismatch or group ID mismatch causes role conflicts, but in reality, a heartbeat failure is the only scenario that makes both units independently declare themselves primary.

How to eliminate wrong answers

Option A is wrong because an incorrect HA password would cause authentication failures during heartbeat exchanges, but both units would still show their correct roles (primary/secondary) based on priority; they would not both become primary. Option C is wrong because a mismatched HA group ID would prevent the cluster from forming entirely, resulting in both units showing as standalone or 'standalone', not both as 'primary'. Option D is wrong because equal HA priority values do not cause both units to become primary; in an active-passive cluster, if priorities are equal, the unit with the higher serial number becomes primary, and the other becomes secondary, so both would not show 'primary'.

115
MCQhard

A FortiGate is configured as a hub in an ADVPN with multiple spokes. The administrator notices that some spokes are not learning routes from other spokes, even though the ADVPN tunnel is up. The hub is using BGP for routing. Which configuration on the hub is required to enable spoke-to-spoke route propagation?

A.Configure the hub as a BGP route reflector and set the spokes as route reflector clients.
B.Set the hub's BGP router ID to match the IPsec tunnel IP address.
C.Enable multihop on the hub's BGP peering with the spokes.
D.Enable split-horizon on the hub's IPsec tunnel interfaces.
AnswerA

In an ADVPN hub-and-spoke topology, the hub must act as a BGP route reflector to propagate routes between spokes. By configuring the hub as a route reflector and the spokes as clients, the hub can reflect routes learned from one spoke to other spokes. This enables spoke-to-spoke communication over dynamic tunnels.

Why this answer

For spoke-to-spoke route propagation in ADVPN, the hub must be configured as a BGP route reflector. This allows the hub to reflect routes received from one spoke to other spokes, enabling dynamic tunnel establishment between spokes. Without route reflection, spokes only learn routes from the hub and cannot directly reach other spokes.

Exam trap

The trap here is confusing route reflection with other BGP features like split-horizon or multihop, which do not enable spoke-to-spoke route propagation in ADVPN.

116
MCQeasy

What is the purpose of header and footer policies in a FortiManager policy package?

A.They are used for VDOM-specific policies that cannot be modified
B.They provide a way to group policies for reporting purposes
C.They define policies that are placed at the top (header) and bottom (footer) of the policy list when applied to a FortiGate
D.They allow policy packages to be installed in a specific sequence
AnswerC

Header and footer policies sit at the very top and bottom of the policy list once the package is installed on a FortiGate, giving administrators guaranteed precedence for global allow or deny rules regardless of where other policies are inserted.

Why this answer

Header and footer policies in FortiManager policy packages allow administrators to define policies that are automatically placed at the very top (header) and very bottom (footer) of the policy list when the package is installed on a FortiGate. This ensures that critical policies, such as default deny rules or inter-VDOM links, remain in a fixed position regardless of other policy changes. This mechanism is essential for maintaining a consistent security posture across managed FortiGates.

Exam trap

The trap here is that candidates often confuse header/footer policies with VDOM-specific policies or policy grouping, when in fact they are specifically designed to enforce a fixed policy order at the top and bottom of the policy list.

How to eliminate wrong answers

Option A is wrong because header and footer policies are not VDOM-specific; they are part of the policy package and can be modified like any other policy. Option B is wrong because header and footer policies are not used for grouping policies for reporting; reporting groups are handled via policy tags or separate grouping features. Option D is wrong because header and footer policies do not control the installation sequence of policy packages; installation sequence is managed by the 'Installation Order' setting in FortiManager, not by header/footer policies.

117
MCQeasy

What is the primary purpose of an administrative VDOM on a FortiGate?

A.To enable transparent mode operation
B.To increase the maximum number of firewall policies
C.To provide independent management and administrative access for different tenants or departments
D.To route traffic between different VDOMs
AnswerC

An administrative VDOM isolates management functions, giving each tenant or department its own administrators, routing and configuration scope without affecting others. This satisfies the stem's requirement for independent management and administrative access, since each VDOM maintains separate admin accounts, policies and objects within the single FortiGate device.

Why this answer

An administrative VDOM on a FortiGate provides independent management and administrative access for different tenants or departments. Each administrative VDOM has its own administrator accounts, authentication settings, and management interfaces (HTTPS, SSH, SNMP), allowing multi-tenant isolation without requiring separate physical firewalls. This is distinct from traffic-forwarding VDOMs, which handle data plane operations.

Exam trap

The trap here is confusing the management-plane isolation of an administrative VDOM with data-plane functions like inter-VDOM routing or transparent mode, leading candidates to select options that describe traffic forwarding or operational modes instead of administrative separation.

How to eliminate wrong answers

Option A is wrong because transparent mode operation is a per-VDOM setting (config system vdom edit <vdom> set mode transparent), not a purpose of an administrative VDOM; administrative VDOMs can operate in either transparent or NAT mode. Option B is wrong because the maximum number of firewall policies is limited by the FortiGate model and total VDOM resources, not by the presence of an administrative VDOM; an administrative VDOM does not increase policy limits. Option D is wrong because routing traffic between different VDOMs is accomplished via inter-VDOM links (config system vdom-link) or VDOM peering, not by an administrative VDOM, which is solely for management plane separation.

118
MCQeasy

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that a specific VDOM can use more system resources, such as sessions and CPU, than other VDOMs. Which FortiGate feature should the administrator use?

A.Configure per-VDOM resource limits in the VDOM settings.
B.Enable NPU offloading for the VDOM to increase its throughput.
C.Create a separate administrative profile for the VDOM with elevated privileges.
D.Assign a higher priority to the VDOM in the global VDOM configuration.
AnswerA

FortiGate allows administrators to set resource limits per VDOM, such as maximum sessions, CPU usage, and memory. This ensures that a VDOM can be allocated more resources or restricted to prevent it from consuming all system resources. The administrator can adjust these limits for the specific VDOM that requires more resources.

Why this answer

To allocate more system resources to a specific VDOM, the administrator should configure per-VDOM resource limits. FortiGate allows setting maximum sessions, CPU usage, memory, and other resources on a per-VDOM basis. This ensures that the VDOM has sufficient resources while preventing it from monopolizing system resources.

This is the correct feature for resource allocation in multi-VDOM deployments.

Exam trap

The trap here is confusing performance optimization features like NPU offloading with resource allocation controls such as per-VDOM limits.

119
MCQeasy

Which FortiAnalyzer feature allows administrators to create automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected?

A.FortiView
B.Reports
C.Incidents
D.Playbooks
AnswerD

Playbooks in FortiAnalyzer chain automated response actions to log-event triggers, so an intrusion detection event can invoke a block-IP action without manual intervention. This satisfies the requirement for automated, event-driven response rather than static alerting or scheduled reports.

Why this answer

Playbooks in FortiAnalyzer allow administrators to define automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected. This feature uses a visual workflow editor to chain conditions and actions (e.g., executing CLI commands via FortiGate API or sending alerts) based on real-time log analysis, enabling automated threat mitigation without manual intervention.

Exam trap

The trap here is that candidates confuse Playbooks with Incidents, assuming Incidents include automation, but Incidents are purely for manual or semi-manual investigation workflows, while Playbooks are the only feature for fully automated, event-triggered responses.

How to eliminate wrong answers

Option A is wrong because FortiView is a real-time monitoring and visualization tool that displays traffic logs, sessions, and security events, but it does not provide automation or trigger-based response actions. Option B is wrong because Reports are scheduled or on-demand document generation tools for summarizing historical data, not for executing automated responses to live events. Option C is wrong because Incidents are a grouping mechanism for related alerts and logs to aid investigation, but they do not include automated action execution like blocking IPs.

120
MCQeasy

What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?

A.To remove potentially malicious content from documents and rebuild them as safe files
B.To convert files into PDF format for safer viewing
C.To detect zero-day malware using sandboxing
D.To block all files containing macros
AnswerA

CDR strips active content — macros, embedded scripts, hyperlinks — from documents, then rebuilds a clean, functional file, satisfying the requirement to neutralise threats rather than merely detect them. Unlike signature-based scanning, which fails against zero-day or polymorphic payloads, this reconstruction guarantees the delivered file contains no executable code.

Why this answer

Content Disarm and Reconstruction (CDR) is designed to remove active or potentially malicious content—such as macros, scripts, embedded objects, and OLE links—from documents (e.g., Office files, PDFs) and then reconstruct them as sanitized, safe versions. This approach prevents threats like macro-based malware or exploit-laden attachments from reaching users, even if the file contains previously unknown (zero-day) payloads, by stripping the dangerous components rather than relying solely on signature-based detection.

Exam trap

The trap here is that candidates often confuse CDR with sandboxing or macro blocking, but CDR is a static sanitization technique that removes active content from files without detonating them, whereas sandboxing involves dynamic analysis and macro blocking is a simpler, all-or-nothing approach that CDR avoids by allowing safe use of the document.

How to eliminate wrong answers

Option B is wrong because CDR does not convert files to PDF format; it sanitizes the original file format (e.g., DOCX, XLSX, PDF) and returns a cleaned version in the same format, not a different one. Option C is wrong because CDR is not a sandboxing or dynamic analysis feature; it statically disarms content by removing active elements, whereas sandboxing (e.g., FortiSandbox) detonates files in a virtual environment to detect zero-day malware. Option D is wrong because CDR does not block all files containing macros; it removes the macros and other active content from the file and then delivers the sanitized file, allowing the document to be used safely without the macro functionality.

121
MCQmedium

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A.The session has expired and is being removed
B.A UDP session on port 443 is being blocked
C.The firewall policy is incorrectly configured
D.A TCP session on port 443 has been active for 1 hour and will expire in 3599 seconds
AnswerD

The output shows proto=6 (TCP), duration=3600 seconds (one hour active) and expire=3599 seconds remaining. This precisely matches a TCP session on destination port 443 that has run for an hour and will time out in 3599 seconds.

Why this answer

The output shows a TCP session (proto=6) on port 443 with a duration of 3600 seconds (1 hour) and an expire value of 3599 seconds, meaning the session has been active for 1 hour and will expire in 3599 seconds. The 'proto=6' indicates TCP, and 'proto_state=01' is the TCP established state, confirming an active TCP session.

Exam trap

The trap here is that candidates may misinterpret 'expire=3599' as the session expiring soon or already expired, when in fact it indicates the remaining time before timeout, and the session is still active with a duration of 3600 seconds.

How to eliminate wrong answers

Option A is wrong because the expire value of 3599 seconds indicates the session is still active and will expire in the future, not that it has expired and is being removed. Option B is wrong because proto=6 indicates TCP, not UDP, and the session is not being blocked; it is active. Option C is wrong because the output does not provide any information about firewall policy configuration; it only shows session state and timing details.

122
MCQeasy

An administrator wants to ensure that voice traffic (UDP 16384-32768) always uses the MPLS link, while internet-bound traffic uses broadband. Which SD-WAN feature should be configured to achieve this?

A.Performance SLA
B.SD-WAN member configuration
C.Load balancing algorithm
D.SD-WAN rule
AnswerD

An SD-WAN rule matches traffic by application or UDP port range and directs it to a preferred member, so voice (UDP 16384-32768) can be pinned to the MPLS link while internet-bound traffic egresses broadband, satisfying the required path separation.

Why this answer

SD-WAN rules (option D) allow administrators to define policy-based forwarding by matching specific traffic characteristics—such as UDP ports 16384-32768 for voice—and steering that traffic to a preferred interface or link (e.g., the MPLS link). This is the correct feature because it directly controls traffic steering based on application or service, overriding any default load-balancing or failover behavior.

Exam trap

The trap here is that candidates confuse Performance SLA (which monitors and reacts to link quality) with the policy engine that actually decides which traffic goes where, leading them to select option A instead of the correct SD-WAN rule.

How to eliminate wrong answers

Option A is wrong because Performance SLA measures link quality (latency, jitter, packet loss) and triggers link failover or path selection changes, but it does not define which traffic uses which link; it only reacts to link degradation. Option B is wrong because SD-WAN member configuration defines the physical or logical interfaces participating in the SD-WAN zone and their roles (e.g., gateway, cost), but it does not contain the policy logic to steer specific UDP port ranges to a particular link. Option C is wrong because the load balancing algorithm (e.g., source-destination-IP hash, volume-based) distributes traffic across multiple links based on a mathematical formula, not on application-level criteria like UDP port ranges; it cannot guarantee voice traffic always uses the MPLS link.

123
MCQmedium

A FortiGate 600E is running in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator assigns physical port3 to VDOM-1 as a dedicated interface, then creates a VLAN subinterface (VLAN 100) on port3 for VDOM-2. After configuration, VLAN 100 traffic is dropped even though the VLAN interface is up. Which action resolves the issue?

A.Configure a VDOM link between VDOM-1 and VDOM-2 and route VLAN 100 traffic through the link.
B.Enable the vlan-forwarding setting under config system interface on port3.
C.Assign the physical port3 interface to VDOM-2 as well, using the same interface in both VDOMs.
D.Create the VLAN 100 subinterface inside VDOM-1, where the parent interface resides, rather than in VDOM-2.
AnswerD

VLAN subinterfaces must be created on the parent interface within the same VDOM that owns the parent. Since port3 belongs to VDOM-1, VLAN 100 must be defined in VDOM-1. If VDOM-2 needs separate VLAN traffic, the parent interface should be shared or a different physical interface used in VDOM-2.

Why this answer

On FortiGate, VLAN subinterfaces inherit the VDOM membership of their parent physical interface. Because port3 is assigned to VDOM-1, VLAN 100 must also be created within VDOM-1. Creating it under VDOM-2 leaves the traffic unhandled in the VDOM that actually receives the frames, so frames are dropped.

Exam trap

The trap here is assuming that a subinterface can be placed in a different VDOM than its parent interface, which is not supported on FortiGate.

124
MCQmedium

A FortiGate VPN tunnel shows 'phase1 negotiation failed' in the logs. The remote gateway is a third-party device. The debug command 'diagnose vpn ike config' shows mismatched proposals. Which setting is MOST likely incorrect on the FortiGate?

A.The pre-shared key
B.The local ID type
C.The encryption algorithm (e.g., AES256 vs 3DES)
D.The DPD configuration
AnswerC

Phase 1 negotiation fails when the two peers' IKE proposals do not intersect. A mismatched encryption algorithm, such as AES256 against 3DES, means no common transform is offered, so the FortiGate's phase 1 proposal must be aligned with the third-party gateway's supported encryption.

Why this answer

The 'diagnose vpn ike config' command displays the IKE proposal parameters (encryption, authentication, DH group) that the FortiGate is configured to offer. When the log shows 'phase1 negotiation failed' and the debug output indicates 'mismatched proposals', it means the FortiGate's configured encryption algorithm (e.g., AES256) does not match any algorithm supported by the remote third-party device (e.g., 3DES). This is the most direct cause of proposal mismatch, as IKE phase 1 requires both sides to agree on a common transform set.

Exam trap

The trap here is that candidates often confuse 'mismatched proposals' with authentication failures (pre-shared key) or identification issues (local ID), but the debug command specifically shows the proposal attributes, making encryption algorithm the most likely culprit.

How to eliminate wrong answers

Option A is wrong because a pre-shared key mismatch would cause an authentication failure after the proposal is accepted, not a 'mismatched proposals' error in the IKE config debug. Option B is wrong because the local ID type is used for identification and policy matching after phase 1 is established; it does not affect the initial proposal exchange. Option D is wrong because DPD (Dead Peer Detection) is a keepalive mechanism configured after phase 1 is complete; a DPD mismatch would not cause a phase 1 negotiation failure.

125
MCQeasy

An administrator is configuring a FortiGate for SD-WAN and wants to ensure that outgoing traffic from the internal network is distributed across two WAN links based on the number of active sessions. Which SD-WAN load balancing algorithm should be used?

A.Weighted round robin
B.Source IP based
C.Volume
D.Session count
AnswerD

The 'session count' algorithm selects the WAN member with the fewest active sessions. This directly satisfies the requirement to load balance based on the number of active sessions. It dynamically adjusts as sessions are created and torn down, making it ideal for scenarios where session load is the primary concern. This is the correct choice for the described scenario.

Why this answer

The 'session count' SD-WAN algorithm selects the member with the fewest active sessions, which directly load balances based on session count. Other algorithms like source IP, volume, or weighted round robin use different criteria such as source address, data volume, or static weights, and do not dynamically balance based on the number of active sessions. Therefore, 'session count' is the correct choice.

Exam trap

The trap here is confusing 'volume' with 'session count'; volume balances data usage, while session count balances the number of connections.

126
MCQeasy

A FortiGate administrator wants to use BFD to quickly detect link failures in an SD-WAN deployment. Which statement about BFD configuration on FortiGate is correct?

A.BFD is enabled by default on all FortiGate interfaces
B.BFD can be configured under the interface or routing protocol to detect forwarding path failures
C.BFD sessions are established automatically when OSPF neighbors form
D.BFD uses performance SLA probes to determine link health
AnswerB

BFD operates as a lightweight, protocol-independent hello mechanism that can be bound either directly to an interface or to a routing protocol such as BGP or OSPF. This dual placement lets it detect forwarding-path failures at sub-second intervals, satisfying the SD-WAN requirement for rapid link-failure detection.

Why this answer

BFD (Bidirectional Forwarding Detection) on FortiGate can be configured either directly on an interface or under a dynamic routing protocol (such as OSPF or BGP). When configured under the interface, BFD monitors the forwarding path to that specific neighbor; when configured under the routing protocol, it provides sub-second failure detection for routes learned via that protocol. This flexibility allows the administrator to tailor BFD to the SD-WAN deployment's needs, ensuring rapid link failure detection without relying on routing protocol timers.

Exam trap

The trap here is that candidates often confuse BFD with performance SLA probes or assume BFD is automatically enabled with routing protocols, but FortiGate requires explicit BFD configuration and BFD does not measure link quality metrics like jitter or packet loss.

How to eliminate wrong answers

Option A is wrong because BFD is not enabled by default on any FortiGate interface; it must be explicitly enabled per interface or per routing protocol. Option C is wrong because BFD sessions are not automatically established when OSPF neighbors form; BFD must be explicitly enabled under the OSPF configuration (e.g., 'set bfd enable' under the OSPF interface or process) for the sessions to be created. Option D is wrong because BFD does not use performance SLA probes; BFD uses its own lightweight hello and echo packets to detect failures, while performance SLA probes are used by SD-WAN rules for link quality measurement (jitter, latency, packet loss).

127
MCQeasy

A FortiGate administrator needs to verify that the firewall is correctly identifying and logging a specific application, 'Facebook', that is being used by internal users. The administrator has already configured an application control profile with logging enabled for Facebook. Which CLI command should the administrator use to view the application control logs in real-time?

A.diagnose debug enable
B.diagnose debug application appctrl -1
C.diagnose sys session list
D.diagnose debug application ipsmonitor -1
AnswerB

The command 'diagnose debug application appctrl -1' enables debug output for the application control daemon, which shows real-time information about application identification and logging. This allows the administrator to see when Facebook is detected and logged. It is the most direct way to verify application control logging in real-time.

Why this answer

To view application control logs in real-time, the administrator should use the debug command for the application control daemon. The 'diagnose debug application appctrl -1' command provides detailed output about application identification and logging decisions. This is more specific than general debug commands and directly addresses the need to verify that Facebook is being identified and logged.

Other commands like ipsmonitor debug or session list do not provide the same level of detail for application control logs.

Exam trap

The trap here is confusing IPS engine debugging with application control debugging; they are separate processes, and only the appctrl debug shows application control logs.

128
MCQmedium

An enterprise FortiGate has multiple VDOMs. The administrator wants to allow traffic from VDOM A to reach servers in VDOM B without traversing an external router. Which configuration is required?

A.Place both VDOMs in the same VDOM group
B.Configure a static route in each VDOM pointing to the other VDOM's management IP
C.Create an inter-VDOM link using the 'config system interface' command with type 'vdom-link'
D.Enable VDOM forwarding in global settings
AnswerC

A vdom-link interface creates a direct virtual connection between VDOMs, allowing traffic to pass internally without an external router. Configuring it via 'config system interface' with type 'vdom-link' satisfies the requirement for VDOM A to reach VDOM B servers without external routing.

Why this answer

Inter-VDOM links are the native FortiGate mechanism for routing traffic between VDOMs without external hardware. Created via 'config system interface' with type 'vdom-link', they act as a direct Layer 3 connection between VDOMs, allowing traffic to flow internally through the FortiGate's backplane. This avoids the need for an external router or physical cabling.

Exam trap

The trap here is that candidates often confuse enabling VDOM forwarding (a global toggle) with creating the actual inter-VDOM link, assuming the toggle alone allows traffic to flow between VDOMs without an explicit interface configuration.

How to eliminate wrong answers

Option A is wrong because VDOM groups are used for administrative grouping or shared resources (like VDOMs in a security fabric), not for enabling Layer 3 traffic forwarding between VDOMs. Option B is wrong because static routes pointing to a VDOM's management IP would only reach the management interface, not forward data traffic to the other VDOM's networks; management IPs are not used for data-plane forwarding. Option D is wrong because VDOM forwarding (enabled via 'config system global' with 'vdom-forward') controls whether the FortiGate can forward traffic between VDOMs at all, but it does not create the actual link or interface needed for inter-VDOM communication; an inter-VDOM link is still required.

129
MCQmedium

A FortiGate administrator is troubleshooting high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which action should the administrator take to reduce the CPU usage while maintaining security?

A.Disable IPS globally.
B.Adjust the IPS fail-open setting to enable fail-open.
C.Increase the FortiGate's memory allocation to the ipsengine process.
D.Review and optimize the IPS sensor configuration to reduce the number of signatures or adjust anomaly thresholds.
AnswerD

Optimizing the IPS sensor by removing unnecessary signatures, adjusting thresholds, or applying IPS only to relevant policies can significantly reduce CPU usage while still providing essential protection. This approach maintains security by focusing on the most critical threats and avoiding unnecessary inspection overhead.

Why this answer

The ipsengine process handles IPS inspection. High CPU usage can be mitigated by optimizing the IPS sensor configuration, such as disabling signatures that are not relevant to the environment, reducing the number of policies with IPS enabled, or adjusting anomaly thresholds. This maintains security by keeping essential protections while reducing the processing load.

Exam trap

The trap here is thinking that disabling IPS or enabling fail-open are acceptable trade-offs, but they weaken security; optimization is the better approach.

130
MCQeasy

A company has two internet connections: a primary fiber link (port1, 100 Mbps) and a backup DSL link (port2, 20 Mbps). They are using SD-WAN to load balance traffic based on volume, with a rule that sends 70% of traffic to port1 and 30% to port2. Recently, users report that video conferencing applications are experiencing high latency and jitter. The network team finds that the SD-WAN performance SLA for the fiber link shows 80% packet loss and high latency. The SD-WAN rule action is set to 'best quality' with a latency threshold of 150 ms. The current latency on port1 is 200 ms, and on port2 is 40 ms. What should the administrator do to ensure that video conferencing traffic uses the DSL link while the fiber link is degraded?

A.Increase the SLA latency threshold to 250 ms so that the fiber link is considered acceptable.
B.Change the SD-WAN rule action to 'lowest cost' to favor the DSL link.
C.Adjust the volume ratio to send 100% of traffic to port2 until the fiber link recovers.
D.No changes are needed; the SD-WAN rule with 'best quality' will automatically use port2 for new sessions because port1 does not meet the SLA.
AnswerD

The 'best quality' action evaluates SLA per session and steers new sessions to port2, which meets the 150 ms latency threshold while port1 at 200 ms does not. Existing sessions may need re-establishment, but new video sessions use the DSL link automatically.

Why this answer

The SD-WAN rule action is set to 'best quality', which means the FortiGate will automatically steer new sessions away from any interface that fails the performance SLA. Since port1 has 80% packet loss and 200 ms latency (exceeding the 150 ms threshold), it is considered degraded, and new video conferencing traffic will be directed to port2 (40 ms latency) without manual intervention.

Exam trap

The trap here is that candidates often assume manual configuration (like changing thresholds or ratios) is required to fix a degraded link, when in fact the 'best quality' action with performance SLA already provides automatic failover to the best-performing link.

How to eliminate wrong answers

Option A is wrong because increasing the SLA latency threshold to 250 ms would make the degraded fiber link appear acceptable, causing traffic to continue using the high-latency, high-packet-loss link and defeating the purpose of SLA monitoring. Option B is wrong because changing the rule action to 'lowest cost' would select the link based on cost metrics (e.g., bandwidth cost), not performance, and the DSL link might not be the lowest cost; even if it were, this action does not consider SLA compliance for latency and jitter. Option C is wrong because manually adjusting the volume ratio to 100% on port2 is a static workaround that bypasses the dynamic SLA-based steering, which is less efficient and not necessary when the 'best quality' action already handles failover automatically.

131
MCQeasy

Which FortiGate command is used to view the current CPU usage of individual processes in real time?

A.diagnose sys session stat
B.get system performance status
C.diagnose sys top
D.diagnose hardware sysinfo memory
AnswerC

`diagnose sys top` refreshes process-level CPU and memory statistics live, satisfying the real-time per-process requirement. Unlike `get system performance status`, which reports only aggregate CPU averages, it lists each running process individually, letting you identify the specific daemon consuming resources.

Why this answer

The 'diagnose sys top' command on FortiGate provides a real-time, top-like display of CPU and memory usage for individual processes, allowing administrators to identify which specific daemons or tasks are consuming resources. This command is essential for troubleshooting performance issues at the process level, unlike other commands that show aggregate or different diagnostic data.

Exam trap

The trap here is that candidates often confuse 'get system performance status' (which shows overall CPU usage) with the per-process view needed for granular troubleshooting, leading them to select option B instead of the correct 'diagnose sys top'.

How to eliminate wrong answers

Option A is wrong because 'diagnose sys session stat' displays session statistics (total sessions, active sessions, etc.) and does not show CPU usage per process. Option B is wrong because 'get system performance status' shows overall system performance metrics (CPU, memory, disk) but not per-process CPU usage in real time. Option D is wrong because 'diagnose hardware sysinfo memory' reports memory hardware information and usage statistics, not CPU usage per process.

132
Drag & Dropmedium

Drag and drop the steps to configure a FortiGate VDOM in multi-VDOM mode into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First enable VDOM mode globally, then create and assign interfaces, then configure each VDOM, then resource allocation.

133
MCQmedium

A FortiGate is configured with a WAF profile to protect a web server. The administrator notices that SQL injection attacks are still reaching the server despite the WAF being enabled. What is the MOST likely reason?

A.The SQL injection signature set is disabled in the WAF profile
B.The attack is coming from a trusted IP
C.The web server is using HTTPS without SSL inspection
D.The WAF profile is not applied to the correct policy
AnswerA

Disabled SQL injection signatures leave the WAF inspecting traffic but matching nothing, so malicious payloads pass to the server. FortiGate's signature-based detection only blocks attacks whose signatures are enabled in the profile; the stem's constraint — WAF active yet injections still arriving — is satisfied precisely because that signature category was switched off.

Why this answer

The WAF profile contains signature sets that detect and block common attack patterns, including SQL injection. If the SQL injection signature set is disabled within the profile, the WAF will not inspect traffic for those patterns, allowing attacks to pass through. This is the most direct and likely reason why SQL injection attacks are reaching the server despite the WAF being enabled.

Exam trap

The trap here is that candidates often assume a WAF profile is a monolithic block of protection, but FortiGate allows granular disabling of individual signature sets, and the exam tests whether you understand that a disabled signature set is the most direct cause of a specific attack type bypassing the WAF.

How to eliminate wrong answers

Option B is wrong because a trusted IP exception would only bypass WAF inspection for traffic from that specific source; it would not explain why SQL injection attacks from other sources are still reaching the server. Option C is wrong because HTTPS without SSL inspection means the WAF cannot decrypt the payload, but FortiGate can still inspect encrypted traffic using certificate-based inspection or flow-based inspection with SSL offloading; the lack of SSL inspection would block all inspection, not just SQL injection. Option D is wrong because if the WAF profile were not applied to the correct policy, no WAF inspection would occur at all, and the administrator would likely see no WAF-related logs or blocking; the question states the WAF is enabled, implying it is applied somewhere.

134
MCQmedium

A FortiGate running FortiOS 7.4.1 has two VDOMs: CustomerA and CustomerB. The administrator wants CustomerA to access an HTTP server in CustomerB. Both VDOMs have appropriate policies. What additional configuration is required?

A.Configure a VDOM link between CustomerA and CustomerB
B.Create a policy allowing traffic from CustomerA to CustomerB
C.Enable inter-VDOM routing under system settings
D.Assign both VDOMs to the same administrative domain in FortiManager
AnswerA

Inter-VDOM routing requires a VDOM link, a virtual point-to-point interface pair connecting the two VDOMs. Without it, traffic from CustomerA cannot reach CustomerB even when both have correct policies, because VDOMs are isolated routing instances.

Why this answer

A VDOM link is required to enable Layer-2 or Layer-3 connectivity between two VDOMs on the same FortiGate. Without a VDOM link, the VDOMs are isolated from each other, even if policies exist. The VDOM link acts as a virtual interface pair that forwards traffic between CustomerA and CustomerB, allowing the HTTP server access.

Exam trap

The trap here is that candidates assume inter-VDOM policies alone suffice, forgetting that VDOMs are fully isolated routing domains requiring a dedicated link (VDOM link) to exchange traffic.

How to eliminate wrong answers

Option B is wrong because policies alone cannot forward traffic between VDOMs; inter-VDOM traffic requires a VDOM link to provide the physical or logical path. Option C is wrong because inter-VDOM routing is not a global setting that can be enabled; it is inherently provided by configuring VDOM links or inter-VDOM links under each VDOM. Option D is wrong because FortiManager administrative domains are management constructs for centralized device management, not for enabling data-plane traffic between VDOMs on a single FortiGate.

135
MCQhard

A FortiGate administrator is troubleshooting a ZTNA access proxy rule that is not matching traffic from a specific user group. The rule is configured with a source of 'ZTNA_Users' and a destination of the internal web server. The administrator confirms that the user is authenticated and has the correct EMS tag. Which FortiGate CLI command should the administrator use to verify that the ZTNA rule is being evaluated correctly?

A.diagnose wad debug enable category ztna
B.diagnose debug application fnbamd -1
C.diagnose vpn ike gateway list
D.diagnose firewall auth list
AnswerA

The 'diagnose wad debug enable category ztna' command enables debugging for ZTNA processing in the WAD daemon. It provides detailed logs about ZTNA rule matching, including source, destination, and user information. This is essential for troubleshooting why a ZTNA rule is not matching traffic. It shows the evaluation process and any errors.

Why this answer

The 'diagnose wad debug enable category ztna' command enables detailed debugging of ZTNA processing in the WAD daemon, which handles access proxy rules. It shows rule matching, user identification, and any errors. Other commands like 'diagnose firewall auth list' only show authentication status, while 'fnbamd' debugging is for authentication daemon issues.

For ZTNA rule matching, WAD debug is the correct tool.

Exam trap

The trap here is using authentication debugging commands when the issue is with ZTNA rule evaluation, not authentication.

136
MCQeasy

A FortiGate administrator needs to identify which process is consuming the most memory. Which command should be used?

A.diagnose sys top
B.show system resource usage
C.diagnose hardware sysinfo memory
D.get system performance status
AnswerA

The diagnose sys top command displays a live, refreshable list of running FortiGate processes ranked by CPU and memory consumption. This directly identifies the process using the most memory, which is the administrator's stated goal.

Why this answer

The 'diagnose sys top' command displays a real-time list of running processes sorted by CPU and memory usage, allowing the administrator to identify which process is consuming the most memory. This is the standard FortiGate CLI command for process-level resource monitoring, similar to 'top' on Linux systems.

Exam trap

The trap here is that candidates may confuse system-level memory commands (like 'diagnose hardware sysinfo memory' or 'show system resource usage') with process-level memory diagnostics, assuming any 'memory' or 'resource' command will show per-process details.

How to eliminate wrong answers

Option B is wrong because 'show system resource usage' displays overall system resource statistics (CPU, memory, disk) but does not break down memory usage by individual process. Option C is wrong because 'diagnose hardware sysinfo memory' shows hardware-level memory information (total, used, free) and memory module details, not per-process memory consumption. Option D is wrong because 'get system performance status' provides a summary of system performance metrics (CPU, memory, sessions) but lacks process-level granularity.

137
Multi-Selectmedium

An administrator is troubleshooting a BGP session that is not establishing between two FortiGates. The administrator has verified that the neighbor IP is reachable. Which TWO commands should be used to further diagnose the issue? (Choose two.)

Select 2 answers
A.get router info bgp neighbor <IP>
B.diagnose debug flow filter daddr <IP>
C.get router info routing-table bgp
D.diagnose sys session filter dport 179
E.diagnose ip router bgp all enable
AnswersA, E

This command shows BGP session state and counters, useful for troubleshooting.

Why this answer

'get router info bgp neighbor <IP>' displays detailed BGP session state information, including the current state (e.g., Idle, Connect, Active, OpenSent, OpenConfirm, Established), hold timer, keepalive interval, and any error codes or notifications. This command directly reveals why the session is not establishing, such as a mismatch in BGP capabilities, AS numbers, or authentication.

Exam trap

The trap here is that candidates often confuse general network troubleshooting commands (like session filtering or flow debugging) with BGP-specific diagnostic commands, failing to recognize that BGP session establishment requires examining the BGP state machine and debug logs, not just TCP connectivity or routing table contents.

138
MCQeasy

A FortiGate administrator wants to prevent users from accessing a list of known malicious domains. The list is updated daily by a third-party provider and available as a plain text file over HTTPS. Which FortiGate feature should be used to ingest and block these domains?

A.FortiGuard DNS Filter with custom categories
B.External Threat Feed connector
C.Static DNS zone with blackhole
D.FortiGate local domain blocklist
AnswerB

The External Threat Feed connector can fetch a plain text list of domains from an HTTPS URL and create a dynamic address object. This object can then be used in a DNS filter or firewall policy to block access. It supports automatic updates at configured intervals, exactly matching the requirement for daily updates from a third-party provider.

Why this answer

The External Threat Feed connector is designed to import IP or domain lists from external HTTP/HTTPS sources and keep them updated. It creates a dynamic object that can be referenced in policies, providing automated blocking. The other options are either static or tied to Fortinet's own categorization, and cannot ingest a custom third-party list automatically.

Exam trap

The trap here is confusing FortiGuard's built-in DNS categories with the ability to import custom external lists, which requires the External Threat Feed connector.

139
MCQhard

A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?

A.Enable 'Security Events' with 'Log' action for all process executions.
B.Set the 'Threat Hunting' module to 'Monitor' mode for all endpoints.
C.Configure 'Exclusions' to prevent FortiEDR from scanning critical applications.
D.Use 'Playbooks' with a 'Block and Remediate' action triggered by a malicious verdict.
AnswerD

FortiEDR playbooks can automatically execute block and remediate actions when a malicious verdict is reached. This stops the malicious process, prevents command-and-control communication, and triggers collection of forensic data such as memory dumps and process trees. It directly satisfies both the containment and the forensic requirements described in the scenario.

Why this answer

FortiEDR playbooks automate responses based on verdicts. A Block and Remediate playbook can terminate the malicious process, sever command-and-control communication, and initiate forensic collection. Logging, exclusions, or monitoring alone do not provide containment, so they cannot meet the combined requirement for automated containment and detailed forensics.

Exam trap

The trap here is equating monitoring or logging features with automated containment, when only a playbook action can block, remediate, and collect forensics in one triggered workflow.

140
MCQhard

An organization has multiple ADOMs in FortiManager. The admin wants to share a set of firewall objects across all ADOMs. What is the best approach?

A.Create a meta field and assign objects
B.Use the Global ADOM to create global objects
C.Manually recreate the objects in each ADOM
D.Enable object sharing in the system settings
AnswerB

Global ADOM objects are inherited by every ADOM, satisfying the cross-ADOM sharing requirement without duplication. Objects created there propagate automatically to all ADOMs, including newly created ones, and remain centrally managed. Per-ADOM objects cannot be referenced elsewhere, so only the Global ADOM provides the required scope.

Why this answer

The Global ADOM in FortiManager is specifically designed to create and manage global objects (such as address objects, services, and schedules) that can be shared across all regular ADOMs. When an object is created in the Global ADOM, it is automatically available in all ADOMs that are linked to it, eliminating the need for duplication. This is the only native, supported method for sharing objects across multiple ADOMs in FortiManager.

Exam trap

The trap here is that candidates may confuse the Global ADOM with a regular ADOM or think that a simple system setting can enable object sharing, when in fact the Global ADOM is a distinct, purpose-built feature for cross-ADOM object sharing.

How to eliminate wrong answers

Option A is wrong because meta fields are used for custom metadata tagging and filtering of objects within an ADOM, not for sharing objects across ADOMs. Option C is wrong because manually recreating objects in each ADOM is inefficient, error-prone, and defeats the purpose of centralized management with FortiManager. Option D is wrong because FortiManager does not have a system-level 'object sharing' toggle; object sharing is achieved exclusively through the Global ADOM mechanism.

141
Multi-Selecteasy

A FortiGate administrator wants to use FortiAnalyzer to view traffic logs from multiple VDOMs. Which TWO steps must the administrator perform on FortiAnalyzer?

Select 2 answers
A.Install a security profile on FortiAnalyzer
B.Add the FortiGate as a device in FortiAnalyzer
C.Create a separate ADOM for each VDOM
D.Configure the FortiGate to send logs to FortiAnalyzer
E.Enable FortiAnalyzer's built-in firewall
AnswersB, D

Adding the FortiGate as a device in FortiAnalyzer establishes the log-receiving relationship and registers each VDOM as a separate ADOM or device entry, satisfying the requirement to view traffic logs from multiple VDOMs. Without this registration, FortiAnalyzer cannot receive or index the FortiGate's logs.

Why this answer

Option B is correct because FortiAnalyzer can only receive, index, and display logs from a FortiGate after that FortiGate has been added as a managed device (via the device registration/authorization process), which establishes the log-receiving relationship. Option D is correct because the FortiGate must be configured to send its logs to FortiAnalyzer, typically by enabling logging to FortiAnalyzer under config log fortianalyzer setting and pointing it at the FortiAnalyzer IP, so that traffic logs from all VDOMs are actually transmitted. Options A and E are incorrect because FortiAnalyzer is a log management and analytics appliance, not a traffic-inspecting firewall, so it does not require security profiles or a built-in firewall to view logs.

Option C is incorrect because a single ADOM can contain the FortiGate and its multiple VDOMs; separate ADOMs per VDOM are not required to view multi-VDOM traffic logs.

Exam trap

The trap here is that candidates often think a separate ADOM is mandatory for each VDOM, but FortiAnalyzer can consolidate logs from multiple VDOMs into a single ADOM, and the key requirement is simply adding the FortiGate as a device and configuring log forwarding.

142
MCQmedium

A security administrator wants to block email spoofing attacks against their organization's domain. They configure SPF, DKIM, and DMARC records. Which protocol authenticates the domain of the email sender by verifying the email's signature against a public key published in DNS?

A.SPF
B.ARC
C.DKIM
D.DMARC
AnswerC

DKIM adds a cryptographic signature to outgoing mail, verified against a public key published in the sender domain's DNS TXT record. This authenticates the domain and confirms message integrity, satisfying the requirement to detect spoofing where the signature fails validation.

Why this answer

DKIM (DomainKeys Identified Mail) is the correct answer because it provides email authentication by allowing the sender to cryptographically sign an email with a private key. The receiving mail server then retrieves the sender's public key from a DNS TXT record and verifies the signature, confirming that the email was not tampered with and originates from a domain the sender is authorized to use.

Exam trap

The trap here is that candidates often confuse SPF's IP-based verification with DKIM's cryptographic signature verification, or they assume DMARC performs the actual authentication, when in fact DMARC only enforces policies based on SPF and DKIM results.

How to eliminate wrong answers

Option A is wrong because SPF (Sender Policy Framework) authenticates the sending server's IP address against a list of authorized IPs published in DNS, not by verifying a cryptographic signature. Option B is wrong because ARC (Authenticated Received Chain) is a protocol that preserves email authentication results across intermediate hops (forwarders or mailing lists), but it does not itself authenticate the original sender's domain via a signature. Option D is wrong because DMARC (Domain-based Message Authentication, Reporting & Conformance) is a policy framework that uses SPF and DKIM results to instruct receivers on how to handle unauthenticated email (e.g., quarantine or reject), but it does not perform signature verification itself.

143
Multi-Selectmedium

An enterprise FortiGate has multiple VDOMs. The security policy requires that all traffic between VDOMs must be inspected by a next-generation firewall profile. Which three steps are necessary to achieve this? (Choose three.)

Select 3 answers
A.Ensure routing is properly configured to forward traffic through the inter-VDOM link
B.Place both VDOMs in the same ADOM in FortiManager
C.Enable VDOM inspection mode in global settings
D.Configure a firewall policy on the inter-VDOM link with the required security profile
E.Create an inter-VDOM link between the VDOMs
AnswersA, D, E

Routes direct traffic to the link interface.

Why this answer

For traffic to traverse between VDOMs via an inter-VDOM link, proper routing must be configured in each VDOM to forward traffic through the inter-VDOM link interface. Without correct routing entries (static or dynamic), packets will not be directed to the inter-VDOM link, and the next-generation firewall profile cannot be applied.

Exam trap

The trap here is that candidates often assume VDOM inspection mode must be enabled globally to apply security profiles on inter-VDOM links, but in reality, the inspection mode only affects how VDOMs handle traffic at the kernel level and does not control policy-based inspection on inter-VDOM links.

144
MCQeasy

Which feature on FortiGate uses machine learning to detect never-before-seen malware based on file characteristics?

A.Machine Learning Engine
B.Outbreak Prevention
C.FortiSandbox
D.Content Disarm and Reconstruction
AnswerA

The Machine Learning Engine inspects file characteristics rather than signatures, so it identifies never-before-seen malware without prior samples. This directly satisfies the stem's requirement for detecting unknown threats through behavioural and structural analysis, unlike signature-based antivirus or sandboxing, which depend on known patterns or dynamic execution.

Why this answer

The Machine Learning Engine (option A) on FortiGate uses static file analysis and machine learning models to detect never-before-seen malware based on file characteristics such as entropy, structure, and opcode sequences, without requiring signatures or behavioral execution. This allows it to identify zero-day threats pre-execution, directly matching the question's description.

Exam trap

The trap here is that candidates often confuse FortiSandbox's dynamic analysis (which also detects unknown malware) with the Machine Learning Engine's static analysis, but the question specifically asks for detection based on file characteristics, not behavioral execution.

How to eliminate wrong answers

Option B (Outbreak Prevention) is wrong because it is a subscription-based threat intelligence service that provides real-time updates on emerging threats, but it does not use machine learning to analyze file characteristics; instead, it relies on signature updates and IoCs from FortiGuard. Option C (FortiSandbox) is wrong because it detonates files in a virtual environment to observe runtime behavior, which is dynamic analysis, not static machine learning based on file characteristics. Option D (Content Disarm and Reconstruction) is wrong because it removes active content (e.g., macros, scripts) from files and rebuilds them into safe versions, but it does not use machine learning to detect malware; it is a prevention technique that strips potential threats regardless of detection.

145
MCQmedium

A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?

A.Check that both routes have the same administrative distance and priority
B.Configure 'set v4-ecmp-mode' to 'source-ip-based'
C.Verify that 'set load-balance-eligible' is enabled on both WAN interfaces
D.Disable 'anti-replay' on the security policy
AnswerA

ECMP installs multiple next-hops only when candidate routes match on administrative distance and priority; differing values leave a single best route, so all traffic egresses one ISP. Verifying both attributes equal confirms the routes are genuinely equal-cost before troubleshooting hashing or link health.

Why this answer

ECMP requires that all candidate routes have identical administrative distance and priority values. If either differs, FortiGate will select only the route with the lower distance/priority, breaking load balancing. The administrator should verify these parameters first because they directly control route selection before ECMP is applied.

Exam trap

The trap here is that candidates often jump to configuring ECMP hashing modes or interface settings, overlooking the fundamental requirement that routes must be truly equal in administrative distance and priority before ECMP can function.

How to eliminate wrong answers

Option B is wrong because 'set v4-ecmp-mode' controls the hashing algorithm (e.g., source-ip-based, weighted) for distributing traffic across ECMP paths, but it does not fix the root cause of routes not being considered equal. Option C is wrong because 'load-balance-eligible' is a per-interface setting for SD-WAN rules, not for standard ECMP routing; ECMP eligibility is determined by route attributes, not this interface flag. Option D is wrong because disabling anti-replay on the security policy affects session state tracking and asymmetric traffic handling, not the selection of ECMP paths.

146
Multi-Selectmedium

A FortiGate administrator is troubleshooting an issue where users are unable to access a web server behind the FortiGate. The web server is on the DMZ network, and users are on the internal network. The firewall policy from internal to DMZ is configured to allow HTTP and HTTPS. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which two actions should the administrator take to resolve this issue? (Choose two.)

Select 2 answers
A.Verify that the firewall policy from internal to DMZ is correctly configured with the correct source and destination interfaces and addresses.
B.Check the FortiGate's ARP table for the web server's MAC address.
C.Verify that the web server is listening on the correct ports and is reachable from the FortiGate.
D.Ensure that the policy is placed in the correct order in the firewall policy list, as a previous policy might be blocking the traffic.
E.Check the routing table to ensure there is a route to the DMZ network.
AnswersA, D

The drop occurs during inbound policy check, which means the packet does not match any policy. Checking the policy configuration ensures that the source interface (internal), destination interface (DMZ), and addresses are correct. A misconfiguration here would cause the drop.

Why this answer

The 'iprope_in_check()' drop indicates that the packet failed the inbound policy check. This can happen if the policy is misconfigured, such as incorrect interfaces or addresses, or if a preceding policy is denying the traffic. Therefore, verifying the policy configuration and its order are the correct actions.

Routing and server-side issues would produce different symptoms.

Exam trap

The trap here is assuming that routing or server issues cause the policy check failure, when in fact the drop is specifically due to policy lookup, so policy configuration and order must be examined.

147
MCQmedium

An administrator configures FortiSandbox inline scanning for HTTP traffic. They notice that files uploaded via HTTP are being scanned but no verdict is being returned, causing delays. What is the MOST likely cause?

A.The FortiSandbox has reached its maximum storage capacity
B.The FortiSandbox is not registered with the FortiGate
C.The file scan timeout is too short, causing FortiGate to pass the file before a verdict is received
D.The file type is not supported by FortiSandbox
AnswerC

With inline scanning, FortiGate holds the file only until the scan timeout expires. If that timeout is shorter than FortiSandbox's verdict time, the file is released and forwarded without a verdict, producing the observed delays.

Why this answer

When FortiGate sends a file to FortiSandbox for inline scanning, it waits for a verdict before allowing the traffic to proceed. If the file scan timeout is too short, FortiGate will stop waiting for the verdict and pass the file anyway, causing the observed delay without a final verdict. This is the most likely cause because the administrator sees scanning occurring but no verdict returned, which aligns with a premature timeout rather than a failure to scan.

Exam trap

The trap here is that candidates often assume a missing verdict is due to a registration or capacity issue, but the question specifically states scanning is occurring, which eliminates options A and B, and the delay points directly to a timeout configuration problem.

How to eliminate wrong answers

Option A is wrong because if the FortiSandbox had reached maximum storage capacity, it would typically reject new submissions or fail to store results, but the file would still be scanned or an error would be returned, not a delay without verdict. Option B is wrong because if the FortiSandbox were not registered with the FortiGate, the FortiGate would not be able to send files for scanning at all, so no scanning would occur. Option D is wrong because if the file type were not supported, FortiSandbox would either skip the file or return an unsupported verdict quickly, not cause a delay without a verdict.

148
MCQhard

An administrator has configured two VDOMs on a FortiGate. One VDOM is in NAT mode and the other in transparent mode. The administrator wants traffic from the transparent mode VDOM to be routed through the NAT mode VDOM. What must be configured to allow inter-VDOM routing?

A.Use a physical interface to connect the VDOMs
B.Create an inter-VDOM link
C.Enable NPU offloading
D.Configure firewall policies between the VDOMs
AnswerB

An inter-VDOM link creates a virtual point-to-point Ethernet interface pairing two VDOMs, enabling traffic to pass between them regardless of operating mode. This satisfies the requirement to route traffic from the transparent VDOM into the NAT-mode VDOM, since the link provides the Layer 3 path that transparent mode alone cannot supply.

Why this answer

Inter-VDOM routing between VDOMs in different modes (NAT and transparent) requires a dedicated inter-VDOM link (IVL), which is a virtual internal connection that allows traffic to pass between VDOMs without consuming physical ports. The IVL creates a pair of virtual interfaces, one in each VDOM, and firewall policies must be configured to permit traffic across them. This is the only method that supports routing between VDOMs of different modes on the same FortiGate.

Exam trap

The trap here is that candidates assume firewall policies alone can route traffic between VDOMs, but without an inter-VDOM link, the VDOMs are completely isolated and cannot exchange any traffic regardless of policy configuration.

How to eliminate wrong answers

Option A is wrong because using a physical interface to connect VDOMs is unnecessary and inefficient; inter-VDOM links are virtual and avoid wasting physical ports. Option C is wrong because NPU offloading is a hardware acceleration feature for packet processing, not a mechanism for enabling inter-VDOM routing. Option D is wrong because firewall policies alone cannot enable inter-VDOM routing; they are required after the inter-VDOM link is created to allow traffic, but the link itself is the fundamental connectivity component.

149
MCQeasy

An administrator is configuring an SD-WAN rule to route traffic to a specific destination through a preferred member, but wants to ensure that if that member fails, traffic automatically switches to another member. Which SD-WAN rule configuration setting should they use to define the order of member preference?

A.Member sequence in the SD-WAN rule
B.SLA target
C.Load balancing algorithm
D.Priority
AnswerA

In an SD-WAN rule, members are listed in a specific order. The FortiGate uses this order as a preference sequence when the strategy is set to 'manual' or when failover occurs. The first member in the list is preferred; if it becomes unavailable, the next member is used. This provides a deterministic failover order.

Why this answer

To define a preferred order of members for failover in an SD-WAN rule, the administrator should list the members in the desired sequence within the rule configuration. The FortiGate will use the first available member according to that order when the strategy is 'manual' or when failover is triggered. This ensures deterministic behavior.

Exam trap

The trap here is confusing the load balancing algorithm with member preference order; the algorithm distributes traffic, while the member sequence defines failover priority.

150
MCQhard

A FortiGate in transparent mode is deployed between a router and a switch. The administrator needs to apply a deep inspection profile to HTTP traffic. What is the correct configuration for the interfaces?

A.Configure a management IP on the VDOM and apply the inspection profile to the policy
B.Place both interfaces in the same VDOM and enable DHCP
C.Switch to NAT mode to enable deep inspection
D.Assign IPs to both interfaces and create a policy from LAN to WAN
AnswerA

The VDOM management IP provides connectivity; policies inspect traffic on the bridge.

Why this answer

In transparent mode, FortiGate acts as a Layer 2 bridge, so interfaces do not require IP addresses. Deep inspection of HTTP traffic is applied via a firewall policy that references a deep inspection profile, and a management IP must be configured on the VDOM to allow the FortiGate to participate in management traffic (e.g., DNS, NTP, or proxy operations). Option A correctly identifies that the management IP is set on the VDOM and the inspection profile is applied to the policy.

Exam trap

The trap here is that candidates assume transparent mode cannot perform deep inspection because it lacks routed interfaces, but FortiGate supports full UTM inspection in transparent mode via the management IP and policy-based profiles.

How to eliminate wrong answers

Option B is wrong because placing both interfaces in the same VDOM is correct for transparent mode, but enabling DHCP is unnecessary and irrelevant—transparent mode interfaces do not require IP addresses or DHCP services. Option C is wrong because deep inspection is fully supported in transparent mode; switching to NAT mode is not required and would change the FortiGate's Layer 2 behavior. Option D is wrong because assigning IPs to both interfaces is not valid in transparent mode—interfaces remain without IPs, and policies are created using the management IP, not LAN-to-WAN direction.

Page 1

Page 2 of 10

Page 3

All pages