Courseiva

Fortinet NSE 7 Advanced Security NSE7 (NSE7) — Questions 151–225

718 questions total · 10pages · All types, answers revealed

Page 2

Page 3 of 10

Page 4
151
MCQmedium

A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees the tunnel state as 'connecting' but no phase2 selectors are listed. Which step should the administrator take next to identify the issue?

A.Run 'diagnose debug application ike -1' and then attempt to bring up the tunnel to capture IKE negotiation details.
B.Run 'diagnose vpn tunnel list' to check the status of all IPsec tunnels and their selectors.
C.Run 'diagnose vpn ike gateway list' with the 'name' parameter to see detailed phase1 and phase2 information.
D.Run 'diagnose vpn ike status' to check the IKE status and any error counters.
AnswerA

When phase2 selectors are missing, it indicates that phase2 negotiation has not completed or failed. Enabling IKE debug with 'diagnose debug application ike -1' will show the detailed exchange, including proposals, selectors, and any error messages. This is the most effective way to identify why phase2 is not establishing, such as mismatched proposals or proxy IDs. The debug output will pinpoint the failure.

Why this answer

When an IPsec tunnel is stuck in 'connecting' with no phase2 selectors, the issue is likely in phase2 negotiation. Enabling IKE debug with 'diagnose debug application ike -1' will show the detailed negotiation, including proposals and selectors, and any error messages. This is the best next step to identify the cause, such as mismatched phase2 proposals or incorrect proxy IDs.

Other commands may not provide the necessary detail.

Exam trap

The trap here is using summary commands like 'diagnose vpn tunnel list' or incorrect commands instead of enabling detailed IKE debug to see the actual negotiation failure.

152
MCQhard

A FortiGate is configured with an SD-WAN rule using 'spillover' algorithm. The primary member has a spillover threshold of 100 Mbps. Traffic of 80 Mbps is currently flowing through the primary member. A new session requiring 30 Mbps arrives. What will happen?

A.The new session is sent to the primary member because the current load is below the threshold.
B.The new session is sent to the secondary member because the primary threshold would be exceeded.
C.The new session is dropped because no member can handle it.
D.The primary member's threshold is dynamically increased.
AnswerB

Spillover forwards a new session to a secondary member when adding it would push the primary member past its configured threshold. Current 80 Mbps plus 30 Mbps equals 110 Mbps, exceeding the 100 Mbps limit, so the session uses the secondary.

Why this answer

The SD-WAN 'spillover' algorithm forwards traffic to the primary member until its load reaches the configured threshold (100 Mbps). With 80 Mbps already flowing, adding a new 30 Mbps session would push the total to 110 Mbps, exceeding the threshold. Therefore, the new session is sent to the secondary member to avoid oversubscription, as per the spillover logic.

Exam trap

The trap here is that candidates often assume the algorithm checks if the *new session alone* exceeds the threshold, rather than evaluating the *cumulative load* after adding the new session, leading them to incorrectly select option A.

How to eliminate wrong answers

Option A is wrong because the current load of 80 Mbps plus the new 30 Mbps session would exceed the 100 Mbps spillover threshold, so the session cannot be sent to the primary member. Option C is wrong because the secondary member is available and can handle the traffic; the session is not dropped. Option D is wrong because the spillover threshold is a static configured value and is not dynamically adjusted by the FortiGate based on traffic load.

153
MCQmedium

A FortiGate administrator is configuring a security profile group and wants to enable inline blocking of malicious files based on FortiGuard cloud threat intelligence, without sending files to FortiSandbox. The administrator has already enabled the antivirus profile and selected the 'Block' action for infected files. Which additional setting should be configured to ensure that files identified as malicious by the FortiGuard service are blocked in real time?

A.Enable 'Scan with FortiSandbox' in the antivirus profile.
B.Enable 'FortiGuard AI-Based Inline Malware Prevention' in the antivirus profile.
C.Enable 'Use FortiSandbox Database' in the antivirus profile.
D.Configure 'External Blocklist' with a threat intelligence feed.
AnswerB

This feature uses FortiGuard AI-based malware prevention to inspect files inline and block malicious content without relying on sandbox detonation. It leverages cloud-based threat intelligence and machine learning to identify and block known and unknown malware in real time, which directly satisfies the requirement to block files identified by FortiGuard without using FortiSandbox.

Why this answer

The correct setting is 'FortiGuard AI-Based Inline Malware Prevention', which enables real-time blocking of malicious files using FortiGuard's cloud-based AI and machine learning, without the need for a FortiSandbox. This feature is part of the antivirus profile and provides inline protection against known and unknown malware, aligning with the administrator's goal of blocking based on FortiGuard intelligence.

Exam trap

The trap here is confusing FortiGuard AI-based inline prevention with FortiSandbox integration, assuming that any cloud-based file analysis requires a sandbox appliance.

154
MCQmedium

A FortiGate administrator has configured a ZTNA access proxy for an internal web application and wants to enforce device compliance before allowing access. The administrator has integrated FortiClient EMS and created ZTNA tags for compliant devices. Users with compliant devices are still being denied access. The firewall policy references the ZTNA server and the tag. What should the administrator verify first?

A.That the FortiGate is configured to use SSL VPN instead of ZTNA for the internal application, because ZTNA does not support tag-based policies.
B.That the ZTNA server is configured with a valid SSL certificate and that the certificate chain is trusted by the client.
C.That the ZTNA tags are correctly received from FortiClient EMS and that the tag names in the firewall policy match the tags assigned to the devices.
D.That the firewall policy is placed after a broader allow policy that matches the same users and services.
AnswerC

ZTNA policy matching depends on the tag names being identical between what FortiClient EMS sends and what the firewall policy references. If the tag is misspelled or not received, the policy will not match even if the device is compliant. Verifying tag reception and name matching is the most direct way to diagnose why compliant users are denied.

Why this answer

When ZTNA tag-based enforcement denies compliant users, the most common cause is a mismatch between the tags received from FortiClient EMS and the tag names referenced in the firewall policy. Confirming that the FortiGate has the expected tags and that the policy uses the exact same names is the correct first step. Certificate issues, protocol substitution, and policy ordering do not fit the reported symptom of denied compliant users.

Exam trap

The trap here is assuming that a compliant device automatically satisfies the policy, when the policy only matches if the tag name received from EMS matches the tag name configured on the FortiGate.

155
MCQhard

A FortiGate administrator is configuring ZTNA to provide access to an internal web application. The administrator wants to ensure that only devices with a specific security posture tag are allowed access. The ZTNA rule is configured with a policy that references a device group synced from FortiClient EMS. However, when a user attempts to access the application, the connection is denied even though the device has the correct tag. What is the most likely cause?

A.The user's device is not running FortiClient, so the tag cannot be evaluated.
B.The ZTNA rule is missing a matching source interface or source address.
C.The FortiClient EMS tag is not synchronized with the FortiGate due to a certificate or connectivity issue.
D.The ZTNA proxy rule requires an application mapping that has not been configured.
AnswerC

If the tag is not synchronized, the FortiGate will not see the device as compliant, even if it has the tag in EMS. This causes the ZTNA policy to deny access. Synchronization issues often stem from expired certificates or network problems.

Why this answer

The most likely cause is that the FortiClient EMS tag is not synchronized with the FortiGate. Even if the device has the tag in EMS, the FortiGate must receive that information via the EMS connector. If synchronization fails due to certificate issues or connectivity, the FortiGate will not recognize the device as compliant, resulting in a denial.

Exam trap

The trap here is focusing on the ZTNA rule configuration itself, but the issue is often in the EMS synchronization, not the rule.

156
MCQmedium

A FortiGate has multiple VDOMs. The administrator notices that traffic from VDOM-1 to VDOM-2 is allowed by inter-VDOM policies but is not being inspected by the security profiles. What is the most likely cause?

A.The security profiles are applied only on the egress VDOM
B.The traffic is using a bypass path due to asymmetric routing
C.The VDOMs are in different virtual routers
D.The VDOM link is configured as a signal interface
AnswerA

Correct.

Why this answer

When inter-VDOM traffic flows through a VDOM link, security profiles are applied only on the egress VDOM by default. This is because the VDOM link acts as a logical wire, and inspection occurs at the point where traffic exits the link. If the administrator has applied security profiles only on the ingress VDOM (VDOM-1), they will not be enforced on traffic leaving VDOM-1 toward VDOM-2, resulting in no inspection.

Exam trap

The trap here is that candidates assume security profiles are applied symmetrically on both sides of an inter-VDOM link, but FortiGate only inspects traffic on the egress VDOM, so profiles must be configured on the destination VDOM's policy.

How to eliminate wrong answers

Option B is wrong because asymmetric routing would cause session setup failures or packet drops, not a bypass of security profiles; inter-VDOM policies still enforce inspection regardless of routing symmetry. Option C is wrong because different virtual routers do not prevent inter-VDOM traffic from being inspected; they only affect routing decisions, not security profile application. Option D is wrong because a signal interface is used for heartbeat or management traffic between VDOMs, not for data traffic, and would not cause security profiles to be skipped.

157
MCQeasy

An administrator wants to use FortiAnalyzer to generate weekly compliance reports for all managed FortiGates. Which FortiAnalyzer feature should be used?

A.Incidents
B.Reports
C.FortiView
D.Log Analytics
AnswerB

FortiAnalyzer Reports is the built-in feature for generating scheduled compliance and security reports from logged data across managed devices. Configuring a weekly schedule with all FortiGates as data sources produces the required recurring output, which other features such as Log Browse or Incidents do not provide.

Why this answer

FortiAnalyzer's Reports feature is specifically designed to generate scheduled, customizable compliance reports that aggregate data from multiple managed FortiGates. This allows administrators to produce weekly reports aligned with regulatory standards (e.g., PCI DSS, HIPAA) without manual effort, leveraging pre-defined or custom report templates.

Exam trap

The trap here is that candidates often confuse FortiView's real-time dashboards with the scheduled, template-driven reporting capability of the Reports module, assuming that visualization tools can substitute for formal compliance report generation.

How to eliminate wrong answers

Option A is wrong because Incidents in FortiAnalyzer are used for tracking and managing security events and alerts, not for generating scheduled compliance reports. Option C is wrong because FortiView provides real-time and historical data visualization for monitoring and troubleshooting, but it lacks the scheduling and template-based reporting required for weekly compliance reports. Option D is wrong because Log Analytics focuses on searching, correlating, and analyzing log data, not on producing formatted, scheduled compliance reports.

158
MCQeasy

A FortiGate administrator wants to enable load balancing for equal-cost paths to the same destination. The FortiGate has two equal-cost routes via two different next-hop routers. Which feature should the admin enable to load balance traffic across both paths?

A.BFD (Bidirectional Forwarding Detection)
B.ECMP (Equal Cost Multi-Path)
C.Policy-based routing
D.SD-WAN load balancing
AnswerB

ECMP installs multiple equal-cost next-hops for the same destination in the routing table, letting the FortiGate distribute traffic across both paths. Without it, only one route is selected, so the second path stays unused despite identical cost.

Why this answer

ECMP (Equal Cost Multi-Path) is the correct feature because it enables a FortiGate to distribute traffic across multiple equal-cost routes to the same destination. When the routing table contains two or more routes with identical administrative distance and metric, ECMP automatically load-balances sessions across those paths using a hash-based algorithm (e.g., source-destination IP hash), without requiring additional configuration beyond enabling the feature globally or per-VDOM.

Exam trap

The trap here is that candidates confuse SD-WAN load balancing with ECMP, but SD-WAN is a separate overlay technology that requires SD-WAN zones and performance SLA rules, whereas ECMP is a simple, direct routing-table feature for equal-cost paths without any overlay or application-awareness.

How to eliminate wrong answers

Option A is wrong because BFD (Bidirectional Forwarding Detection) is a fast failure detection protocol that monitors link or neighbor liveness, not a load-balancing mechanism; it can be used with ECMP to quickly remove dead paths but does not distribute traffic. Option C is wrong because policy-based routing (PBR) overrides the routing table with user-defined policies to steer traffic based on attributes like source IP or port, but it does not automatically load-balance across equal-cost paths; it is a manual, rule-based approach that can disrupt ECMP behavior. Option D is wrong because SD-WAN load balancing is a higher-level feature that uses performance SLA rules and application steering to distribute traffic across WAN links, but it is not designed for simple equal-cost path load balancing within a single routing domain; ECMP is the native, lightweight solution for this scenario.

159
MCQeasy

A network administrator is setting up an IPsec VPN between two FortiGates. The administrator wants to ensure that if the VPN tunnel goes down, the FortiGate can automatically re-establish it without manual intervention. Which IPsec feature should the administrator enable to detect peer failures and trigger tunnel renegotiation?

A.Dead Peer Detection (DPD) with the mode set to on-idle or always.
B.Automatic Key Negotiation (AutoIKE) to dynamically negotiate new SAs.
C.Perfect Forward Secrecy (PFS) to generate new keys for each phase 2 negotiation.
D.IKEv2 fragmentation to allow large packets to traverse the tunnel.
AnswerA

DPD is the IPsec feature that detects when a peer becomes unreachable. When enabled, the FortiGate sends periodic probes or waits for idle traffic before probing. If the peer fails to respond, DPD marks the tunnel as down and triggers renegotiation or failover. Setting DPD mode to on-idle or always ensures detection occurs and the tunnel can be automatically re-established without manual intervention.

Why this answer

Dead Peer Detection is the IPsec mechanism that monitors peer liveness by sending probes or waiting for idle periods. When the peer fails to respond, DPD marks the tunnel as down and triggers renegotiation or failover. Setting DPD mode to on-idle or always ensures continuous monitoring, enabling automatic tunnel recovery without manual intervention.

Exam trap

The trap here is confusing security features like PFS or fragmentation with the liveness detection provided by DPD.

160
Multi-Selectmedium

An administrator needs to configure advanced email security on FortiMail to protect against phishing and spoofing. Which THREE features should be enabled to achieve comprehensive email authentication?

Select 3 answers
A.DKIM signing and verification
B.SPF checking
C.DMARC policy enforcement
D.Anti-spam Bayesian filtering
E.TLS encryption for inbound/outbound
AnswersA, B, C

DKIM signing and verification uses cryptographic signatures to confirm message integrity and domain authenticity. FortiMail verifies signatures on inbound mail and signs outbound mail, preventing tampering and impersonation, which satisfies the authentication requirement alongside SPF and DMARC.

Why this answer

DKIM (DomainKeys Identified Mail) signing and verification is correct because it allows the sending domain to cryptographically sign outgoing emails, and the receiving server to verify that the signature matches the domain’s public DNS record. This ensures the email was not tampered with and originates from an authorized server, directly addressing phishing and spoofing by validating message integrity and sender authenticity.

Exam trap

The trap here is that candidates confuse transport security (TLS) or content filtering (Bayesian) with sender authentication protocols, forgetting that only DKIM, SPF, and DMARC directly verify domain ownership and prevent spoofing, while TLS and Bayesian filtering address different security layers (confidentiality and spam classification).

161
MCQhard

A multinational corporation is implementing ZTNA for remote access to a critical internal application hosted on a server with IP 10.0.1.200:8443. The FortiGate is deployed at the edge with WAN IP 203.0.113.50. The administrator configures a ZTNA rule with proxy destination 10.0.1.200:8443, a firewall policy allowing traffic from the ZTNA gateway to the internal server, and a VIP for port forwarding for testing. However, remote users report that they can establish a ZTNA connection to the gateway but the application page fails to load, showing a blank page after a long delay. The FortiGate logs show no errors, and the debug output indicates that the proxy successfully forwarded the request to 10.0.1.200:8443 and received a response. The internal server team confirms the application is working correctly for on-site users. What is the most likely cause?

A.The ZTNA proxy is not configured to support HTTPS.
B.The internal server is not reachable from the FortiGate.
C.The client's ZTNA tags are expired.
D.The application uses hardcoded IP addresses or internal hostnames that are not resolvable externally.
AnswerD

The proxy forwards successfully and the server replies, so the failure lies in the returned content: the application generates links or redirects referencing internal addresses that remote clients cannot resolve. That matches the blank page after delay despite a healthy ZTNA tunnel.

Why this answer

The application uses hardcoded IP addresses or internal hostnames that are not resolvable externally. When the ZTNA proxy forwards the request to the internal server, the server responds with HTML content that references internal resources (e.g., images, scripts, or links) using private IP addresses (like 10.0.1.200) or internal DNS names. The remote client cannot resolve or reach these internal addresses, causing the page to load partially or display a blank page after a delay, even though the initial proxy connection and response are successful.

Exam trap

The trap here is that candidates see the proxy successfully forwarding and receiving a response and assume the issue is network connectivity or proxy configuration, overlooking the fact that the application's embedded content (hardcoded IPs/hostnames) can break the client-side rendering even when the initial proxy transaction succeeds.

How to eliminate wrong answers

Option A is wrong because the ZTNA proxy is configured with a proxy destination of 10.0.1.200:8443, which implies HTTPS (port 8443 is commonly used for HTTPS), and the debug output confirms the proxy successfully forwarded the request and received a response, indicating HTTPS support is present. Option B is wrong because the debug output explicitly states the proxy forwarded the request to 10.0.1.200:8443 and received a response, proving the internal server is reachable from the FortiGate. Option C is wrong because if the client's ZTNA tags were expired, the client would not be able to establish a ZTNA connection to the gateway at all; the question states remote users can establish the connection, so tags are valid.

162
MCQmedium

An admin needs to configure a FortiGate to send logs to FortiAnalyzer for a specific VDOM only. How can this be achieved?

A.Set the FortiAnalyzer IP in the specific VDOM's log settings
B.Create a separate ADOM in FortiAnalyzer for that VDOM
C.Configure log forwarding globally; it applies to all VDOMs
D.Use a firewall policy to filter logs to FortiAnalyzer
AnswerA

Configuring FortiAnalyzer under the target VDOM's log settings scopes log forwarding to that VDOM alone, since each VDOM maintains independent log configuration on the FortiGate. This satisfies the stem's requirement to send logs for a specific VDOM only, leaving other VDOMs unaffected.

Why this answer

FortiGate allows per-VDOM log configuration, including the FortiAnalyzer IP address, under the VDOM's log settings. This ensures that only logs from that specific VDOM are sent to the designated FortiAnalyzer, while other VDOMs remain unaffected.

Exam trap

The trap here is that candidates often confuse global log forwarding with per-VDOM log settings, assuming that a global configuration can be selectively applied to a single VDOM, which is not supported in FortiGate's VDOM architecture.

How to eliminate wrong answers

Option B is wrong because creating a separate ADOM in FortiAnalyzer is a management and administrative grouping on the FortiAnalyzer side, not a configuration on the FortiGate to control which VDOM's logs are sent. Option C is wrong because configuring log forwarding globally applies to all VDOMs, which does not meet the requirement of sending logs for a specific VDOM only. Option D is wrong because firewall policies are used for traffic filtering and not for selecting which logs are forwarded to FortiAnalyzer; log forwarding is controlled by log settings, not firewall policies.

163
MCQeasy

A company is implementing a Security Fabric with multiple FortiGate devices. They want to use FortiAnalyzer for centralized logging and FortiManager for centralized management. Which of the following is a prerequisite for adding a FortiGate to the Security Fabric?

A.The FortiGate must have FortiAnalyzer configured as a log device
B.The FortiGate's management IP must be configured via DHCP
C.The FortiGate must have network connectivity to the FortiManager
D.The FortiGate must be operating in transparent mode
AnswerC

Connectivity is required for management.

Why this answer

For a FortiGate to join a Security Fabric, it must have network connectivity to the FortiManager that manages the fabric. FortiManager acts as the fabric root or controller, and the FortiGate registers with it using the FortiManager IP or FQDN. Without this connectivity, the FortiGate cannot be added to the Security Fabric topology.

Exam trap

The trap here is that candidates often confuse the prerequisite for logging (FortiAnalyzer) with the prerequisite for fabric management (FortiManager), assuming both must be configured before adding a FortiGate, but only FortiManager connectivity is required for fabric membership.

How to eliminate wrong answers

Option A is wrong because configuring FortiAnalyzer as a log device is not a prerequisite for adding a FortiGate to the Security Fabric; logging can be configured after the FortiGate joins the fabric. Option B is wrong because the FortiGate's management IP can be static or DHCP, but DHCP is not a requirement; the prerequisite is simply that the FortiGate has a reachable management IP. Option D is wrong because the FortiGate can operate in NAT/route mode or transparent mode when joining the Security Fabric; transparent mode is not a requirement.

164
MCQmedium

An administrator wants to use FortiGate to automatically block traffic if FortiEDR detects a threat on an endpoint. Which feature should the administrator configure?

A.Configure a VPN tunnel between FortiGate and FortiEDR
B.Enable FortiGuard Outbreak Prevention on the antivirus profile
C.Configure a static route to the FortiEDR management IP
D.Create an automation stitch with a trigger from FortiEDR and an action to block the source IP
AnswerD

An automation stitch links a FortiEDR detection trigger to a FortiGate action that blocks the offending source IP, giving the automatic enforcement the administrator wants. The trigger-action pairing is what makes the response occur without manual intervention.

Why this answer

FortiGate integrates with FortiEDR via automation stitches, which allow events from FortiEDR (such as a detected threat) to trigger automated actions on FortiGate, such as blocking the source IP of the compromised endpoint. This provides real-time, policy-driven threat response without manual intervention, leveraging the Fortinet Security Fabric. Option A is incorrect because a VPN tunnel is not required; FortiEDR and FortiGate communicate via APIs.

Option B is incorrect because FortiGuard Outbreak Prevention is a separate service that provides threat intelligence, not direct endpoint detection integration. Option C is incorrect because a static route is unnecessary for the API-based communication.

Exam trap

The trap here is that candidates often confuse integration methods, assuming a VPN or routing change is needed for communication, when in fact FortiEDR and FortiGate communicate via the Security Fabric's REST API and automation stitches, not traditional network tunnels.

How to eliminate wrong answers

Option A is wrong because a VPN tunnel is used for secure site-to-site or remote access connectivity, not for receiving threat events from FortiEDR; FortiEDR communicates with FortiGate via REST API or Fabric connector, not VPN. Option B is wrong because FortiGuard Outbreak Prevention is a signature-based feature within antivirus profiles that blocks known outbreaks based on FortiGuard threat intelligence, not a mechanism to receive and act on FortiEDR-specific endpoint detections. Option C is wrong because a static route is used for IP routing and does not enable event-driven communication or automation between FortiEDR and FortiGate; the integration requires API-based triggers, not routing entries.

165
MCQeasy

A FortiGate administrator wants to use PKI certificates for IPsec VPN authentication instead of pre-shared keys. Which phase1 parameter must be set to 'signature' to enable certificate-based authentication?

A.set authmethod signature
B.set cert-validation enable
C.set ike-version 2
D.set peer-id certificate
AnswerA

Setting authmethod to signature makes phase1 use X.509 certificates for peer authentication rather than a pre-shared key, satisfying the requirement to replace PSKs with PKI. FortiGate then validates the peer certificate against the configured local or CA certificate.

Why this answer

In FortiGate IPsec phase1 configuration, certificate-based authentication is enabled by setting authmethod to signature, which tells the FortiGate to use digital signatures (certificates) instead of pre-shared keys. This is the specific phase1 parameter that switches authentication from PSK to certificate-based.

Exam trap

NSE7 often tests the confusion between authmethod (which selects PSK vs signature) and other certificate-related parameters like cert-validation or peer-id — candidates pick cert-validation thinking it enables certificate auth, but it only validates the chain.

How to eliminate wrong answers

Option B is wrong because cert-validation is not the parameter that selects certificate authentication; it relates to validating the peer certificate chain, not choosing the auth method. Option C is wrong because ike-version 2 selects IKEv2 but does not by itself enable certificate authentication — authmethod must still be set to signature. Option D is wrong because peer-id certificate is not a valid FortiGate phase1 parameter for enabling certificate auth; peer-id is used for peer identification, not auth method selection.

166
MCQmedium

A FortiGate with SD-WAN configured has a Performance SLA monitoring Google DNS (8.8.8.8). The SLA is configured with latency threshold 100 ms and jitter threshold 20 ms. The link is currently meeting both thresholds. The administrator wants to ensure that if the SLA fails, traffic moves to another link. Which SD-WAN rule strategy should be used?

A.Best quality
B.Manual selection
C.Maximize bandwidth (SLA)
D.Failover (SLA)
AnswerD

The Failover (SLA) strategy actively monitors the Performance SLA and withdraws the primary link from the rule once latency or jitter breaches its thresholds, redirecting new sessions to the secondary member. This directly satisfies the requirement to move traffic when the SLA fails.

Why this answer

The Failover (SLA) strategy is correct because it ensures that traffic is moved to another link only when the Performance SLA fails, while the primary link is used as long as it meets the configured latency (100 ms) and jitter (20 ms) thresholds. This strategy provides deterministic failover behavior, matching the administrator's requirement to switch traffic only upon SLA failure.

Exam trap

The trap here is that candidates often confuse 'Failover (SLA)' with 'Best quality', thinking that any SLA degradation should trigger a switch, but Best quality would switch even if thresholds are still met, while Failover (SLA) only switches upon threshold violation.

How to eliminate wrong answers

Option A (Best quality) is wrong because it continuously selects the link with the best SLA metrics (lowest latency/jitter), not just failing over when thresholds are exceeded, which can cause unnecessary link switching even when the primary link is still meeting thresholds. Option B (Manual selection) is wrong because it requires explicit administrator intervention to change the active link and does not automatically failover based on SLA conditions. Option C (Maximize bandwidth (SLA)) is wrong because it load-balances traffic across multiple links based on SLA health, rather than providing a primary/backup failover behavior when the SLA fails.

167
MCQeasy

An administrator wants to block a zero-day malware outbreak detected by FortiGuard. Which feature should be configured to automatically block the threat across all enabled FortiGate devices?

A.FortiSandbox Cloud
B.IPS Custom Signatures
C.FortiGuard Outbreak Prevention
D.Application Control
AnswerC

FortiGuard Outbreak Prevention pushes indicators and IPS signatures for active outbreaks to every licensed FortiGate, blocking the zero-day automatically without manual signature authoring. This satisfies the requirement for immediate, fleet-wide blocking rather than per-device configuration.

Why this answer

FortiGuard Outbreak Prevention (option C) is the correct feature because it automatically pushes signatures to all FortiGate devices enrolled in the same FortiGuard network when a new zero-day malware outbreak is detected. This enables immediate, coordinated blocking without manual intervention, which is exactly what the administrator needs for a fast-spreading threat.

Exam trap

The trap here is that candidates often confuse FortiSandbox Cloud with a real-time blocking mechanism, but FortiSandbox Cloud provides analysis and retrospective detection, not automatic, proactive blocking across all devices like Outbreak Prevention does.

How to eliminate wrong answers

Option A is wrong because FortiSandbox Cloud is a sandboxing service that analyzes suspicious files and behaviors, but it does not automatically push blocking signatures to all FortiGate devices; it provides detection results that require manual or policy-based action. Option B is wrong because IPS Custom Signatures are manually created by the administrator to block specific known patterns; they cannot be automatically generated or distributed by FortiGuard for a zero-day outbreak. Option D is wrong because Application Control is designed to manage and block specific applications based on signatures, not to respond to zero-day malware outbreaks with automatically distributed threat intelligence.

168
MCQhard

An administrator configures an ALG for SIP traffic but notices that some SIP calls are failing. The admin suspects the ALG is modifying SIP headers incorrectly. Which debug command can help verify the ALG's actions on SIP packets?

A.diagnose debug application sip -1
B.diagnose debug application alg -1
C.get system performance status
D.diagnose sys session filter proto 17
AnswerA

diagnose debug application sip -1 enables verbose SIP ALG debugging, printing how the ALG parses and rewrites SIP headers and SDP. This directly exposes incorrect header modifications causing call failures, satisfying the administrator's need to verify ALG behaviour on live traffic.

Why this answer

The command 'diagnose debug application sip -1' enables detailed debugging of the SIP ALG process on FortiGate, showing how the ALG inspects and modifies SIP headers (e.g., Via, Contact, SDP). This allows the admin to verify if the ALG is incorrectly rewriting IP addresses or ports, which is a common cause of call failures. The '-1' flag sets the debug level to maximum verbosity, capturing all ALG-related SIP transactions.

Exam trap

The trap here is that candidates confuse the generic 'debug application alg' command with the protocol-specific debug commands, or they assume 'get system performance status' can diagnose ALG issues, when in fact only the protocol-specific debug (e.g., 'debug application sip') reveals header-level modifications.

How to eliminate wrong answers

Option B is wrong because 'diagnose debug application alg -1' is not a valid command; the correct syntax for debugging an ALG requires specifying the application protocol (e.g., 'sip', 'h323') after 'application', not 'alg' itself. Option C is wrong because 'get system performance status' shows system resource usage (CPU, memory) and does not provide packet-level or ALG-specific header modification details. Option D is wrong because 'diagnose sys session filter proto 17' filters sessions by protocol number 17 (UDP), which is useful for narrowing session dumps but does not debug ALG actions or show SIP header modifications.

169
MCQmedium

A FortiGate administrator runs the following command and sees the output: diagnose sys session filter dport 443 diagnose sys session list Output shows sessions with proto=6 and expire time decreasing. What does this indicate?

A.The sessions are using UDP protocol
B.The FortiGate is performing deep packet inspection on these sessions
C.The sessions are being blocked by a firewall policy
D.The sessions are TCP sessions and are active
AnswerD

Proto=6 identifies TCP, and a decreasing expire timer proves the session remains live in the FortiGate session table rather than timing out. This satisfies the stem's constraint: port 443 traffic is being tracked as established, active TCP sessions, confirming normal stateful inspection behaviour.

Why this answer

The command 'diagnose sys session filter dport 443' filters sessions with destination port 443, and 'diagnose sys session list' displays them. The output shows 'proto=6', which is the protocol number for TCP (per IANA protocol numbers). The 'expire time decreasing' indicates that the session timer is counting down, which is normal behavior for an active TCP session that is being refreshed by ongoing traffic.

Therefore, the sessions are TCP and active.

Exam trap

The trap here is that candidates may confuse 'expire time decreasing' with a session being blocked or expiring, when in fact it is a normal indicator of an active TCP session that is being refreshed by traffic.

How to eliminate wrong answers

Option A is wrong because proto=6 specifically indicates TCP, not UDP (UDP is protocol 17). Option B is wrong because the command output does not show any deep packet inspection (DPI) status; DPI would require additional configuration and is not indicated by session list output. Option C is wrong because blocked sessions would not appear in the session list with a decreasing expire time; blocked traffic is denied by the firewall policy and does not create a session entry.

170
MCQeasy

A FortiGate administrator wants to integrate ZTNA with FortiClient EMS to control access to an internal application based on device posture. The admin has configured a ZTNA tag in EMS for 'AntiVirus enabled' and created a ZTNA rule in FortiGate. What additional configuration is required on the FortiGate to enforce access based on the ZTNA tag?

A.Configure SSL VPN to authenticate users and assign tags
B.Install a client certificate on each FortiClient from the FortiGate
C.Enable ZTNA inline CASB in the antivirus profile
D.Configure the FortiGate as an EMS connector and import the tag
AnswerD

FortiGate must be configured as an EMS connector so it can poll FortiClient EMS and import the ZTNA tag. Without this connector, the firewall has no visibility of the 'AntiVirus enabled' tag, so the ZTNA rule cannot match device posture and enforcement fails.

Why this answer

For FortiGate to enforce ZTNA tags created in FortiClient EMS, the FortiGate must be configured as an EMS connector so it can poll and import the tags. Once the EMS connector is authorized and the tags are imported, the ZTNA rule can match on those tags to grant or deny access based on device posture. Without the EMS connector, FortiGate has no visibility into the EMS-defined tags.

Exam trap

The trap is assuming ZTNA tag enforcement works without an EMS connector — candidates often pick SSL VPN or certificate options, but the exam tests that FortiGate must be an authorized EMS connector to import and enforce EMS-defined ZTNA tags.

How to eliminate wrong answers

Option A is wrong because SSL VPN is a remote-access method, not the mechanism for importing ZTNA tags from EMS; ZTNA uses its own rule framework and does not require SSL VPN to assign tags. Option B is wrong because installing client certificates is a separate authentication feature and does not import or synchronize ZTNA tags from EMS. Option C is wrong because inline CASB in an antivirus profile is for cloud application control and data protection, not for enforcing ZTNA tag-based access.

171
Multi-Selectmedium

An administrator is configuring FortiGate automation stitches to respond to a detected ransomware outbreak. The trigger is a high severity event from FortiSandbox. Which TWO actions can be used in an automation stitch to contain the threat?

Select 2 answers
A.Create a new FortiGate administrator account
B.Send an SNMP trap to a monitoring system
C.Change the SSID of a wireless network
D.Execute a CLI script to block the infected host's IP address
E.Quarantine the endpoint using FortiClient EMS integration
AnswersD, E

CLI scripts can be used to block IPs via firewall policies or blacklist.

Why this answer

Executing a CLI script to block the infected host's IP address directly on the FortiGate allows immediate containment by applying a firewall policy or address-based block, which is a standard action in automation stitches for threat response. Option E is correct because quarantining the endpoint via FortiClient EMS integration leverages the FortiClient endpoint agent to isolate the infected device from the network, which is a supported action in automation stitches for ransomware containment.

Exam trap

The trap here is that candidates may confuse notification actions (like SNMP traps) or administrative changes (like creating accounts) with actual containment actions, failing to recognize that only actions that actively block or isolate the threat (CLI script or EMS quarantine) are valid in an automation stitch for ransomware response.

172
MCQmedium

A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?

A.Server-Side Request Forgery
B.Command Injection
C.SQL Injection
D.Cross-Site Scripting
AnswerC

The SQL Injection signature category contains patterns matching SQL syntax manipulation in HTTP requests. Enabling it lets the WAF inspect parameters and block injection attempts, directly satisfying the requirement to block SQL injection attacks against the public web server.

Why this answer

SQL injection attacks specifically target database queries by injecting malicious SQL statements through input fields. FortiGate's WAF signature category for SQL Injection is designed to detect and block these patterns, such as 'OR 1=1' or UNION-based injections, by matching against known attack signatures in the HTTP request payload.

Exam trap

The trap here is that candidates may confuse SQL Injection with Command Injection (Option B) because both involve injection attacks, but SQL Injection targets database layers via SQL syntax, while Command Injection targets the OS shell via system commands.

How to eliminate wrong answers

Option A is wrong because Server-Side Request Forgery (SSRF) is an attack that forces a server to make internal requests, not directly related to SQL injection; FortiGate's WAF has a separate signature category for SSRF. Option B is wrong because Command Injection involves executing system commands (e.g., via shell metacharacters) on the server, not database queries, and is covered by a different WAF signature category. Option D is wrong because Cross-Site Scripting (XSS) injects client-side scripts into web pages viewed by other users, targeting browsers rather than the database backend, and is handled by its own WAF signature category.

173
Multi-Selectmedium

A FortiGate administrator wants to use FortiManager automation stitches to automatically block IP addresses that trigger multiple intrusion prevention events. Which two components are required to configure an automation stitch? (Choose two.)

Select 2 answers
A.Trigger
B.Playbook
C.Destination
D.Schedule
E.Action
AnswersA, E

A trigger defines the event that initiates the automation stitch, such as an IPS log or event handler. Without a trigger, FortiManager has no condition to evaluate, so it is a required component for automatically blocking offending IP addresses.

Why this answer

An automation stitch in FortiManager requires a Trigger to define the event that initiates the stitch (e.g., an intrusion prevention event) and an Action to specify the response (e.g., blocking an IP address via a firewall address object). The Trigger monitors for specific log messages or system events, while the Action executes the configured remediation step. Without both, the stitch cannot be created or function.

Exam trap

The trap here is that candidates often confuse 'Playbook' (an optional grouping of actions) with a required component, or mistakenly think 'Destination' or 'Schedule' are needed for event-driven automation, when in fact only Trigger and Action are mandatory.

174
MCQmedium

A network administrator is troubleshooting why a FortiGate does not appear to be enforcing a newly configured application control profile. The policy is applied to traffic from the internal network to the internet. The administrator runs 'diagnose sys session list' and sees that sessions are being created, but the application control profile is not listed in the session details. Which action should the administrator take to verify that the application control profile is being applied?

A.Use 'diagnose sys session filter' to filter sessions by the policy ID and then run 'diagnose sys session list' to check if the application control profile is referenced.
B.Check the FortiGate's event log for application control violations.
C.Run 'diagnose debug application ipsmonitor -1' to check if the IPS engine is inspecting the traffic.
D.Run 'diagnose test application appctrl 1' to display the application control statistics.
AnswerA

Filtering sessions by the policy ID and listing them will show detailed session information, including the UTM profiles applied. If the application control profile is active, it will appear in the session output. This is the most direct way to verify profile enforcement on a per-session basis.

Why this answer

To verify that an application control profile is being applied to a session, the administrator should filter sessions by the policy ID and list them. The session output includes the UTM profiles associated with the session. This method provides definitive evidence of whether the profile is active, unlike global statistics or logs that may not reflect per-session enforcement.

Exam trap

The trap here is assuming that global application control statistics or logs will confirm per-session profile enforcement, when in fact only detailed session inspection reveals the applied profiles.

175
MCQeasy

Which of the following is a valid command to check the status of all BGP neighbors on a FortiGate?

A.diagnose router bgp summary
B.get router info bgp summary
C.show bgp neighbors
D.diagnose ip router bgp all
AnswerB

'get router info bgp summary' is the FortiOS diagnostic command that lists all BGP neighbours with their state, peer address and prefix counts, letting an administrator verify neighbour status directly from the CLI. It satisfies the requirement to check all BGP neighbours.

Why this answer

'get router info bgp summary' is the standard FortiGate CLI command to display the status of all BGP neighbors, including their state, uptime, and prefixes received. This command retrieves the BGP routing table summary from the FortiGate's routing daemon, which is essential for verifying neighbor relationships and troubleshooting BGP peering issues.

Exam trap

The trap here is that candidates familiar with Cisco IOS often default to 'show bgp neighbors' (Option C), but FortiGate uses a different CLI syntax with 'get router info' for operational state queries, and 'diagnose' commands are reserved for low-level debugging, not standard status checks.

How to eliminate wrong answers

Option A is wrong because 'diagnose router bgp summary' is not a valid FortiGate command; the 'diagnose' prefix is used for advanced debugging, but the correct syntax for BGP summary is under 'get router info bgp summary'. Option C is wrong because 'show bgp neighbors' is a Cisco IOS command, not a FortiGate CLI command; FortiGate uses 'get router info bgp neighbors' for detailed neighbor information, but the question specifically asks for a summary of all neighbors. Option D is wrong because 'diagnose ip router bgp all' is not a valid FortiGate command; the correct diagnostic command for BGP is 'diagnose router bgp all' (without 'ip'), but even that does not provide a summary of neighbor status.

176
MCQmedium

A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?

A.Web filter profile with a URL filter entry set to block
B.IPS sensor with a custom signature that matches the domain name in DNS queries
C.Application control profile with a signature to block the botnet application
D.DNS filter profile with a static domain filter entry set to block
AnswerD

A DNS filter profile allows the administrator to create a static domain filter that blocks or allows specific domains. When applied to a firewall policy, FortiGate inspects DNS queries and blocks resolution for the malicious domain, preventing hosts from learning the IP address. This directly addresses the requirement to block DNS resolution before a connection is attempted.

Why this answer

The DNS filter profile is designed to inspect DNS queries and can block resolution of specific domains using static domain filters. When applied to a policy, it prevents internal hosts from resolving malicious domains, effectively stopping connections before they start. Other features like web filter or application control operate at later stages and do not block DNS resolution.

Exam trap

The trap here is assuming that blocking a URL or application also blocks DNS resolution, but DNS filtering must be configured separately to prevent domain resolution.

177
MCQmedium

A FortiGate has two VDOMs: 'root' and 'customer'. The admin wants to route traffic from 'customer' to the internet via 'root', which has a BGP connection to an ISP. What is the required configuration?

A.Enable VDOM forwarding on the WAN interface in 'root'
B.Configure a static route in 'customer' pointing to the 'root' VDOM's management IP
C.Place both VDOMs in the same VDOM group and enable route leak
D.Create an inter-VDOM link between 'customer' and 'root', and configure policies to allow traffic
AnswerD

An inter-VDOM link provides the Layer 3 path between 'customer' and 'root', since VDOMs have separate routing tables. Firewall policies on both VDOMs must then permit the traffic, allowing 'customer' to reach the internet via root's BGP-learned default route.

Why this answer

Inter-VDOM links are the only supported method for routing traffic between VDOMs on the same FortiGate. An inter-VDOM link creates a virtual point-to-point connection between two VDOMs, allowing traffic to flow through firewall policies. Without this link, VDOMs are isolated and cannot exchange traffic, even if static routes or BGP are configured.

Exam trap

The trap here is that candidates often assume VDOMs can route traffic to each other simply by configuring static routes or using a shared interface, but FortiGate requires a dedicated inter-VDOM link with firewall policies to enable inter-VDOM traffic.

How to eliminate wrong answers

Option A is wrong because VDOM forwarding on a WAN interface is not a feature; interfaces belong to a single VDOM and cannot forward traffic to another VDOM without an inter-VDOM link. Option B is wrong because a static route in 'customer' pointing to the 'root' VDOM's management IP would only route control traffic to the management interface, not data-plane traffic between VDOMs. Option C is wrong because VDOM groups are used for administrative grouping and configuration sharing, not for routing traffic between VDOMs; route leaking is not a supported feature between VDOMs on the same FortiGate.

178
MCQmedium

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator wants VDOM-A and VDOM-B to exchange routing information dynamically without using static routes. The administrator has already created a VDOM link named 'vlink' between the two VDOMs and assigned IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. Which additional configuration is required on each VDOM to enable OSPF adjacency over the VDOM link?

A.Create a firewall policy allowing OSPF (protocol 89) between the VDOM link interfaces.
B.Set the VDOM link interfaces to 'wan' role and enable OSPF on the physical interfaces.
C.Enable OSPF on the VDOM link interface and assign both interfaces to the same OSPF area.
D.Configure a static route on each VDOM pointing to the other VDOM's interface IP address.
AnswerC

OSPF requires that interfaces be enabled for OSPF and placed in the same area to form an adjacency. The VDOM link acts as a point-to-point connection, so configuring both ends with matching area ID and network type will allow OSPF neighbors to form. This is the standard method for dynamic routing between VDOMs.

Why this answer

To enable OSPF over a VDOM link, you must configure OSPF on the link interfaces and ensure they are in the same area. This allows the two VDOMs to form an adjacency and exchange routes dynamically. The VDOM link provides the Layer 3 connectivity, but the routing protocol configuration is what enables dynamic route exchange.

Exam trap

The trap here is assuming that creating a VDOM link automatically enables routing protocols or that a firewall policy is needed for OSPF, when in fact OSPF must be explicitly configured on the link interfaces.

179
Multi-Selecthard

Which THREE actions can an administrator perform using FortiManager in a Security Fabric environment? (Choose three.)

Select 3 answers
A.Upgrade the firmware of multiple FortiGates at once
B.View logs from all managed FortiGates in a single dashboard
C.Terminate IPsec VPN tunnels on the FortiManager
D.Configure FortiGate to manage the FortiManager
E.Push firewall policies to multiple FortiGates simultaneously
AnswersA, B, E

Firmware upgrade can be done centrally.

Why this answer

FortiManager supports centralized firmware management, allowing administrators to upgrade the firmware of multiple FortiGates simultaneously via the 'Firmware Upgrade' wizard in the Device Manager. This leverages the FortiManager's role as a central management point, which can stage and push firmware images to managed devices in a Security Fabric, reducing downtime and ensuring consistency across the fabric.

Exam trap

The trap here is that candidates confuse FortiManager's ability to configure VPN settings with the ability to terminate active tunnels, or they mistakenly think the FortiGate can manage the FortiManager (reversing the management relationship), which is a common misconception in centralized management architectures.

180
MCQeasy

A FortiGate administrator wants to ensure that files in email attachments are disarmed before delivery. Which security feature should be configured in the antivirus profile?

A.Content Disarm and Reconstruction (CDR)
B.FortiSandbox inline scanning
C.Machine Learning Engine
D.Outbreak Prevention
AnswerA

Content Disarm and Reconstruction strips active content from email attachments, rebuilding each file into a safe, functional equivalent before delivery. This satisfies the stem's requirement to disarm files rather than merely detect known threats, unlike signature-based antivirus scanning, which cannot neutralise zero-day or weaponised payloads embedded in documents.

Why this answer

Content Disarm and Reconstruction (CDR) is the correct answer because it is specifically designed to remove active content (e.g., macros, scripts, embedded objects) from email attachments and rebuild them into safe, sanitized versions before delivery. Unlike detection-based methods, CDR proactively disarms threats by stripping potentially malicious elements while preserving the file's usability, making it the ideal choice for disarming attachments in an antivirus profile.

Exam trap

The trap here is that candidates often confuse detection-based features like FortiSandbox or Machine Learning with proactive disarming, assuming that any advanced threat protection feature can 'disarm' files, whereas CDR is the only option that actively reconstructs attachments to remove active content.

How to eliminate wrong answers

Option B is wrong because FortiSandbox inline scanning is a behavioral analysis feature that detonates files in a sandbox to detect threats, but it does not actively strip or reconstruct file content; it relies on detection and blocking, not proactive disarming. Option C is wrong because the Machine Learning Engine uses statistical models to classify files as malicious or benign based on patterns, but it does not modify or reconstruct attachments to remove active content. Option D is wrong because Outbreak Prevention is a FortiGuard service that provides real-time signatures and intelligence for emerging threats, but it is a detection and prevention mechanism, not a file sanitization or reconstruction technology.

181
MCQmedium

An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?

A.show system sdwan health-check
B.diagnose sys sdwan health-check
C.diagnose sys session list
D.execute ping-options source 8.8.8.8
AnswerB

This command displays each SD-WAN member's health-check status, including latency and jitter values from the ping probes. Comparing those readings against the 150 ms and 20 ms thresholds reveals why the member is marked dead.

Why this answer

The 'diagnose sys sdwan health-check' command is the correct tool because it provides real-time, detailed probe results for each SD-WAN health-check member, including latency, jitter, packet loss, and SLA status. This allows the administrator to see exactly why the member is marked as 'dead', such as exceeding the 150 ms latency or 20 ms jitter thresholds. The 'show system sdwan health-check' command only displays configured parameters, not live probe data.

Exam trap

The trap here is that candidates confuse the configuration display command ('show system sdwan health-check') with the diagnostic command ('diagnose sys sdwan health-check'), assuming the former shows live results when it only shows static configuration.

How to eliminate wrong answers

Option A is wrong because 'show system sdwan health-check' displays only the configured SLA parameters (e.g., probe target, thresholds) and not the actual live probe results or current member status. Option C is wrong because 'diagnose sys session list' shows active session entries in the session table, which is unrelated to SD-WAN health-check probe results or SLA compliance. Option D is wrong because 'execute ping-options source 8.8.8.8' sets the source IP for ping commands but does not verify SD-WAN health-check probe results; it is a configuration command, not a diagnostic one.

182
MCQmedium

A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?

A.The FortiSandbox is configured to use 'Analysis' mode instead of 'Inline' mode.
B.The FortiGate is using a different protocol for file submission than for verdict retrieval.
C.The FortiSandbox is not licensed for verdict submission.
D.The FortiGate is not configured with the correct FortiSandbox IP address and API key.
AnswerD

For FortiSandbox to return verdicts to FortiGate, the FortiGate must be configured with the FortiSandbox's IP address and a valid API key. If these are incorrect or missing, the FortiGate cannot authenticate or receive verdicts. The administrator should verify this configuration to ensure verdicts are delivered and acted upon.

Why this answer

The most common reason for missing verdicts is incorrect integration settings on the FortiGate. The FortiGate must have the FortiSandbox's IP address and API key configured correctly to receive verdicts. Without this, files may be submitted, but the firewall cannot authenticate or retrieve results, so blocking does not occur.

Verifying these settings resolves the issue.

Exam trap

The trap here is assuming that licensing or analysis mode affects verdict delivery, when the primary cause is often a misconfigured API key or IP address on the FortiGate.

183
Multi-Selectmedium

An organization wants to implement email authentication to prevent spoofing and phishing attacks. They use FortiMail as their email security gateway. Which THREE mechanisms should they configure to achieve comprehensive email authentication?

Select 3 answers
A.Transport Layer Security (TLS) for SMTP
B.FortiGuard Antispam
C.Sender Policy Framework (SPF)
D.Domain-based Message Authentication, Reporting and Conformance (DMARC)
E.DomainKeys Identified Mail (DKIM)
AnswersC, D, E

SPF verifies that the sending server is authorized by the domain owner.

Why this answer

Sender Policy Framework (SPF) is correct because it allows the domain owner to publish a DNS TXT record listing authorized sending IP addresses, enabling receiving mail servers (like FortiMail) to verify that the email originated from an approved source. This directly prevents spoofing by rejecting messages from unauthorized IPs claiming to be from the domain.

Exam trap

The trap here is that candidates confuse encryption (TLS) or antispam filtering with authentication mechanisms, failing to recognize that SPF, DKIM, and DMARC are the three complementary protocols specifically designed for email authentication and spoofing prevention as defined in RFC 7208, RFC 6376, and RFC 7489.

184
MCQmedium

A FortiGate administrator has deployed ZTNA with FortiClient EMS tagging. A remote user's endpoint is tagged as 'Compliant' in EMS, but the FortiGate ZTNA policy still denies the user's connection to the internal web application. The administrator confirmed the EMS connector status on the FortiGate shows 'Connected' and the tag is visible in the FortiGate's device inventory. What is the most likely cause of the access denial?

A.The ZTNA firewall policy references the tag as a source address, but the user's traffic is being matched by a broader policy above it that denies access.
B.FortiClient EMS requires the endpoint to be re-registered with the FortiGate before the tag can be used in a ZTNA policy.
C.The ZTNA policy must use the EMS tag as a destination address rather than a source address to match the endpoint.
D.The FortiGate requires a valid SSL certificate on the endpoint before it will honor any EMS compliance tag in a ZTNA policy.
AnswerA

Firewall policies are evaluated top-down, and the first matching policy is applied. If a broader deny or restrictive policy appears above the ZTNA tag-based policy and matches the user's source, destination, or service, the ZTNA policy is never reached. This is the most common reason a correctly tagged device still gets denied despite the EMS connector showing Connected and the tag being visible in inventory.

Why this answer

A correctly tagged endpoint can still be denied if a policy earlier in the top-down evaluation order matches the traffic first. The FortiGate applies the first matching firewall policy, so a broad deny or restrictive allow placed above the ZTNA tag-based policy will intercept the connection before the tag-based rule is evaluated. Verifying policy order and specificity resolves the denial.

Exam trap

The trap here is assuming that a visible EMS tag guarantees the ZTNA policy will be reached, ignoring top-down policy evaluation order.

185
Multi-Selectmedium

A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?

Select 2 answers
A.ADOM configuration
B.Log analytics
C.Reports
D.Automation stitches
E.Policy packages
AnswersB, C

Log analytics aggregates and correlates log data from multiple FortiGates, letting the engineer build compliance reports from consolidated views. It satisfies the multi-device collection and reporting requirement directly, rather than relying on per-device raw logs.

Why this answer

Log analytics (option B) is correct because it provides the ability to search, filter, and visualize logs from multiple FortiGates, enabling the identification of trends and anomalies necessary for compliance reporting. Reports (option C) is correct because FortiAnalyzer includes a dedicated reporting engine that can generate scheduled or on-demand compliance reports based on collected logs, with pre-defined templates for standards like PCI DSS, HIPAA, and SOX.

Exam trap

The trap here is that candidates confuse FortiAnalyzer's ADOM feature (which is for administrative separation) with log collection or reporting, or they mistakenly associate automation stitches or policy packages with compliance reporting, which are actually features of FortiGate or FortiManager, not FortiAnalyzer.

186
MCQeasy

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own separate routing table. Which statement is correct?

A.All VDOMs share a single global routing table, but policies can filter routes.
B.Only the management VDOM has a routing table; other VDOMs use the management VDOM's routing table.
C.Each VDOM maintains its own independent routing table, and routes are not shared between VDOMs by default.
D.Routes are automatically synchronized between VDOMs to ensure consistent routing.
AnswerC

In multi-VDOM mode, each VDOM operates as a separate virtual firewall with its own routing table, interfaces, and policies. By default, routes are not shared between VDOMs. This isolation allows each VDOM to have independent routing decisions, which is essential for multi-tenant or segmented environments. Inter-VDOM routing must be explicitly configured if needed.

Why this answer

In a multi-VDOM FortiGate, each VDOM has its own independent routing table. Routes are not shared between VDOMs by default, ensuring isolation. This allows each VDOM to have separate routing policies and next-hop gateways.

Inter-VDOM routing must be explicitly configured using VDOM links if communication between VDOMs is required.

Exam trap

The trap here is assuming that VDOMs share a common routing table or that routes are synchronized, when in fact each VDOM maintains its own separate routing table.

187
MCQmedium

An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?

A.Potentially Unwanted Program
B.Newly Observed Domain
C.Malicious Websites
D.Dynamic DNS
AnswerB

The Newly Observed Domain category is designed to flag domains that have recently appeared and are frequently associated with malicious activity such as phishing. Blocking this category provides proactive protection without manual submissions and typically has low false-positive impact on established business domains, making it the appropriate choice for this requirement.

Why this answer

Newly Observed Domain is a FortiGuard category that identifies domains registered recently, which are disproportionately used in phishing and malware campaigns. Blocking it provides proactive protection against unknown malicious domains without manual URL submission. Other categories either target different threat types or are reactive, so they do not meet the requirement for minimal-impact, automated blocking of newly registered domains.

Exam trap

The trap here is confusing the reactive Malicious Websites category with the proactive Newly Observed Domain category, which is specifically intended for recently registered domains.

188
MCQeasy

What is the purpose of a route map when used with route redistribution on a FortiGate?

A.To create a prefix list for BGP
B.To define the administrative distance of redistributed routes
C.To enable the redistribution process
D.To filter or modify route attributes during redistribution
AnswerD

A route map applies match conditions and set actions during redistribution, permitting or denying specific routes and altering attributes such as metric, tag, or community. This controls exactly which routes enter the target routing protocol and with what values.

Why this answer

Route maps are used with route redistribution to filter which routes are redistributed and to modify route attributes (such as metric, tag, or next-hop) as they are injected from one routing protocol into another. Option D is correct because route maps provide granular control over the redistribution process, allowing administrators to match specific routes using prefix lists or ACLs and then set attributes like metric or tag before the routes are redistributed.

Exam trap

The trap here is that candidates often confuse the route map's role as a filter or modifier with the enabling of redistribution itself, thinking the route map is required to start redistribution, when in fact redistribution is enabled by the 'redistribute' command and the route map is an optional parameter.

How to eliminate wrong answers

Option A is wrong because a prefix list is a separate tool used to match IP prefixes, not a route map; route maps can reference prefix lists, but the route map itself is not a prefix list. Option B is wrong because administrative distance is a property of the routing protocol or static route, not something set by a route map during redistribution; route maps can set metric, tag, or next-hop, but not administrative distance. Option C is wrong because the redistribution process is enabled by the 'redistribute' command under the routing protocol configuration, not by a route map; the route map is an optional filter applied to that redistribution.

189
MCQhard

A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that only specific subnets are allowed over the tunnel and that the tunnel uses strong encryption. After configuring phase1 and phase2, the administrator notices that the tunnel is up, but traffic from a subnet that should be allowed is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. What is the most likely reason for the traffic not passing?

A.The phase2 selectors do not match the local and remote subnets exactly as configured in the firewall address objects.
B.The dead peer detection (DPD) is disabled, causing the tunnel to become stale.
C.The encryption algorithm used in phase2 is not supported by the remote peer.
D.The firewall policy allowing the traffic does not have NAT enabled.
AnswerA

In IPsec VPN, phase2 selectors define the traffic that is allowed over the tunnel. If the local and remote subnets configured in phase2 do not match the actual source and destination addresses of the traffic, the FortiGate will not route that traffic into the tunnel. This is a common misconfiguration. Even if the tunnel is up, mismatched selectors will cause traffic to be dropped or sent unencrypted, depending on routing. The administrator should verify that the phase2 selectors exactly match the subnets defined in the firewall policies and address objects.

Why this answer

Phase2 selectors must match the actual traffic subnets. If they do not, the FortiGate will not encrypt and send that traffic over the tunnel. Even with the tunnel up, mismatched selectors cause traffic to be dropped or routed elsewhere.

The other options would either prevent tunnel establishment or are not relevant to the symptom.

Exam trap

The trap here is assuming that an established tunnel guarantees traffic will pass, overlooking that phase2 selectors must match the actual traffic subnets.

190
MCQmedium

A healthcare provider is deploying ZTNA to secure access to an internal electronic health records (EHR) system. The EHR system is composed of multiple web services running on different ports behind a load balancer with IP 10.0.10.100. The load balancer listens on ports 443, 8443, and 9090. The administrator configures a single ZTNA rule with proxy destination 10.0.10.100:443, expecting that the other ports will be accessed via the same rule. However, users report that they can only access the service on port 443; connections to ports 8443 and 9090 fail. The FortiGate logs show that requests to other ports are being dropped. What should the administrator do to resolve this?

A.Configure the load balancer to redirect all traffic to port 443.
B.Configure the ZTNA gateway to allow all ports to the load balancer.
C.Create separate ZTNA rules for each port (8443 and 9090).
D.Ask users to change the port in their browser to 443.
AnswerC

A ZTNA proxy destination matches the exact IP-and-port pair, so 10.0.10.100:443 covers only port 443. Traffic to 8443 and 9090 matches no rule and is dropped. Separate rules, or a destination covering all three ports, are required.

Why this answer

Each ZTNA rule maps to a single proxy destination port. The rule configured with proxy destination 10.0.10.100:443 only forwards traffic for that specific port. To access services on ports 8443 and 9090, separate ZTNA rules must be created for each port, each with its own proxy destination and access proxy configuration.

Exam trap

The trap here is that candidates assume a single ZTNA rule with a destination IP will automatically forward traffic to all ports on that IP, overlooking that ZTNA rules are port-specific and require separate rules for each service port.

How to eliminate wrong answers

Option A is wrong because redirecting all traffic to port 443 would break the intended functionality of the separate web services running on ports 8443 and 9090, and the load balancer is not designed to redirect traffic arbitrarily. Option B is wrong because the ZTNA gateway does not support a wildcard 'allow all ports' configuration; ZTNA rules require explicit proxy destination IP and port pairs. Option D is wrong because asking users to change the port in their browser does not address the underlying ZTNA rule limitation; the gateway would still drop connections to ports not defined in the rule.

191
MCQeasy

In a Fortinet ZTNA deployment, which component is responsible for forwarding decrypted traffic to the internal application server after the FortiGate proxy has performed SSL inspection?

A.FortiClient EMS
B.ZTNA proxy on FortiGate
C.IPsec VPN tunnel
D.FortiNAC
AnswerB

The FortiGate's ZTNA proxy terminates the client TLS session, performs SSL inspection, then opens a separate connection to the internal application server, forwarding the decrypted traffic onward. This satisfies the stem's requirement that traffic reaches the server after inspection, since the FortiGate itself acts as the forwarding proxy rather than an external access broker.

Why this answer

In Fortinet ZTNA, the FortiGate acts as the ZTNA proxy (also called the access proxy). After it terminates the client's TLS session and performs SSL inspection, the FortiGate itself re-originates the connection to the internal application server. No separate component forwards that decrypted traffic — the FortiGate proxy handles both the client-facing and server-facing legs.

Exam trap

NSE7 often tests the confusion between the control plane (FortiClient EMS distributing tags) and the data plane (FortiGate proxy forwarding traffic) — candidates pick EMS thinking it forwards traffic.

How to eliminate wrong answers

Option A is wrong because FortiClient EMS is the management plane that distributes ZTNA tags and policies to endpoints; it does not proxy or forward application traffic. Option C is wrong because an IPsec VPN tunnel is a transport mechanism for site-to-site or client-to-site connectivity, not the component that forwards decrypted ZTNA proxy traffic to the app server. Option D is wrong because FortiNAC provides network access control (device visibility, onboarding, quarantine), not ZTNA traffic forwarding.

192
Drag & Dropmedium

Drag and drop the steps to configure a site-to-site IPsec VPN on a FortiGate firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Phase 1 establishes the IKE SA, Phase 2 creates the IPsec SA, then routing and policies are applied to allow traffic through the tunnel.

193
MCQmedium

A network administrator is configuring SD-WAN on a FortiGate. They have multiple WAN links and want to ensure that traffic for a critical application uses the link with the lowest latency. Which SD-WAN configuration component should be used to achieve this?

A.Performance SLA with latency threshold and SD-WAN rule using best-quality strategy
B.SD-WAN rule with spillover load balancing
C.SD-WAN members with static priority
D.Load balancing algorithm set to lowest-cost (SLA)
AnswerA

A Performance SLA actively probes each WAN link, measuring latency against the configured threshold, while the SD-WAN rule's best-quality strategy selects the member with the lowest measured latency for the critical application. This directly satisfies the requirement to route traffic over the lowest-latency link.

Why this answer

The Performance SLA monitors latency (and other metrics) against a configured threshold, and the SD-WAN rule with the 'best-quality' strategy dynamically selects the WAN link that currently has the lowest latency. This ensures the critical application traffic is steered to the optimal link based on real-time performance measurements.

Exam trap

The trap here is that candidates confuse 'static priority' (which is a fixed preference) with dynamic SLA-based selection, or they incorrectly assume 'spillover' or 'lowest-cost' algorithms can react to latency changes in real time.

How to eliminate wrong answers

Option B is wrong because spillover load balancing uses bandwidth utilization thresholds to shift traffic, not latency, so it cannot ensure the lowest-latency link is selected. Option C is wrong because static priority assigns fixed preference to links regardless of current performance; if the highest-priority link has high latency, traffic will still use it. Option D is wrong because 'lowest-cost (SLA)' is not a valid load balancing algorithm in FortiOS; the correct term for SLA-based selection is 'best-quality' or 'SLA' strategy, and 'lowest-cost' typically refers to routing protocol metrics, not SD-WAN link quality.

194
MCQeasy

A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?

A.Antivirus
B.Email Filter
C.Web Filter
D.IPS
AnswerA

Antivirus scanning inspects SMTP traffic inline, extracting and examining attachments against FortiGuard signatures to block malicious files before delivery to internal users. Configuring it on the firewall policy governing outbound and inbound mail satisfies the requirement to protect users from email-borne malware at the network perimeter.

Why this answer

FortiGate's Antivirus feature is designed to scan SMTP traffic for malware by inspecting email attachments and body content against virus signatures. When configured in a security policy, it intercepts SMTP sessions, buffers the email data, and performs real-time scanning to block or quarantine malicious files before delivery to internal users.

Exam trap

The trap here is that candidates confuse 'Email Filter' (which handles spam and content filtering) with antivirus scanning, assuming email security is solely about filtering, when in fact malware detection requires the dedicated Antivirus feature to inspect SMTP payloads at the file level.

How to eliminate wrong answers

Option B (Email Filter) is wrong because it focuses on spam filtering, content blocking, and email address/domain blacklisting, not on malware detection in attachments. Option C (Web Filter) is wrong because it controls HTTP/HTTPS traffic to block malicious URLs and web content, not SMTP email traffic. Option D (IPS) is wrong because it detects and prevents network-level attacks (e.g., exploits, buffer overflows) based on signatures, but it does not perform file-level malware scanning on email attachments.

195
MCQmedium

An administrator wants to block outbound traffic from internal hosts to known malicious domains without relying on full URL inspection or certificate inspection. The requirement is to use a lightweight DNS-based security service on FortiGate that can block botnet C2 and phishing domains. Which FortiGuard feature should the administrator enable and configure in a DNS filter profile?

A.FortiGuard Anti-Spam
B.FortiGuard IP Reputation
C.FortiGuard DNS Filter
D.FortiGuard Web Filter
AnswerC

FortiGuard DNS Filter uses the FortiGuard DNS rating service to categorize and block malicious domains at the DNS resolution stage. It requires a DNS filter profile applied to a policy, with the FortiGuard category set to block botnet C2, phishing, and other malicious categories. This matches the requirement to block outbound traffic to malicious domains without full URL or certificate inspection.

Why this answer

FortiGuard DNS Filter is the correct choice because it provides DNS-layer security by categorizing and blocking malicious domains using FortiGuard's DNS rating service. It is lightweight and does not require full URL inspection or certificate inspection. Enabling it in a DNS filter profile and applying it to a firewall policy allows the FortiGate to block botnet C2 and phishing domains effectively.

Exam trap

The trap here is confusing DNS filtering with web filtering, assuming that web filtering can block domains at the DNS layer without SSL inspection.

196
MCQhard

You are troubleshooting a VPN phase 2 negotiation failure. The logs show 'no proposal chosen'. What is the MOST likely cause?

A.The remote gateway IP is incorrect
B.The pre-shared key mismatch
C.The IKE version mismatch
D.The phase 2 proposal settings differ between the peers
AnswerD

Phase 2 negotiation requires both peers to agree on identical encryption, authentication and lifetime parameters. When the responder's proposal set shares no matching transform with the initiator's, it discards every offer and returns 'no proposal chosen', so mismatched phase 2 settings directly cause the failure.

Why this answer

The 'no proposal chosen' error in VPN phase 2 indicates that the IPsec peers could not agree on a common set of phase 2 parameters (such as encryption algorithm, authentication algorithm, or PFS group). Since phase 2 negotiation occurs after IKE phase 1 has successfully completed, the issue is specifically with the IPsec SA proposal settings, not with pre-shared keys or IKE version. Therefore, differing phase 2 proposals between the peers are the most likely cause.

Exam trap

The trap here is that candidates often confuse phase 1 and phase 2 errors, assuming any 'no proposal chosen' relates to IKE proposals, when in fact the error message is specific to the IPsec SA negotiation in phase 2.

How to eliminate wrong answers

Option A is wrong because an incorrect remote gateway IP would prevent phase 1 (IKE) from establishing, not cause a phase 2 'no proposal chosen' error. Option B is wrong because a pre-shared key mismatch would cause an IKE authentication failure during phase 1, not a phase 2 proposal mismatch. Option C is wrong because an IKE version mismatch would prevent phase 1 negotiation entirely, resulting in a different error (e.g., 'no acceptable proposal' during phase 1), not a phase 2-specific 'no proposal chosen'.

197
MCQeasy

A FortiGate is configured with ECMP load balancing. What is the default behavior when multiple routes have equal cost?

A.The route with the lowest metric is always preferred
B.The administrator must enable per-packet load balancing
C.Traffic is load balanced across the routes using a hash algorithm
D.All traffic is sent over the first route until it fails
AnswerC

With equal-cost multipath, FortiGate installs all matching routes and distributes sessions across them using a hash of source and destination addresses and ports. This preserves per-flow ordering while sharing traffic, rather than selecting one route or preferring the oldest entry.

Why this answer

When ECMP load balancing is configured on a FortiGate, the default behavior is to distribute traffic across multiple equal-cost routes using a hash algorithm. This hash algorithm considers fields such as source/destination IP, protocol, and ports to ensure session consistency, meaning all packets belonging to the same session follow the same path. This is the standard ECMP behavior in FortiOS, as documented in the FortiGate Administration Guide.

Exam trap

The trap here is that candidates often confuse ECMP with per-packet load balancing or assume that FortiGate defaults to a failover model, but the NSE7 exam expects you to know that ECMP uses a hash algorithm for per-session load balancing by default, not per-packet or primary-backup.

How to eliminate wrong answers

Option A is wrong because in ECMP, all routes have equal cost (metric), so no single route is preferred based on metric; the FortiGate uses a hash algorithm instead. Option B is wrong because per-packet load balancing is not the default and must be explicitly enabled via CLI (e.g., 'set load-balance-mode per-packet'), and even then it is rarely used due to packet reordering issues; the default is per-session load balancing using a hash. Option D is wrong because that describes a failover or primary/backup routing behavior, not ECMP; FortiGate does not send all traffic over the first route until failure unless 'set priority' or 'set weight' is used to create unequal costs.

198
MCQmedium

During a failover test in an active-passive HA cluster, the administrator notices that the secondary unit does not take over the primary role after a link failure on the primary. The 'get system ha status' shows both units in 'standalone' mode. What is the MOST likely cause?

A.The session pickup feature is disabled
B.The HA heartbeat interface is down or misconfigured on one unit
C.The cluster is running in active-active mode
D.The HA override feature is disabled
AnswerB

HA state synchronisation and failover depend on heartbeat packets traversing the dedicated HA link. If that interface is down or misconfigured, each unit loses peer visibility and reverts to standalone, so the secondary never detects primary failure and cannot assume the primary role.

Why this answer

When both units show 'standalone' mode in 'get system ha status', it indicates that the HA cluster has lost communication between the primary and secondary units, causing them to operate independently. The most common cause is a failure or misconfiguration of the HA heartbeat interface, which is the dedicated link used for cluster synchronization and health monitoring. Without a functional heartbeat, the secondary cannot detect the primary's link failure and will not initiate a failover.

Exam trap

The trap here is that candidates often confuse session pickup or override features with the fundamental requirement of a working heartbeat interface, assuming that failover is triggered by link failure detection on data ports rather than requiring a separate, dedicated heartbeat link.

How to eliminate wrong answers

Option A is wrong because session pickup is a feature for synchronizing existing sessions during a failover, not for detecting link failures or triggering role changes; disabling it does not prevent the secondary from taking over the primary role. Option C is wrong because if the cluster were running in active-active mode, both units would show as 'active' in HA status, not 'standalone', and the question specifies an active-passive cluster. Option D is wrong because the HA override feature controls whether a primary unit can preempt a secondary after recovery, not the ability to detect link failures or perform failover; disabling it does not cause standalone mode.

199
MCQmedium

An organization wants to deploy a web application firewall (WAF) to protect a public-facing web application. They are evaluating FortiGate versus FortiWeb. Which of the following is a key advantage of using FortiWeb over FortiGate for WAF functionality?

A.FortiWeb offers advanced bot detection and positive security model
B.FortiGate can perform SSL deep inspection without performance impact
C.FortiGate supports a larger number of web servers behind a single policy
D.FortiGate can automatically patch web application vulnerabilities
AnswerA

FortiWeb provides dedicated WAF engines with machine-learning bot detection and a positive security model that whitelists known-good behaviour, unlike FortiGate's signature-based IPS approach. This satisfies the requirement for advanced application-layer protection against automated threats and zero-day attacks targeting the public-facing application.

Why this answer

FortiWeb is a dedicated web application firewall that provides advanced bot detection and a positive security model, which allows only explicitly allowed traffic based on a whitelist of known good patterns. This is a key advantage over FortiGate, which primarily uses a negative security model (signature-based) and lacks the same depth of bot mitigation and positive enforcement for web-specific threats.

Exam trap

The trap here is that candidates assume FortiGate's integrated WAF features are equivalent to a dedicated WAF, but FortiWeb's positive security model and advanced bot detection are unique differentiators that FortiGate lacks.

How to eliminate wrong answers

Option B is wrong because FortiGate, like any device performing SSL deep inspection, incurs performance overhead due to decryption/re-encryption, and FortiGate does not claim zero performance impact. Option C is wrong because FortiGate does not inherently support a larger number of web servers behind a single policy; both platforms can scale, but FortiWeb is specifically optimized for high-volume web server pools with granular per-server policies. Option D is wrong because neither FortiGate nor FortiWeb automatically patches web application vulnerabilities; they detect and block exploit attempts but do not modify application code.

200
Multi-Selecthard

A company is deploying ZTNA to protect an internal application. They want to ensure that only users with devices that have disk encryption enabled and the latest OS patches can access the application. Which THREE components must be configured to achieve this?

Select 3 answers
A.FortiNAC for network admission control
B.IPsec VPN to encrypt traffic between client and FortiGate
C.FortiClient on the endpoint device
D.FortiGate ZTNA access proxy with tag-based rules
E.FortiClient EMS to define compliance policies and assign tags
AnswersC, D, E

FortiClient performs the endpoint posture checks for disk encryption and OS patch level, then reports compliance to EMS. These checks generate the tags that the FortiGate evaluates, so FortiClient is essential to enforce the stated conditions.

Why this answer

Option C is correct because FortiClient is the endpoint agent that performs the on-device posture checks (disk encryption status and OS patch level) and reports that information to FortiClient EMS. Option E is correct because FortiClient EMS is where the compliance/ZTNA tagging policies are defined and where tags (such as 'disk-encrypted' and 'patched') are assigned to endpoints based on those posture results. Option D is correct because the FortiGate ZTNA access proxy enforces tag-based rules, only allowing access to the internal application when the endpoint presents the required compliance tags.

Option A is not needed since FortiNAC provides network admission control (NAC) for LAN/port-level access, not ZTNA application access control. Option B is not required because ZTNA uses TLS-based access proxy tunnels rather than an IPsec VPN to reach the protected application.

Exam trap

NSE7 often tests the division of labor between FortiClient (collector), EMS (policy/tag engine), and FortiGate (enforcer) — candidates who conflate FortiNAC's NAC role with ZTNA posture enforcement pick the FortiNAC distractor.

201
Multi-Selectmedium

An administrator is deploying a FortiGate with multiple VDOMs in NAT/route mode. The administrator needs to configure inter-VDOM routing between VDOM-A and VDOM-B. Which two actions are required to enable traffic to flow between the two VDOMs? (Choose two.)

Select 2 answers
A.Configure a static route in the global routing table pointing to both VDOMs.
B.Configure firewall policies in each VDOM to allow traffic from the source to the destination through the VDOM link.
C.Enable inter-VDOM routing globally using the command 'config system global' and set 'inter-vdom-routing enable'.
D.Assign the same VDOM ID to both VDOMs to allow routing between them.
E.Create a VDOM link and assign it to both VDOM-A and VDOM-B.
AnswersB, E

Even with a VDOM link, the implicit deny policy in each VDOM blocks traffic. You must create policies in VDOM-A and VDOM-B that permit the desired traffic, specifying the VDOM link as the incoming and outgoing interface. Both directions require policies to allow bidirectional communication.

Why this answer

Inter-VDOM routing requires a VDOM link to provide the Layer 3 connection, and firewall policies in both VDOMs to permit the traffic. The VDOM link acts as a virtual cable between the two VDOMs, and each VDOM must have a policy allowing traffic from the source to the destination via that link. Without both, traffic is blocked by the implicit deny.

Exam trap

The trap here is thinking that a global setting can enable inter-VDOM routing, when in fact it requires per-VDOM VDOM links and policies.

202
MCQmedium

An administrator wants to use FortiGate to block outbound traffic to known malicious IP addresses based on a threat intelligence feed. They configure a threat feed connector and a firewall policy with a destination address group. However, the policy is not blocking traffic to the malicious IPs. What is the most likely cause?

A.The destination address group does not include the threat feed connector object.
B.The threat feed connector is not enabled in the security fabric settings.
C.The threat feed connector is configured with the wrong protocol (HTTP instead of HTTPS).
D.The firewall policy is placed after a more permissive policy that allows the traffic.
AnswerD

FortiGate processes firewall policies in top-down order. If a more permissive policy above the blocking policy allows the traffic, the blocking policy is never evaluated. This is a common misconfiguration. The administrator should move the blocking policy above the permissive policy or adjust the permissive policy.

Why this answer

FortiGate evaluates firewall policies sequentially. If a permissive policy appears above the blocking policy, traffic is allowed and never reaches the blocking rule. Placing the blocking policy before any permissive policies ensures malicious traffic is denied.

Exam trap

The trap here is focusing on the threat feed configuration while overlooking the fundamental firewall policy processing order.

203
MCQmedium

A company wants to receive threat intelligence feeds from external sources to enhance their FortiGate's protection. Which method should be used to integrate external threat feeds into FortiGate?

A.Use FortiGuard Threat Intelligence Service which automatically pulls feeds.
B.Manually add IP addresses to local address objects.
C.Configure an external threat feed connector in FortiGate, such as using a URL to a STIX/TAXII feed.
D.Use FortiAnalyzer to push feeds to FortiGate.
AnswerC

Configuring an external threat feed connector lets FortiGate ingest STIX/TAXII feeds directly from external providers, satisfying the requirement to receive third-party threat intelligence. FortiOS polls the feed URL and populates threat feed objects, which external connectors then reference in firewall policies, blocklists and DNS filters without manual updates.

Why this answer

FortiGate supports integration with external threat intelligence feeds via the External Threat Feed connector, which can consume STIX/TAXII feeds from a URL. This allows the FortiGate to dynamically update its threat database with indicators from third-party sources, enhancing its protection without relying solely on FortiGuard services.

Exam trap

The trap here is that candidates may confuse FortiGuard's built-in threat intelligence service with the ability to integrate external feeds, assuming FortiGuard can be customized to pull from third-party sources, when in fact the External Threat Feed connector is the dedicated feature for that purpose.

How to eliminate wrong answers

Option A is wrong because FortiGuard Threat Intelligence Service is a built-in Fortinet service that provides curated feeds, not a method to integrate external third-party feeds; it cannot be configured to pull from arbitrary external sources. Option B is wrong because manually adding IP addresses to local address objects is a static, labor-intensive approach that does not support automated, dynamic updates from external threat feeds, defeating the purpose of real-time intelligence integration. Option D is wrong because FortiAnalyzer is a log management and analytics platform, not a mechanism to push threat feeds to FortiGate; it can forward logs or events but does not handle external feed ingestion for threat intelligence updates.

204
MCQeasy

A FortiGate administrator is configuring a ZTNA rule to protect an internal application. The administrator wants to ensure that only devices with a specific compliance tag are allowed, while all other devices are denied. The administrator has already created the ZTNA server and the FortiClient EMS tags. What is the correct way to enforce this requirement in the firewall policy?

A.Use a firewall policy with the ZTNA server as the destination and a schedule that only allows access during business hours, which implicitly blocks non-compliant devices.
B.Create a firewall policy that allows all users to the ZTNA server, then create a separate deny policy for non-compliant devices below it.
C.Create a firewall policy that references the ZTNA server and includes the compliance tag as a source or destination condition, so only tagged devices match the allow rule.
D.Configure the ZTNA server to require the compliance tag in its application mapping, which automatically denies untagged devices at the proxy level.
AnswerC

ZTNA tag-based enforcement is implemented by referencing the ZTNA server in the policy and using the compliance tag as a matching condition. Only devices that have the tag will match the allow policy, and all others will fall through to the implicit deny. This directly enforces the requirement without needing a separate deny rule.

Why this answer

ZTNA tag enforcement is achieved by referencing the ZTNA server in the firewall policy and adding the compliance tag as a matching condition. Only devices that present the tag match the allow policy; all others are denied by the implicit deny. Separate deny policies, ZTNA server mappings, and schedules do not provide the required tag-based control.

Exam trap

The trap here is thinking that a deny policy placed after an allow policy will block non-compliant devices, when the allow policy must itself require the compliance tag to match.

205
MCQmedium

An organization deploys FortiEDR to protect endpoints. Which component is responsible for collecting and sending telemetry data to the FortiEDR management console?

A.FortiGate firewall
B.FortiEDR Sensor (Agent)
C.FortiAnalyzer
D.FortiClient EMS
AnswerB

The FortiEDR Sensor, installed on each endpoint, performs continuous event collection and forwards normalised telemetry to the management console, satisfying the stem's requirement for the collecting and sending component. Unlike the Central Manager or Aggregator, which handle policy and correlation, the Sensor is the sole endpoint-resident agent generating raw telemetry.

Why this answer

The FortiEDR Sensor (Agent) is the endpoint-resident component that collects telemetry data—such as process creation, network connections, file system changes, and registry modifications—and securely transmits it to the FortiEDR management console (Controller) for analysis and threat detection. Without the sensor, the management console has no visibility into endpoint activity.

Exam trap

The trap here is that candidates often confuse FortiClient EMS (which manages endpoint policies) with the FortiEDR Sensor, assuming that EMS handles telemetry collection, when in fact the sensor is a separate, dedicated agent for endpoint detection and response.

How to eliminate wrong answers

Option A is wrong because FortiGate is a next-generation firewall that provides network security and can integrate with FortiEDR via API or syslog, but it does not collect or send endpoint telemetry data to the FortiEDR management console. Option C is wrong because FortiAnalyzer is a centralized logging and reporting appliance that aggregates logs from Fortinet devices (e.g., FortiGate, FortiMail) but does not act as the telemetry collection agent for FortiEDR endpoints. Option D is wrong because FortiClient EMS manages endpoint compliance, VPN, and web filtering policies, and while it can integrate with FortiEDR, it is not the component that collects and sends endpoint telemetry to the FortiEDR console.

206
Matchingmedium

Match each FortiGate routing concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manually configured route

Link-state dynamic routing protocol

Path-vector dynamic routing protocol

Routes traffic based on policy criteria

Load balancing across multiple paths

Why these pairings

Correct matches: PBR, Route redistribution, Administrative distance, and Static route are correctly paired. ECMP and Metric are swapped; ECMP distributes traffic across equal-cost paths, while Metric compares routes within a protocol.

207
MCQhard

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to multiple VDOMs to save physical ports. Which feature should they use?

A.VDOM links
B.Transparent mode
C.VLAN subinterfaces
D.Interface zones
AnswerC

VLAN subinterfaces allow a single physical interface to be logically divided into multiple VLAN interfaces, each of which can be assigned to a different VDOM. This enables sharing of a physical port across VDOMs while maintaining traffic separation. It is the standard method for this requirement.

Why this answer

VLAN subinterfaces allow a physical interface to be partitioned into multiple logical interfaces, each with its own VLAN ID. These subinterfaces can be assigned to different VDOMs, enabling the sharing of a single physical port while keeping traffic isolated. This is the correct feature for the scenario.

Exam trap

The trap here is confusing VDOM links with VLAN subinterfaces; VDOM links connect VDOMs internally, while VLAN subinterfaces connect VDOMs to external networks over a shared physical link.

208
MCQmedium

A FortiGate is configured with a firewall policy that has a URL filter profile. Users report that access to a specific website is blocked, but the administrator wants to verify which URL filter category matched the request. The administrator runs 'diagnose debug application urlfilter -1' in the CLI. However, no output appears. What is the MOST likely reason for the lack of output?

A.The urlfilter debug application is not available on this FortiGate model or firmware version.
B.The URL filter profile is not applied to the firewall policy that matches the user traffic.
C.The URL filter debug level is set to 0 by default and must be enabled with 'diagnose debug enable'.
D.The administrator did not run 'diagnose debug enable' after setting the debug level.
AnswerD

In FortiOS, to view debug output for a specific application, you must first set the debug level using 'diagnose debug application <name> <level>' and then enable debug globally with 'diagnose debug enable'. Without enabling debug, no output is displayed even if the level is set. This is a common oversight. The command 'diagnose debug application urlfilter -1' sets the level to verbose, but debug remains disabled until 'diagnose debug enable' is issued.

Why this answer

To capture URL filter debug messages, the administrator must set the debug level for the urlfilter application and then enable debug globally. The command 'diagnose debug application urlfilter -1' sets the level, but without 'diagnose debug enable', no output is generated. This is a common troubleshooting step that is often missed.

Once enabled, the debug will show category matches and other details.

Exam trap

The trap here is assuming that setting the debug level automatically enables debug output, when in fact a separate global enable command is required.

209
MCQmedium

A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?

A.Configure the policy to use full SSL inspection and import the pinned applications' certificates as trusted CAs on the FortiGate.
B.Disable SSL inspection entirely on the policy and rely on the application control profile to identify the pinned applications.
C.Create an exemption in the SSL inspection profile for the pinned applications and apply deep inspection to the remaining traffic.
D.Set the SSL inspection profile to certificate-inspection for the policy and leave the rest of the traffic uninspected.
AnswerC

An SSL exemption lets the FortiGate bypass decryption for specified destinations or applications that use certificate pinning, while deep inspection continues for all other HTTPS traffic. This satisfies the goal of inspecting as much traffic as possible without breaking the pinned applications, and it is the supported way to handle pinned or sensitive traffic in a deep-inspection policy.

Why this answer

Deep inspection is required to examine encrypted traffic for threats, but certificate-pinned applications will reject the FortiGate's re-signed certificate. The supported approach is to add those applications or destinations to an SSL exemption so they are not decrypted, while deep inspection continues for everything else. This balances security visibility with application availability and is the recommended operational practice for mixed traffic.

Exam trap

The trap here is assuming that disabling SSL inspection or importing certificates is an acceptable substitute for a targeted SSL exemption when certificate-pinned applications must keep working.

210
MCQmedium

A FortiGate administrator needs to configure a policy that allows traffic from VDOM A to VDOM B using inter-VDOM routing. Which configuration is required?

A.A single policy in VDOM A with destination VDOM B
B.A static route in VDOM A pointing to VDOM B
C.Policies in both VDOMs allowing traffic to and from the inter-VDOM link
D.Disable VDOM security features
AnswerC

Inter-VDOM links terminate in both VDOMs, so each side needs a firewall policy permitting traffic across the link. Without policies in both VDOM A and VDOM B, the implicit deny drops packets, so this satisfies the bidirectional inter-VDOM routing requirement.

Why this answer

Inter-VDOM routing requires explicit policy enforcement on both sides of the inter-VDOM link. A single policy in VDOM A cannot control return traffic from VDOM B, and FortiGate does not implicitly allow traffic between VDOMs. Therefore, policies must be configured in both VDOMs to permit traffic in both directions, ensuring stateful inspection and security controls are applied consistently.

Exam trap

The trap here is that candidates assume a single policy in the source VDOM is sufficient, forgetting that FortiGate treats each VDOM as a separate virtual firewall requiring its own policy for return traffic.

How to eliminate wrong answers

Option A is wrong because a single policy in VDOM A only controls outbound traffic from VDOM A; return traffic from VDOM B would be dropped without a corresponding policy in VDOM B. Option B is wrong because static routes direct traffic but do not provide firewall policy enforcement; inter-VDOM traffic still requires explicit allow policies in both VDOMs. Option D is wrong because disabling VDOM security features would bypass all security controls, which is not a valid or secure configuration for inter-VDOM routing.

211
MCQhard

An administrator configures email authentication (SPF, DKIM, DMARC) on FortiMail. They find that legitimate emails are being marked as spam by FortiMail. The SPF check passes but DKIM fails. What could be the issue?

A.The SPF record is too strict
B.The email was forwarded by an intermediary that strips the DKIM signature
C.FortiMail has a bug in the DKIM verification module
D.The DMARC policy is set to reject
AnswerB

DKIM validates a signature over specific headers and body. An intermediary forwarding the message can modify or strip those elements, invalidating the signature, so DKIM fails even though SPF still passes on the sending path.

Why this answer

When an email is forwarded by an intermediary (e.g., a mailing list or forwarding service), the intermediary often modifies the message headers or body, which invalidates the DKIM signature. Since DKIM relies on a cryptographic hash of the original message content and selected headers, any alteration—even by a legitimate forwarder—causes the signature verification to fail. The SPF check passes because the forwarding server may be authorized in the SPF record, but DKIM failure triggers spam classification if the DMARC policy is not aligned.

Exam trap

The trap here is that candidates assume DKIM failure is always due to a misconfiguration on the sending side, rather than recognizing that forwarding or intermediary modification is a common and legitimate cause of DKIM breakage.

How to eliminate wrong answers

Option A is wrong because a strict SPF record (e.g., -all) would cause SPF to fail, not pass; the question states SPF passes, so this is irrelevant. Option C is wrong because FortiMail's DKIM verification module is RFC 6376 compliant and does not have a known bug that would cause legitimate DKIM signatures to fail; this is a red herring. Option D is wrong because DMARC policy (p=reject) only dictates how receivers handle messages that fail both SPF and DKIM alignment; it does not cause DKIM to fail—it is an action based on the result, not the cause of the failure.

212
Multi-Selecthard

An organization is deploying FortiEDR to enhance endpoint protection. Which THREE capabilities does FortiEDR provide? (Choose three.)

Select 3 answers
A.Forensic investigation and root cause analysis
B.Decoy deployment to lure attackers
C.Real-time threat detection using behavioral analysis
D.Automated response to isolate compromised endpoints
E.Email security filtering
AnswersA, C, D

FortiEDR provides detailed forensic data for investigation.

Why this answer

FortiEDR provides forensic investigation and root cause analysis by recording detailed endpoint telemetry, including process creation, network connections, and file system changes. This allows security teams to reconstruct the full attack chain after an incident, identifying the initial infection vector and all subsequent malicious activities. The platform correlates these events across multiple endpoints to provide a comprehensive timeline for investigation.

Exam trap

The trap here is that candidates may confuse FortiEDR's capabilities with those of other Fortinet products, such as assuming decoy deployment (FortiDeceptor) or email filtering (FortiMail) are part of FortiEDR's endpoint protection suite.

213
MCQmedium

A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?

A.Web filter with FortiGuard category-based blocking
B.Application control with botnet signatures
C.DNS filter with botnet C&C domain blocking enabled
D.Antivirus profile with botnet C&C IP blocking
AnswerC

FortiGate's DNS filter, when configured with botnet C&C domain blocking, intercepts DNS responses for known malicious domains and redirects them to a sinkhole IP, preventing resolution. This directly addresses the scenario where malicious domains are not being blocked despite FortiGuard category blocking being active, because category blocking alone may not cover all C&C domains unless DNS filtering is enforced.

Why this answer

The DNS filter with botnet C&C domain blocking is designed to intercept DNS responses for known malicious domains and redirect them to a sinkhole, effectively preventing communication. This is the correct mechanism when the goal is to block DNS resolution of malicious domains. Other features operate at different layers and do not provide DNS-level sinkholing, so they would not address the specific problem.

Exam trap

The trap here is assuming that FortiGuard category-based web filtering alone will block all malicious domains, but it does not intercept DNS queries unless DNS filtering with botnet C&C blocking is enabled.

214
MCQhard

Refer to the exhibit. A tunnel interface is configured with IP 10.0.1.1/30 and remote-ip 10.0.1.2/30. The phase2 defines src-subnet as 10.0.1.0/30 and dst-subnet as 10.0.2.0/30. What is the most likely problem with this configuration?

A.The phase2 src-subnet includes the tunnel interface IP
B.The remote gateway is set to a static IP but the peer might be dynamic
C.The tunnel interface is missing the 'ip' command
D.The phase2 dst-subnet overlaps with the remote gateway
AnswerA

The phase2 selector 10.0.1.0/30 overlaps the tunnel interface subnet, so traffic sourced from 10.0.1.1 matches the encryption domain and is routed into the tunnel rather than reaching the remote gateway. FortiGate requires selectors distinct from the tunnel IP range to avoid this routing conflict.

Why this answer

The phase2 src-subnet is set to 10.0.1.0/30, which includes the tunnel interface IP 10.0.1.1/30. In IPsec VPN configurations, the phase2 selector must not include the tunnel interface IP itself because the tunnel interface is used for routing encapsulated traffic; including it can cause routing loops or prevent the tunnel from establishing correctly. The correct src-subnet should be the protected internal network behind the FortiGate, not the tunnel subnet.

Exam trap

The trap here is that candidates often confuse the tunnel interface subnet with the protected local subnet, assuming the phase2 selectors should match the tunnel IPs, when in fact they must specify the actual internal networks behind the VPN gateways.

How to eliminate wrong answers

Option B is wrong because the question does not provide any information about the peer being dynamic; the remote-ip is statically configured, and a static peer is valid. Option C is wrong because the tunnel interface is configured with an IP address (10.0.1.1/30), which implies the 'ip' command is present; the issue is not a missing command. Option D is wrong because the phase2 dst-subnet (10.0.2.0/30) does not overlap with the remote gateway (10.0.1.2/30); they are on different subnets, so no overlap exists.

215
MCQmedium

A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?

A.They are used for NAT policies only
B.They provide default logging for all traffic
C.They apply only to the root VDOM
D.They are evaluated before other policies in the same policy package
AnswerD

Header policies sit at the top of a policy package and are evaluated before the package's other policies, letting administrators enforce global rules such as logging or blocking across all managed FortiGates without editing each individual policy.

Why this answer

Header policies in FortiManager are evaluated before any other policies in the same policy package. This allows administrators to enforce mandatory rules—such as blocking specific traffic or applying global inspection—that must be processed first, ensuring they are not bypassed by more specific policies later in the sequence.

Exam trap

The trap here is that candidates often confuse header policies with global policies or default settings, assuming they apply only to NAT or root VDOMs, when in fact they are simply policies that are evaluated first within a specific policy package.

How to eliminate wrong answers

Option A is wrong because header policies are not limited to NAT policies; they can include any firewall policy type, including security, authentication, or traffic shaping. Option B is wrong because header policies do not automatically provide default logging; logging must be explicitly configured within each policy. Option C is wrong because header policies apply to the entire policy package, not just the root VDOM; they affect all VDOMs that use that package.

216
MCQeasy

What is the purpose of a management VDOM in a multi-VDOM FortiGate?

A.To apply security profiles for all VDOMs
B.To route all inter-VDOM traffic
C.To provide a dedicated VDOM for system administration and management traffic
D.To host customer-facing services
AnswerC

A management VDOM isolates administrative traffic—HTTPS, SSH and SNMP—from production VDOMs, satisfying the requirement to separate system administration from user data forwarding. It centralises management access, letting administrators reach the FortiGate without exposing management interfaces on customer-facing VDOMs.

Why this answer

A management VDOM is a dedicated administrative VDOM that isolates system management traffic (e.g., SSH, HTTPS, SNMP, syslog) from data-plane VDOMs. This ensures that administrative access and logging remain available even if a data VDOM fails or is misconfigured, and it prevents management traffic from competing with production traffic for resources.

Exam trap

The trap here is that candidates often confuse the management VDOM with a 'super-VDOM' that controls all others, but in reality it only handles administrative traffic and has no data-plane forwarding role.

How to eliminate wrong answers

Option A is wrong because security profiles (e.g., antivirus, web filtering) are applied per VDOM or per policy, not centrally by a management VDOM; each VDOM has its own independent security policy engine. Option B is wrong because inter-VDOM traffic is routed by the VDOM link or inter-VDOM link feature, not by the management VDOM; the management VDOM does not participate in data-plane forwarding. Option D is wrong because customer-facing services (e.g., web servers, application hosting) are typically placed in a separate data VDOM, not the management VDOM, which is reserved strictly for administrative access and monitoring.

217
MCQmedium

A FortiGate is configured as a ZTNA access proxy for an internal application. The administrator wants to enforce device compliance using FortiClient EMS tags before allowing access. Which configuration step is required to ensure that only endpoints with a specific EMS tag can access the application?

A.Set the ZTNA rule action to 'deny' for non-compliant devices.
B.Configure FortiClient EMS as a fabric connector and synchronize EMS tags.
C.Create a ZTNA rule with a source address of the EMS tag.
D.Enable 'device-detection' on the ZTNA rule.
AnswerB

To use EMS tags in ZTNA rules, FortiGate must be integrated with FortiClient EMS via a fabric connector. This allows FortiGate to receive dynamic tag information about endpoints. After synchronization, the EMS tags become available as source objects in ZTNA rules. This is the essential step to enforce compliance based on EMS tags.

Why this answer

Enforcing device compliance via EMS tags in ZTNA requires FortiGate to be integrated with FortiClient EMS using a fabric connector. This integration synchronizes EMS tags, which can then be used as source objects in ZTNA rules. Without this, tags are not available, and compliance cannot be enforced.

Other steps like device detection or deny actions are secondary.

Exam trap

The trap here is thinking that simply referencing an EMS tag in a rule is enough, without first establishing the EMS fabric connector and tag synchronization.

218
MCQeasy

A FortiGate administrator wants to see the current number of active sessions. Which command provides this information?

A.show system session-info
B.diagnose sys session stat
C.diagnose sys session list
D.get system performance status
AnswerB

The diagnose sys session stat command outputs session statistics including the current count of active sessions on the FortiGate. It directly satisfies the requirement to view the present number of established sessions, unlike commands that list session details or clear the session table.

Why this answer

The 'diagnose sys session stat' command displays a summary of the current session table, including the total number of active sessions, which is exactly what the administrator needs. This command is part of FortiGate's diagnostic tools and provides a quick statistical overview without listing individual session details.

Exam trap

The trap here is that candidates confuse 'diagnose sys session stat' with 'diagnose sys session list' or 'show system session-info', assuming any command with 'session' in it will show the session count, but only 'stat' provides the aggregated summary without listing every session.

How to eliminate wrong answers

Option A is wrong because 'show system session-info' is not a valid FortiGate CLI command; the correct command for viewing session information is 'diagnose sys session stat' or 'get system session-info' (which shows session-related configuration, not active session counts). Option C is wrong because 'diagnose sys session list' dumps all individual session entries, which is useful for deep inspection but does not provide a simple count of active sessions and can overwhelm the output. Option D is wrong because 'get system performance status' shows overall system performance metrics like CPU and memory usage, not the number of active sessions.

219
Multi-Selecteasy

A company is deploying ZTNA to replace their legacy VPN. They want to ensure that only users with a valid certificate and compliant antivirus can access the internal application. Which TWO components are required on the FortiGate for this deployment?

Select 2 answers
A.ZTNA proxy rule with access proxy
B.Dynamic routing protocol (BGP)
C.Firewall policy with ZTNA tags matching
D.SSL-VPN portal
E.IPsec phase1 with certificate authentication
AnswersA, C

The access proxy defines the protected internal application and terminates ZTNA traffic, enforcing certificate and posture checks before forwarding. Without this proxy rule on the FortiGate, no ZTNA policy can validate the user certificate and compliant antivirus required by the stem.

Why this answer

Option A is correct because the ZTNA proxy rule with an access proxy is the FortiGate component that publishes the internal application and enforces the ZTNA access proxy, which is where client certificate authentication and device posture (such as compliant antivirus) are validated before traffic is allowed. Option C is correct because a firewall policy with ZTNA tags matching is required to permit and control the traffic from ZTNA-authenticated users, using the dynamic ZTNA tags that FortiClient EMS assigns based on certificate and antivirus compliance. Together, the access proxy handles the ZTNA authentication and posture check, while the firewall policy with ZTNA tag matching authorizes the session to the internal application.

Option B is not required because BGP is a dynamic routing protocol unrelated to ZTNA access control. Option D is not required because SSL-VPN portal is the legacy VPN feature being replaced by ZTNA. Option E is not required because IPsec phase1 with certificate authentication is a site-to-site or remote VPN tunnel mechanism, not the ZTNA access proxy enforcement used here.

Exam trap

NSE7 often tests the confusion between ZTNA components and legacy VPN components, causing candidates to select SSL-VPN or IPsec options instead of the required ZTNA proxy rule and ZTNA tag-based firewall policy.

220
MCQhard

An administrator is deploying an ADVPN with a hub and two spokes. The hub is behind a NAT device and has a static public IP, while both spokes are behind NAT with dynamic public IPs. The administrator wants the spokes to establish shortcuts directly between each other. Which configuration is required for the shortcut to form?

A.Configure the hub to use a dial-up VPN with a pre-shared key and disable DPD on the spokes to prevent shortcut teardown.
B.Enable IPsec NAT traversal on the hub and both spokes, and ensure that the spokes can exchange IKE and ESP traffic through their NAT devices.
C.Configure the spokes with a static public IP address so that the hub can advertise them for direct shortcut negotiation.
D.Enable IPsec NAT traversal on the hub only, because the hub is the device that initiates shortcut negotiation.
AnswerB

ADVPN shortcut negotiation relies on IKE and ESP packets reaching the spoke peers directly. When spokes are behind NAT, NAT-T must be enabled on every peer so that the traffic is encapsulated in UDP and the NAT devices can maintain the mappings. This allows the hub to relay the shortcut proposal and the spokes to establish the direct tunnel.

Why this answer

For ADVPN shortcuts to form between spokes that are behind NAT, every peer must support NAT traversal so IKE and ESP can be carried over UDP through the NAT devices. The hub relays the shortcut information, but the direct tunnel between spokes depends on NAT-T being enabled on those spokes as well. Static addresses and DPD changes are not prerequisites for shortcut creation.

Exam trap

The trap here is thinking that NAT traversal is only needed on the device behind NAT or only on the hub, when every ADVPN peer that may be behind NAT must have it enabled.

221
MCQhard

An administrator has a FortiGate with multiple VDOMs and a management VDOM enabled. The management VDOM is used for out-of-band management and logging. The administrator wants to ensure that the management VDOM can reach a syslog server on the Internet while all other VDOMs use a separate data VDOM for their Internet traffic. Which configuration is required to allow the management VDOM to use a different default route than the other VDOMs?

A.Configure a default route in the management VDOM pointing to the management gateway, and ensure that the management VDOM has its own interface with Internet connectivity.
B.Use the global routing table to define a default route that applies only to the management VDOM.
C.Enable 'allow-subnet-overlap' in the management VDOM to permit a separate default route.
D.Create a policy route in the management VDOM that forwards all traffic to the data VDOM's default gateway.
AnswerA

Each VDOM maintains its own routing table. To give the management VDOM a distinct default route, you must configure it within that VDOM. The management VDOM must also have an interface connected to the Internet or a next-hop that can reach the syslog server. This isolates management traffic from data traffic.

Why this answer

To allow the management VDOM to use a different default route, you must configure that route within the management VDOM itself. Each VDOM has its own routing table, so a default route in one VDOM does not affect others. The management VDOM also needs its own interface with Internet reachability.

This ensures management traffic uses the intended path while data VDOMs use theirs.

Exam trap

The trap here is confusing the global routing table with per-VDOM routing tables; the global table does not provide default routes for VDOM traffic.

222
MCQhard

A network administrator is troubleshooting a FortiGate HA cluster in active-passive mode. The administrator notices that the secondary unit is not receiving heartbeat packets from the primary unit, and the cluster has split. The administrator runs 'diagnose sys ha status' on both units and sees that the primary unit shows the secondary as 'not connected', while the secondary unit shows the primary as 'not connected'. The administrator verifies that the heartbeat interfaces are correctly configured and physically connected. What is the MOST likely cause of the split?

A.The primary unit is overloaded and cannot send heartbeat packets.
B.The heartbeat interfaces are configured with different VLAN IDs on each unit.
C.The HA group ID is different on the two units, preventing them from forming a cluster.
D.The heartbeat packets are being dropped by an intermediate switch due to a native VLAN mismatch.
AnswerD

In HA, heartbeat packets are typically sent as untagged or with a specific VLAN. If the heartbeat interfaces are connected through a switch, a native VLAN mismatch on the switch ports can cause untagged heartbeat packets to be dropped or misdirected. This would result in both units showing each other as not connected, leading to a split. Since the administrator verified the FortiGate interfaces are correctly configured, the issue likely lies in the network infrastructure, such as a native VLAN mismatch on the switch.

Why this answer

The most likely cause is that heartbeat packets are being dropped by an intermediate switch due to a native VLAN mismatch. When the FortiGate heartbeat interfaces are connected through a switch, the switch must properly forward the heartbeat traffic. A native VLAN mismatch can cause untagged packets to be dropped or sent to the wrong VLAN, preventing heartbeats from reaching the peer.

This leads to both units losing communication and forming separate clusters.

Exam trap

The trap here is focusing solely on FortiGate configuration and overlooking the network infrastructure, such as switch VLAN settings, which can silently drop heartbeat packets.

223
MCQmedium

An administrator has a FortiGate 600E running FortiOS 7.2 with multiple VDOMs enabled. The administrator wants to create a new VDOM named 'DMZ' and assign it a specific physical interface (port3) that is currently unused. After creating the VDOM, the administrator navigates to Network > Interfaces in the DMZ VDOM but cannot see port3 in the list of available interfaces to assign. What is the most likely reason for this?

A.The interface port3 is currently used by another VDOM, so it is hidden until it is removed from that VDOM.
B.The administrator needs to reboot the FortiGate after creating the VDOM for the interface to become visible.
C.The physical interface port3 must be assigned to a VDOM from the global configuration before it appears in the VDOM's interface list.
D.The administrator must enable 'VDOM mode' on the interface before it can be seen in the VDOM.
AnswerC

In FortiOS, physical interfaces are initially in the global configuration. To make an interface available within a VDOM, the administrator must first assign it to that VDOM from the global VDOM settings (System > VDOM > select VDOM > assign interfaces). Only after assignment does the interface appear in the VDOM's Network > Interfaces list for configuration.

Why this answer

In a multi-VDOM FortiGate, physical interfaces belong to the global configuration by default. To use an interface within a VDOM, the administrator must explicitly assign it to that VDOM from the global VDOM settings. Until that assignment is made, the interface will not be listed in the VDOM's Network > Interfaces section, preventing configuration.

Exam trap

The trap here is assuming that any unused physical interface is automatically available in all VDOMs, when in fact it must be explicitly assigned from the global configuration.

224
MCQhard

A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?

A.Static URL filter with the action set to 'Block' and the type set to 'Simple'.
B.FortiGuard web filter category override using a local category definition.
C.DNS filter with a custom blocklist entry for the domain.
D.Application control signature that matches the domain's HTTP header.
AnswerA

A static URL filter entry of type 'Simple' can match a specific URL or domain and apply the 'Block' action regardless of the FortiGuard category. This override takes precedence over category-based filtering, which is why the domain is blocked even though it is categorized as 'Unrated'. The custom blocklist is implemented through static URL filter entries that are evaluated before category actions.

Why this answer

A static URL filter entry with the action set to Block and type Simple allows an administrator to block specific URLs or domains regardless of their FortiGuard category. This is why a domain categorized as Unrated can still be blocked and present a block page. The static URL filter is evaluated as part of the web filter profile and overrides category-based actions.

Exam trap

The trap here is assuming that a block page always reflects the FortiGuard category action, when a static URL filter entry can enforce blocking independently of the category.

225
MCQmedium

In FortiManager, an administrator wants to apply a set of firewall policies to multiple FortiGates in different ADOMs. The policies must be centrally managed. What is the best approach?

A.Use the Global ADOM to define global policies that apply to all ADOMs
B.Create a policy package in each ADOM and use the same policies
C.Configure the policies directly on each FortiGate
D.Use automation stitches to copy policies between ADOMs
AnswerA

Global ADOM policies are inherited by all ADOMs, providing central management.

Why this answer

The Global ADOM in FortiManager allows administrators to define firewall policies that are automatically inherited by all ADOMs, ensuring consistent, centrally managed policy enforcement across multiple FortiGates without manual duplication. This approach leverages FortiManager's hierarchical policy model, where global policies are pushed to each ADOM's policy packages and take precedence over local policies unless overridden.

Exam trap

The trap here is that candidates often confuse the Global ADOM with a simple 'global policy' feature, not realizing it is a dedicated administrative domain with its own policy database and inheritance rules, leading them to choose option B (manual duplication) or D (automation stitches) as workarounds.

How to eliminate wrong answers

Option B is wrong because creating a policy package in each ADOM with the same policies duplicates configuration effort and defeats centralized management, as each ADOM's policies must be individually maintained and pushed. Option C is wrong because configuring policies directly on each FortiGate bypasses FortiManager's centralized control, leading to configuration drift and no single source of truth. Option D is wrong because automation stitches are designed for event-triggered actions (e.g., dynamic responses), not for replicating static policy sets between ADOMs, and they lack the inheritance and revision control of Global ADOM policies.

Page 2

Page 3 of 10

Page 4

All pages