Courseiva

Fortinet NSE 7 Advanced Security NSE7 (NSE7) — Questions 301–375

718 questions total · 10pages · All types, answers revealed

Page 4

Page 5 of 10

Page 6
301
MCQmedium

An administrator has configured an SD-WAN zone named 'virtual-wan-link' with two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'SLA1' is created and assigned to the zone. The administrator wants to ensure that SD-WAN rules use the SLA results to select the best member. Which statement correctly describes how the FortiGate uses the performance SLA results in SD-WAN rule selection?

A.The performance SLA results are used only for monitoring and logging; SD-WAN rules do not consider them.
B.The FortiGate uses the SLA status to mark members as 'alive' or 'dead' and only selects members that are 'alive' when the rule's strategy is 'SLA' or when the rule is configured to use SLA information.
C.The FortiGate uses the SLA results to automatically adjust the link cost of each member, which then influences routing decisions.
D.The performance SLA results are used only for load balancing algorithms like 'source-ip-based' and 'session-based'.
AnswerB

SD-WAN rules can be configured with a strategy that considers SLA status. When a member fails the SLA, it is marked as dead and not used for traffic that requires the SLA. This ensures traffic is steered to a member that meets the configured latency, jitter, and packet loss thresholds.

Why this answer

When a performance SLA is assigned to an SD-WAN zone, the FortiGate actively probes the members. If a member fails to meet the SLA thresholds, it is marked as dead. SD-WAN rules that are configured to use SLA information will then avoid that member, ensuring traffic is sent over a link that meets the required performance criteria.

This is a core feature of Fortinet SD-WAN.

Exam trap

The trap here is assuming that SLA results are only for monitoring and do not influence traffic steering, when in fact they directly affect member selection in SD-WAN rules.

302
MCQeasy

An administrator is troubleshooting an HA cluster where both units show as primary after a link failure. What is the most likely cause of this split-brain scenario?

A.The HA heartbeat interface is down or misconfigured
B.The priority values are set identically
C.The HA uptime is mismatched between the two units
D.The session pickup feature is disabled
AnswerA

A failed or misconfigured heartbeat interface prevents the cluster units from exchanging HA hello packets, so each unit loses visibility of its peer and independently promotes itself to primary. This directly satisfies the stem's link-failure constraint, producing the dual-primary split-brain condition described.

Why this answer

In a Fortinet HA cluster, the heartbeat interface is responsible for exchanging health and synchronization information between units. If this interface goes down or is misconfigured, the units lose communication and each assumes the other is dead, causing both to transition to the primary state (split-brain). This is the most common cause of split-brain scenarios in FortiGate HA clusters.

Exam trap

The trap here is that candidates often confuse the cause of split-brain with configuration mismatches like priority or session pickup, but the root cause is almost always a loss of heartbeat communication between the cluster members.

How to eliminate wrong answers

Option B is wrong because identical priority values do not cause split-brain; they simply mean the cluster will use other tie-breakers (such as serial number or uptime) to determine the primary. Option C is wrong because mismatched uptime is a normal tie-breaker used when priorities are equal, not a cause of split-brain. Option D is wrong because session pickup is a feature for synchronizing sessions during failover, and disabling it does not affect the HA election process or cause both units to become primary.

303
MCQhard

An administrator configures SD-WAN with multiple members. The SD-WAN rule uses the 'latency' strategy. The administrator notices that traffic is not switching to the best-performing member even when latency exceeds the threshold. What could be the issue?

A.The SLA target is not configured or not applied to the SD-WAN rule
B.The load balancing algorithm is set to 'source-ip-based'
C.The threshold is set too low
D.The SD-WAN members are in different VDOMs
AnswerA

The latency strategy only steers traffic away from a member when an SLA target is defined and bound to the rule. Without that target, FortiGate has no threshold to compare measured latency against, so no member is ever marked out of SLA and traffic stays put.

Why this answer

The latency-based SD-WAN rule requires an SLA target to define acceptable performance thresholds. Without an SLA target configured and applied to the rule, the FortiGate has no baseline to compare against, so it will never trigger a member switch even if latency exceeds the threshold. The SLA target must be linked to the SD-WAN rule via the 'set sla' command in the rule configuration.

Exam trap

The trap here is that candidates assume the 'latency' strategy alone will automatically monitor and switch based on real-time latency, but FortiGate requires an explicit SLA target to define the threshold and trigger the evaluation.

How to eliminate wrong answers

Option B is wrong because the load balancing algorithm (e.g., source-ip-based) affects how traffic is distributed among members under normal conditions, but it does not prevent the latency strategy from switching traffic when the SLA is violated; the latency strategy overrides load balancing for failover decisions. Option C is wrong because setting the threshold too low would cause more frequent switching, not prevent it; the issue is that no switching occurs at all, indicating the threshold is not being evaluated. Option D is wrong because SD-WAN members in different VDOMs are supported as long as inter-VDOM links are properly configured; this would not inherently block SLA-based switching.

304
MCQmedium

A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?

A.The destination IP only
B.The combination of source IP and destination IP hashed to select an interface
C.The source IP only
D.The interface with the lowest current utilization
AnswerB

Source-dst-ip load balancing hashes the source and destination address pair, so 10.0.0.1 to 172.16.0.1 always maps to the same SD-WAN member, satisfying the stem's requirement to identify the determining factor. Unlike source-ip-only, both addresses feed the hash, pinning this flow to one interface.

Why this answer

With 'set load-balance-mode source-dst-ip', the FortiGate performs a hash of both the source IP and destination IP to deterministically select an outgoing SD-WAN member. This ensures that all packets belonging to the same source-destination pair are consistently forwarded over the same interface, preserving flow symmetry without relying on per-packet metrics.

Exam trap

The trap here is that candidates confuse 'source-dst-ip' with 'source-ip' or 'destination-ip' modes, or incorrectly assume that SD-WAN load balancing always considers real-time link utilization, which is only true for 'spillover' or 'lowest-cost' strategies, not hash-based modes.

How to eliminate wrong answers

Option A is wrong because the destination IP alone is used only in 'load-balance-mode destination-ip', not in 'source-dst-ip' mode. Option C is wrong because the source IP alone is used only in 'load-balance-mode source-ip', not in 'source-dst-ip' mode. Option D is wrong because 'load-balance-mode source-dst-ip' uses a static hash of the IP pair, not dynamic interface utilization; the FortiGate does not consider current utilization in this mode.

305
Multi-Selectmedium

An administrator is troubleshooting a scenario where traffic from VLAN 100 to a server at 10.1.2.100 is being blocked. The FortiGate has an active security policy allowing the traffic and the routing table shows a correct route. Which TWO diagnostic commands should the administrator run to identify the cause of the blockage?

Select 2 answers
A.diagnose sniffer packet any 'host 10.1.2.100' 4
B.get system performance status
C.diagnose ip arp list
D.diagnose sys session list
E.diagnose debug flow
AnswersA, E

Captures packets to verify traffic reaches the FortiGate.

Why this answer

'diagnose sniffer packet any host 10.1.2.100 4' captures packets to/from the server at the interface level, allowing the administrator to see if traffic from VLAN 100 is actually arriving at the FortiGate and whether it is being dropped or forwarded. This command helps identify if the issue is at Layer 2 (e.g., VLAN misconfiguration) or Layer 3 (e.g., routing or firewall drops).

Exam trap

The trap here is that candidates often choose 'diagnose sys session list' thinking it shows blocked traffic, but it only lists established sessions, not dropped packets or failed session creation attempts.

306
MCQhard

Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?

A.The Fabric Root serial number is incorrect
B.The FortiGate is not registered with FortiManager
C.The policy package on FortiManager is not assigned to the correct device group or policy target
D.The Security Fabric is not fully connected
AnswerC

FortiManager pushes policy only to devices covered by the installed policy package's assignment. If the FortiGate is absent from the target device group or policy target, installation silently skips it, so no updates arrive despite successful registration and Security Fabric membership.

Why this answer

FortiManager uses policy packages that must be explicitly assigned to a device group or specific FortiGate. Even if the FortiGate is registered and part of the Security Fabric, if the policy package is not assigned to the correct device group or policy target, the FortiGate will not receive policy updates. This is a common misconfiguration where the policy package exists but is not linked to the device.

Exam trap

The trap here is that candidates assume registration and Fabric connectivity guarantee policy updates, but FortiManager requires explicit policy package assignment to the device group or policy target, which is a separate configuration step.

How to eliminate wrong answers

Option A is wrong because the Fabric Root serial number is used for Security Fabric topology discovery and does not affect FortiManager policy push; a mismatch would break Fabric connectivity, not policy updates. Option B is wrong because the scenario explicitly states the FortiGate is registered with FortiManager, so this option contradicts the given information. Option D is wrong because the Security Fabric being not fully connected would impact Fabric services like topology sharing, but FortiManager policy updates use a direct management tunnel (port 541/TCP) independent of Fabric connectivity.

307
MCQmedium

An administrator deploys a FortiGate in transparent mode within a Layer 2 network. They apply a firewall policy with an antivirus profile to inspect traffic between two VLANs. What is a key characteristic of transparent mode that affects policy application?

A.NAT is automatically applied to all traffic to preserve private IP addresses
B.Firewall policies are applied only to traffic entering the management interface
C.Each VDOM in transparent mode requires a unique IP address for management
D.Traffic is forwarded based on MAC addresses, and policies are applied transparently without changing the IP path
AnswerD

Operating at Layer 2, the FortiGate forwards frames by MAC address rather than routing between subnets, so the IP path is unchanged. Policies and antivirus inspection still apply to the bridged traffic, satisfying the requirement to inspect inter-VLAN traffic without altering the existing IP topology.

Why this answer

In transparent mode, FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses rather than IP addresses. This allows firewall policies, including antivirus inspection, to be applied to traffic between VLANs without modifying the IP path or requiring NAT, ensuring seamless integration into existing Layer 2 networks.

Exam trap

The trap here is that candidates often assume transparent mode requires NAT or IP-based routing changes, but the key is that it operates purely at Layer 2, forwarding based on MAC addresses and applying policies without altering the IP path.

How to eliminate wrong answers

Option A is wrong because NAT is not automatically applied in transparent mode; NAT is a Layer 3 function and transparent mode operates at Layer 2, preserving the original IP addresses. Option B is wrong because firewall policies in transparent mode are applied to traffic passing through the FortiGate interfaces, not just the management interface; the management interface is used for administrative access only. Option C is wrong because VDOMs in transparent mode do not require a unique IP address for management; each VDOM can share the management IP or use a dedicated IP, but it is not a mandatory characteristic that affects policy application.

308
MCQeasy

A FortiGate administrator enables Dead Peer Detection (DPD) on an IPsec VPN tunnel. What is the primary purpose of DPD?

A.To dynamically adjust the tunnel MTU
B.To encrypt the IKE negotiation traffic
C.To automatically renegotiate the IKE SA before it expires
D.To detect when the remote peer is no longer reachable
AnswerD

DPD sends periodic encrypted probes (R-U-THERE) through the tunnel and expects replies. When the remote FortiGate stops responding within the configured retry limits, the local FortiGate tears down the stale IKE SA and routes traffic through an alternate path, satisfying the requirement to detect an unreachable peer.

Why this answer

DPD is used to monitor the liveness of the remote peer. If the peer becomes unreachable, DPD detects it and can trigger a failover or tunnel teardown, ensuring traffic does not blackhole.

309
MCQhard

An administrator runs 'get router info bgp summary' and sees that the BGP session to a neighbor is in the 'Idle' state. The neighbor IP is reachable via ping. The BGP configuration uses loopback interfaces with 'update-source loopback1'. What is the MOST likely reason for the Idle state?

A.There is no route on the neighbor back to the FortiGate's loopback IP
B.The loopback interface is down or has no IP address assigned
C.The BGP neighbor's remote-as is misconfigured
D.The BGP timer values (keepalive/hold) are mismatched
AnswerA

With update-source loopback1, the FortiGate sources BGP packets from its loopback address, so the neighbour must have a return route to that loopback. Ping to the neighbour succeeds, but without the reverse route the TCP session cannot establish, leaving BGP Idle.

Why this answer

The 'Idle' state in BGP indicates that the session cannot start, often due to a missing route to the neighbor's update-source IP. Since the neighbor IP is reachable via ping but the session uses loopback interfaces with 'update-source loopback1', the FortiGate's BGP packets will source from its loopback1 IP. If the neighbor does not have a route back to that loopback IP, it cannot respond to the TCP handshake, leaving the session stuck in Idle.

This is a classic BGP loopback peering issue where reachability of the source IP is required, not just the physical interface IP.

Exam trap

The trap here is that candidates assume ping reachability to the neighbor IP guarantees BGP session establishment, but they overlook that BGP packets are sourced from the loopback interface, requiring the neighbor to have a return route to that specific source IP.

How to eliminate wrong answers

Option B is wrong because if the loopback interface were down or had no IP, the 'update-source loopback1' command would fail to source packets, but the question states the neighbor IP is reachable via ping, implying the loopback is operational. Option C is wrong because a misconfigured remote-as would typically cause the session to transition to 'Active' or 'Connect' states, not remain in 'Idle', as BGP first attempts a TCP connection before checking AS numbers. Option D is wrong because mismatched keepalive/hold timers do not prevent the session from leaving Idle; they are negotiated during the Open message exchange after the TCP connection is established, so the session would reach 'Active' or 'Connect' first.

310
MCQeasy

What is the function of a VRF (Virtual Routing and Forwarding) on a FortiGate?

A.To provide redundancy for routing protocols
B.To aggregate multiple physical interfaces into one logical interface
C.To create multiple independent routing tables
D.To encrypt traffic between different virtual domains
AnswerC

A VRF maintains a separate routing table and forwarding instance, allowing overlapping IP subnets to coexist on one FortiGate. Traffic within each VRF is isolated from others, enabling multi-tenant or segmented routing without additional hardware.

Why this answer

VRF (Virtual Routing and Forwarding) on a FortiGate allows the creation of multiple independent routing tables within a single physical device. This enables network segmentation and traffic isolation at Layer 3, where each VRF maintains its own routing table, forwarding decisions, and interface associations, preventing routes from leaking between VRFs unless explicitly configured with route leaking.

Exam trap

The trap here is that candidates confuse VRF with VDOM (Virtual Domain), but VRF is a Layer 3 routing isolation mechanism within a single VDOM, whereas VDOM provides full administrative and security separation at the device level.

How to eliminate wrong answers

Option A is wrong because VRF does not provide redundancy for routing protocols; redundancy is achieved through protocols like VRRP, FGCP (FortiGate Cluster Protocol), or routing protocol features like BGP multipath. Option B is wrong because aggregating multiple physical interfaces into one logical interface is the function of link aggregation (LAG) or interface bonding, not VRF. Option D is wrong because encrypting traffic between different virtual domains is the role of IPsec VPNs or VDOM inter-VDOM links with encryption, not VRF; VRF focuses on routing table separation, not encryption.

311
MCQhard

A FortiGate has multiple IPsec VPNs to different branch offices. The administrator notices that one VPN tunnel is flapping (going up and down repeatedly). From the CLI, 'diagnose vpn ike gateway list' shows the gateway state as 'up' but then quickly goes to 'down'. What is the MOST likely cause?

A.The remote gateway's certificate is expired
B.The phase2 proposal is mismatched
C.Dead Peer Detection (DPD) retry interval is too short
D.The pre-shared key is incorrect
AnswerC

An overly aggressive DPD retry interval causes the FortiGate to declare the peer dead before replies arrive, tearing down the IKE SA and forcing renegotiation; the gateway cycles up then down, matching the observed flapping.

Why this answer

A flapping IPsec tunnel where the IKE gateway shows 'up' then quickly 'down' is most commonly caused by Dead Peer Detection (DPD) being too aggressive — if the DPD retry interval or retry count is too short, transient packet loss or latency causes the FortiGate to declare the peer dead and tear down the tunnel, which then renegotiates and flaps.

Exam trap

NSE7 often tests the misconception that any tunnel problem is a crypto mismatch — candidates pick phase2 or PSK errors, but those prevent establishment, not cause flapping after 'up'.

How to eliminate wrong answers

Option A is wrong because an expired remote certificate would cause the tunnel to fail to establish entirely (IKE negotiation failure), not flap up and down after coming up. Option B is wrong because a phase2 proposal mismatch would prevent the tunnel from ever reaching 'up' — it would fail at quick mode, not flap. Option D is wrong because an incorrect pre-shared key causes IKE phase1 authentication to fail outright, so the tunnel would never come up.

312
MCQeasy

An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links based on the source IP address of the traffic. Which load balancing algorithm should be used to achieve this?

A.Volume-based
B.Session-based
C.Source IP-based
D.Spoiled-weighted round robin
AnswerC

The source IP-based algorithm distributes traffic across members based on the source IP address, ensuring that sessions from the same source IP consistently use the same member. This meets the requirement to load balance based on source IP. It is a common method for session persistence.

Why this answer

The source IP-based algorithm is designed to distribute traffic across SD-WAN members based on the source IP address. This ensures that all sessions from a particular source IP are consistently routed through the same member, which can be important for applications that require session persistence. It is one of the available load balancing algorithms in FortiOS SD-WAN.

Exam trap

The trap here is confusing session-based with source IP-based load balancing, as both involve sessions but use different criteria for distribution.

313
MCQmedium

An administrator configures two FortiGate units in an active-passive HA cluster. During a failover test, the administrator notices that the secondary unit becomes primary but the session table is empty, causing all existing connections to drop. Which configuration change should be made to preserve session information during failover?

A.Enable FGCP configuration synchronization
B.Configure dead gateway detection on the FortiGate units
C.Enable link-failover on the monitored interfaces
D.Enable session pickup and configure HA session synchronization
AnswerD

Session pickup forwards the primary's session table to the secondary, and HA session synchronization keeps TCP and UDP session state mirrored. Without both, the newly promoted unit has no existing sessions, so every established connection drops during failover.

Why this answer

Session pickup and HA session synchronization are specifically designed to replicate the session table from the primary FortiGate to the secondary unit in an active-passive cluster. Without this feature, the secondary unit becomes primary but has no knowledge of existing sessions, causing all active connections to drop. Enabling session synchronization ensures that session state information is continuously mirrored to the standby unit, allowing seamless failover without disrupting established flows.

Exam trap

The trap here is that candidates often confuse configuration synchronization (which is automatic and covers settings) with session synchronization (which must be explicitly enabled), leading them to incorrectly select option A thinking it preserves sessions.

How to eliminate wrong answers

Option A is wrong because FGCP configuration synchronization (enabled by default in HA clusters) only synchronizes configuration changes, not the dynamic session table; it does not preserve active sessions during failover. Option B is wrong because dead gateway detection is a network monitoring feature used to detect upstream gateway failures and trigger route changes, not a mechanism for replicating session state between HA units. Option C is wrong because link-failover on monitored interfaces triggers a failover when a monitored interface goes down, but it does not address the preservation of session information; the session table remains empty on the standby unit unless session synchronization is enabled.

314
MCQmedium

A FortiGate 600E is running multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 each have an inter-VDOM link interface named 'ivl-1' and 'ivl-2' respectively, and both are assigned IP addresses in the 10.10.10.0/30 subnet. VDOM-1 has a static route to 192.168.2.0/24 via 10.10.10.2, and VDOM-2 has a static route to 192.168.1.0/24 via 10.10.10.1. A user in VDOM-1 (192.168.1.10) cannot ping a server in VDOM-2 (192.168.2.10). What is the most likely cause?

A.A firewall policy allowing traffic from VDOM-1 to VDOM-2 is missing.
B.The inter-VDOM link interfaces must be configured with the same VDOM ID.
C.The inter-VDOM link interfaces do not have 'set allowaccess ping' enabled.
D.The inter-VDOM link interfaces are not assigned to a zone.
AnswerA

Even with correct routes and inter-VDOM link IPs, traffic between VDOMs is blocked by default. A firewall policy must explicitly permit traffic from the source interface (or zone) in VDOM-1 to the destination interface in VDOM-2. Without such a policy, the FortiGate drops the packets, causing the ping to fail.

Why this answer

Inter-VDOM link routing requires three elements: correct IP addressing on the link interfaces, static or dynamic routes in each VDOM pointing to the other VDOM's networks, and a firewall policy permitting traffic between the VDOMs. The scenario indicates that routes are already configured, so the missing piece is the firewall policy. Without it, the FortiGate's default deny action blocks the transit traffic.

Exam trap

The trap here is assuming that inter-VDOM links automatically allow traffic once routes are in place; in reality, firewall policies are still required to permit inter-VDOM traffic.

315
MCQhard

A company uses SSL VPN with FortiGate for remote access. Users report that after connecting, they can access internal web servers but cannot ping them. Which configuration is most likely missing?

A.Split tunneling settings
B.SSL VPN web portal settings
C.Firewall policy allowing ICMP
D.DNS server configuration
AnswerC

SSL VPN tunnel mode permits traffic only through firewall policies referencing the SSL VPN tunnel interface. Web access works because an existing policy allows HTTP/HTTPS, but ICMP echo has no matching policy, so pings are dropped. Adding an ICMP-accepting policy on that interface restores reachability.

Why this answer

SSL VPN tunnels typically allow TCP-based traffic like HTTP/HTTPS to internal web servers, but ICMP (ping) is a separate protocol that requires explicit permission in the firewall policy. Without a firewall policy rule permitting ICMP from the SSL VPN interface to the internal network, the FortiGate will drop the ping requests, even though the tunnel is established and other traffic flows.

Exam trap

The trap here is that candidates assume split tunneling or DNS is the cause, but the real issue is that ICMP is a separate protocol that must be explicitly permitted in the firewall policy, unlike TCP-based web traffic.

How to eliminate wrong answers

Option A is wrong because split tunneling controls whether traffic to the internet goes through the VPN tunnel or directly, not the ability to ping internal servers; it does not affect ICMP traffic to internal resources. Option B is wrong because the SSL VPN web portal settings define the web-based interface and bookmarks for users, not the underlying firewall rules that govern ICMP or other protocols. Option D is wrong because DNS server configuration resolves hostnames to IP addresses, but the issue is that ping fails even when using the IP address, indicating a lack of ICMP permission rather than name resolution.

316
MCQeasy

What is the primary difference between using a Web Application Firewall (WAF) on FortiGate versus using FortiWeb?

A.There is no difference; they are the same.
B.FortiGate WAF is cloud-based, while FortiWeb is on-premises.
C.FortiWeb provides dedicated, advanced WAF features and higher performance for web traffic, while FortiGate WAF is a basic protection feature.
D.FortiGate WAF can protect multiple web servers simultaneously, while FortiWeb protects only one.
AnswerC

FortiWeb is a purpose-built appliance offering full WAF capabilities, including advanced ML-based detection and higher throughput for web workloads. FortiGate's WAF is a lightweight UTM feature with limited inspection depth. This architectural split satisfies the stem's request for the primary difference between the two platforms.

Why this answer

FortiWeb is a dedicated web application firewall appliance that provides advanced, specialized WAF features such as machine learning-based bot detection, API discovery, and granular signature tuning, along with higher throughput for web traffic. In contrast, the WAF feature on FortiGate is a basic, integrated protection module that offers essential HTTP/HTTPS inspection and signature-based filtering, but lacks the depth and performance optimization of FortiWeb.

Exam trap

The trap here is that candidates assume all WAF implementations are functionally identical, overlooking the architectural and performance differences between an integrated feature and a dedicated appliance.

How to eliminate wrong answers

Option A is wrong because FortiGate WAF and FortiWeb are fundamentally different products; FortiGate integrates a basic WAF as a feature within its NGFW, while FortiWeb is a dedicated appliance with advanced web security capabilities. Option B is wrong because FortiGate WAF is not cloud-based; it runs on-premises as part of the FortiGate hardware or VM, and FortiWeb can be deployed both on-premises and as a cloud service (e.g., FortiWeb Cloud). Option D is wrong because both FortiGate WAF and FortiWeb can protect multiple web servers simultaneously; FortiWeb supports multi-server load balancing and virtual server configurations, while FortiGate WAF can apply policies to multiple web servers behind the firewall.

317
MCQeasy

An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The configuration uses certificates for authentication. The admin sees the following log message: 'Certificate validation failed: unable to get local issuer certificate.' What is the most likely cause?

A.The peer's certificate has expired
B.The CA certificate that signed the peer's certificate is not imported on the FortiGate
C.The certificate revocation list (CRL) is not configured
D.The local certificate does not match the peer's expected CN
AnswerB

The error means the FortiGate cannot build a chain to a trusted root for the peer's certificate. Importing the issuing CA certificate into the local store lets the FortiGate validate the peer's certificate chain, resolving the 'unable to get local issuer certificate' failure.

Why this answer

The error 'unable to get local issuer certificate' indicates that the FortiGate cannot find the CA certificate that signed the peer's certificate in its local store. Without the CA certificate, the FortiGate cannot validate the peer's certificate chain. Importing the correct CA certificate resolves the issue.

Exam trap

The trap is confusing this error with an expired certificate or CRL issue. The specific phrase 'unable to get local issuer certificate' points directly to a missing CA certificate.

How to eliminate wrong answers

Option A is wrong because an expired certificate would produce a different error, such as 'certificate has expired'. Option C is wrong because a missing CRL would cause a revocation check failure, not an issuer lookup failure. Option D is wrong because a CN mismatch would result in a name mismatch error, not an issuer certificate error.

318
MCQmedium

An organization uses FortiManager to manage multiple FortiGates. A junior admin accidentally deleted a critical firewall policy on one device and the change was auto-installed. How can the senior admin revert the device to the previous configuration?

A.Delete the ADOM and recreate it
B.Go to Device Manager -> Revision History and restore the previous revision
C.Use the 'restore' command on FortiManager
D.Manually recreate the policy on the FortiGate
AnswerB

Device Manager's Revision History stores per-device configuration revisions, so restoring the prior revision pushes the pre-deletion policy back to that FortiGate. This satisfies the scenario's requirement to revert a single device after an auto-installed change, without affecting other managed FortiGates or relying on full-system backups.

Why this answer

FortiManager automatically stores configuration revisions for managed FortiGates. By navigating to Device Manager -> Revision History, the admin can select the previous revision and restore it, which reverts the device to its state before the accidental deletion. This process ensures the change is undone without manual intervention or affecting other devices.

Exam trap

The trap here is that candidates may think the only way to revert a change is to manually recreate the policy (Option D) or use a generic command (Option C), overlooking FortiManager's built-in revision history feature which is specifically designed for this purpose.

How to eliminate wrong answers

Option A is wrong because deleting the ADOM would remove all configurations for all devices in that ADOM, not just revert a single policy change, and would require recreating the entire ADOM from scratch, which is excessive and disruptive. Option C is wrong because there is no generic 'restore' command on FortiManager; the correct method is through the GUI or CLI using the 'execute restore' command with a specific revision, but the question implies a GUI-based approach, and the 'restore' command alone is ambiguous. Option D is wrong because manually recreating the policy on the FortiGate is error-prone, does not leverage FortiManager's revision history, and may not match the exact previous configuration, especially if other changes occurred.

319
MCQmedium

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. After configuration, traffic from VDOM-A cannot reach VDOM-B. Which configuration step is MOST likely missing?

A.Create a firewall policy on VDOM-A and VDOM-B allowing traffic over the VDOM link interface
B.Enable 'inter-vdom-routing' under system settings
C.Configure a static route on VDOM-A pointing to VDOM-B's subnet via the VDOM link
D.Assign both VDOM link interfaces to the same VDOM
AnswerA

A VDOM link provides the physical path, but FortiGate evaluates inter-VDOM traffic through firewall policies. Without policies on both VDOM-A and VDOM-B permitting traffic across the link interface, packets are dropped, which explains why connectivity fails despite the link existing.

Why this answer

VDOM links are special inter-VDOM interfaces that require firewall policies on both VDOMs to permit traffic. Without a policy on VDOM-A and VDOM-B that allows traffic over the VDOM link interface, packets will be dropped by the implicit deny rule. This is the most common missing step when inter-VDOM routing fails.

Exam trap

The trap here is that candidates often assume static routes or a global inter-VDOM routing toggle are required, overlooking that VDOM links function like physical interfaces and need firewall policies to permit traffic.

How to eliminate wrong answers

Option B is wrong because 'inter-vdom-routing' is not a configurable setting under system settings; inter-VDOM routing is inherently enabled when VDOMs are enabled and a VDOM link is created. Option C is wrong because static routes are not strictly required if the VDOM link is used as a transit link and the destination subnet is directly connected; the missing firewall policy is the primary issue. Option D is wrong because assigning both VDOM link interfaces to the same VDOM would defeat the purpose of inter-VDOM routing, as the link is designed to connect two different VDOMs.

320
MCQmedium

A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?

A.Intrusion Prevention System (IPS) with botnet signatures
B.Application Control with botnet category
C.DNS Filter with botnet domain database
D.FortiGuard Category Based Filter
AnswerA

The IPS engine on FortiGate includes a comprehensive signature database that detects known botnet command-and-control patterns. When enabled, IPS inspects traffic flows and matches them against signatures specifically designed to identify C2 communication, such as those used by Mirai or Necurs. This provides the required signature-based detection and can block or log the traffic, directly addressing the administrator's goal.

Why this answer

The Intrusion Prevention System (IPS) on FortiGate uses a signature database that includes patterns for known botnet command-and-control traffic. Enabling IPS with botnet signatures allows the firewall to inspect packets and block or log C2 communications. Other features like web filtering, application control, or DNS filtering do not provide the same level of signature-based detection for C2 traffic.

Exam trap

The trap here is assuming that application control or DNS filtering can substitute for IPS when detecting botnet command-and-control traffic, but only IPS provides the deep packet inspection with botnet-specific signatures.

321
MCQmedium

A FortiGate 600E is configured with multiple VDOMs in NAT mode. The administrator wants to route traffic between VDOM-1 and VDOM-2 without using physical interfaces. They create a VDOM link named 'vlink' with interfaces vlink0 and vlink1, assign vlink0 to VDOM-1 (IP 10.0.1.1/30) and vlink1 to VDOM-2 (IP 10.0.1.2/30). However, traffic from a host in VDOM-1 (192.168.1.0/24) to a server in VDOM-2 (192.168.2.0/24) fails. The administrator has added static routes in both VDOMs pointing to the respective VDOM link IPs. What is the most likely cause of the failure?

A.The VDOM link interfaces must be in the same VDOM.
B.The VDOM link interfaces require a firewall policy to allow traffic between VDOMs.
C.The IP addresses on the VDOM link interfaces must be in different subnets.
D.The static routes must be configured with the VDOM link interface as the outgoing interface, not the next-hop IP.
AnswerB

Even with VDOM links and static routes, inter-VDOM traffic is subject to firewall policies. By default, no policy exists to permit traffic from VDOM-1 to VDOM-2 across the VDOM link. The administrator must create a firewall policy in each VDOM (or at least in the initiating VDOM) to allow the traffic, otherwise it will be dropped.

Why this answer

Inter-VDOM routing via VDOM links requires both routing and firewall policies. The VDOM link provides the Layer 3 path, and static routes direct traffic, but without a firewall policy allowing traffic from the source to destination VDOM, the FortiGate drops the packets. The administrator must add a policy in VDOM-1 (and possibly VDOM-2 for return traffic) to permit the flow.

Exam trap

The trap here is assuming that VDOM links automatically permit traffic once routes are in place, ignoring the need for explicit firewall policies.

322
MCQmedium

An organization wants to prevent zero-day attacks by using Content Disarm and Reconstruction (CDR) on email attachments. Which Fortinet product provides this capability?

A.FortiWeb
B.FortiGate
C.FortiMail
D.FortiSandbox
AnswerC

FortiMail performs Content Disarm and Reconstruction on email attachments, stripping active content and rebuilding files into safe, inert versions before delivery. This directly satisfies the stem's requirement to block zero-day attacks, since CDR neutralises unknown exploits rather than relying on signature detection, which cannot identify previously unseen malware.

Why this answer

FortiMail is the correct answer because it natively integrates Content Disarm and Reconstruction (CDR) to sanitize email attachments by removing active content (e.g., macros, scripts, embedded objects) and rebuilding the file in a safe format. This prevents zero-day exploits that bypass signature-based detection, as CDR does not rely on threat intelligence but instead strips potentially malicious elements before delivery.

Exam trap

The trap here is that candidates often confuse FortiSandbox's dynamic analysis with CDR, assuming both provide proactive protection against zero-days, but FortiSandbox requires execution and detection, whereas CDR prevents exploitation by removing the attack surface entirely without relying on signatures or behavioral analysis.

How to eliminate wrong answers

Option A is wrong because FortiWeb is a web application firewall (WAF) that protects web servers from HTTP/HTTPS attacks (e.g., SQL injection, XSS) and does not process email attachments or provide CDR functionality. Option B is wrong because FortiGate is a next-generation firewall (NGFW) that can perform antivirus and sandboxing for traffic passing through it, but it does not include native CDR for email attachments; CDR is a feature specific to FortiMail's email security pipeline. Option D is wrong because FortiSandbox is a separate advanced threat detection appliance that uses dynamic analysis (e.g., detonating files in a sandbox) to identify unknown malware, but it does not perform CDR; CDR proactively disarms attachments without execution, whereas FortiSandbox relies on behavioral analysis after execution.

323
MCQmedium

An administrator has configured a FortiGate HA cluster with two units. The cluster uses a virtual cluster for load balancing in active-active mode. The administrator notices that traffic from one VDOM is not being load-balanced and is only handled by one unit. What is the most likely cause?

A.Session pickup is disabled
B.The HA priority is set to 0 on the secondary unit
C.The VDOM is not assigned to any virtual cluster
D.The management interface is not configured on the VDOM
AnswerC

Virtual clustering distributes traffic across units only for VDOMs explicitly assigned to a virtual cluster. A VDOM left outside every virtual cluster has no load-balancing scope, so all its traffic is processed by the primary unit alone.

Why this answer

In an active-active HA cluster with virtual clusters, each VDOM must be explicitly assigned to a virtual cluster to participate in load balancing. If a VDOM is not assigned to any virtual cluster, it defaults to being handled only by the primary unit, regardless of the cluster mode. This explains why traffic from that VDOM is not load-balanced.

Exam trap

The trap here is that candidates often assume active-active mode automatically load-balances all traffic across both units, overlooking the requirement that each VDOM must be explicitly assigned to a virtual cluster to enable load balancing for that VDOM.

How to eliminate wrong answers

Option A is wrong because session pickup is a feature for synchronizing existing sessions after failover, not a prerequisite for load balancing traffic across units in active-active mode. Option B is wrong because setting HA priority to 0 on the secondary unit would make it a standby unit, but the question states the cluster is in active-active mode, where both units should actively forward traffic; priority 0 would prevent load balancing entirely, not just for one VDOM. Option D is wrong because the management interface configuration is unrelated to VDOM traffic forwarding or load balancing; it only affects administrative access to the VDOM.

324
MCQhard

An administrator has deployed a ZTNA configuration on a FortiGate where remote users authenticate through FortiClient EMS. The administrator wants to ensure that only devices with an up-to-date operating system and active antivirus are granted access to an internal web application. The FortiGate is configured as the ZTNA access proxy. Which FortiGate component or configuration is required to enforce these device compliance checks?

A.Configure an IPsec VPN tunnel between FortiClient and FortiGate and apply a firewall policy with antivirus scanning.
B.Create a firewall policy that uses a schedule to allow access only during business hours, assuming devices are patched.
C.Configure a ZTNA server with a tag that references the FortiClient EMS compliance tags and apply it in the ZTNA policy.
D.Enable client certificate authentication on the ZTNA server and require a specific certificate issued by the EMS.
AnswerC

FortiGate ZTNA can use dynamic tags received from FortiClient EMS to enforce endpoint compliance. The ZTNA policy can match on these tags, ensuring only compliant devices access the protected resource. This is the correct method for integrating EMS compliance checks into ZTNA access decisions.

Why this answer

ZTNA on FortiGate integrates with FortiClient EMS to receive compliance tags. Using these tags in a ZTNA policy allows enforcement of device posture before granting access. This dynamic tagging ensures that only devices meeting the defined compliance criteria can reach the protected application, aligning with zero-trust principles.

Exam trap

The trap here is confusing authentication with authorization based on device posture, assuming that any form of certificate or VPN automatically enforces compliance.

325
MCQeasy

An administrator is configuring a FortiGate with VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that routes in one VDOM do not affect another. Which statement about VDOM routing is correct?

A.All VDOMs share a single global routing table, but route entries are tagged with VDOM IDs.
B.Each VDOM maintains its own separate routing table, and routes are isolated per VDOM.
C.Only the root VDOM can have a default route; other VDOMs must use inter-VDOM links for all traffic.
D.Routes are automatically synchronized between VDOMs to ensure consistent routing.
AnswerB

In a multi-VDOM FortiGate, each VDOM operates as an independent virtual device with its own routing table. Routes configured in one VDOM are not visible to or used by other VDOMs. This isolation is fundamental to VDOM functionality and ensures that routing changes in one VDOM do not impact others.

Why this answer

VDOMs on a FortiGate are independent virtual instances, each with its own routing table. This means that routes configured in one VDOM are not shared with or visible to other VDOMs. This isolation is a key benefit of VDOMs, allowing separate routing domains for different departments or customers without interference.

Exam trap

The trap here is assuming that VDOMs share routing information or that routes are global; they are isolated per VDOM.

326
MCQeasy

Which FortiManager feature allows an administrator to roll back a policy package to a previous version?

A.Install preview
B.Revision history
C.Device manager
D.Automation stitch
AnswerB

Revision history stores timestamped snapshots of each policy package, letting administrators revert to any prior version directly from FortiManager. This satisfies the rollback requirement precisely, since the feature preserves complete package states rather than individual object changes, enabling full restoration after an unintended or faulty policy installation.

Why this answer

FortiManager's Revision History feature automatically creates a versioned snapshot of policy packages each time they are installed or modified. Administrators can browse prior revisions and revert to any previous version, restoring the exact policy state. This is the built-in rollback mechanism for policy packages.

Exam trap

NSE7 often tests the distinction between previewing changes (Install Preview) and actually reverting changes (Revision History) — candidates confuse the two because both relate to policy package management.

How to eliminate wrong answers

Option A is wrong because Install Preview only shows what changes will be pushed to a device before installation — it does not store or restore prior versions. Option C is wrong because Device Manager is used to add, organize, and manage FortiGate devices in FortiManager, not to version policy packages. Option D is wrong because Automation Stitches are event-driven workflows that trigger actions based on log events, not a versioning or rollback tool.

327
MCQmedium

A company with a hub-and-spoke SD-WAN topology uses FortiGates at each site. The hub has two WAN links: MPLS (10 Mbps) and broadband (100 Mbps). The spokes connect only via MPLS. The company deploys a new real-time application that requires low latency and low jitter. The network administrator creates an SD-WAN rule for this application with 'best quality' strategy and both MPLS and broadband as members. The SLA for MPLS is configured with latency < 10 ms and jitter < 5 ms. The SLA for broadband is configured with latency < 50 ms and jitter < 20 ms. The actual measured latency on MPLS is 12 ms, and jitter is 4 ms. The broadband latency is 25 ms, jitter 10 ms. Which path will the application traffic take?

A.The traffic will use the broadband link because MPLS SLA fails and broadband SLA is met.
B.The traffic will be load-balanced between MPLS and broadband.
C.The traffic will use the MPLS link because it is the preferred member.
D.The traffic will be dropped because no link meets the SLA.
AnswerA

Broadband satisfies its configured SLA thresholds (25 ms latency, 10 ms jitter, both within 50 ms and 20 ms), while MPLS breaches its latency SLA at 12 ms against the 10 ms limit. FortiGate's best quality strategy selects the member meeting its SLA, so traffic fails over to broadband despite MPLS's lower measured latency.

Why this answer

The SD-WAN rule uses the 'best quality' strategy, which selects the member with the best SLA performance. The MPLS link fails its SLA because its measured latency of 12 ms exceeds the configured threshold of 10 ms, even though jitter is within limits. The broadband link meets both its latency (25 ms < 50 ms) and jitter (10 ms < 20 ms) thresholds, so it becomes the active path for the application traffic.

Exam trap

The trap here is that candidates assume MPLS is always preferred due to its lower latency profile, but the 'best quality' strategy strictly enforces SLA thresholds, and a link that fails its SLA is excluded from selection regardless of its absolute performance.

How to eliminate wrong answers

Option B is wrong because 'best quality' strategy does not perform load-balancing; it selects a single best path based on SLA compliance and performance metrics. Option C is wrong because MPLS is not inherently preferred; the rule treats both members equally, and MPLS is disqualified due to SLA failure. Option D is wrong because the broadband link meets its SLA thresholds, so traffic is not dropped.

328
MCQeasy

An administrator wants to enforce that only devices with antivirus software installed and running can access a sensitive application via ZTNA. Which ZTNA feature should be used to verify this requirement?

A.ZTNA inline CASB
B.NAC with FortiNAC
C.ZTNA tags with device posture checks
D.IPsec VPN with DPD
AnswerC

ZTNA tags with device posture checks have FortiClient EMS inspect the endpoint and assign a tag only when antivirus is installed and running. The access proxy rule then matches that tag, satisfying the requirement that only protected devices reach the application.

Why this answer

ZTNA tags with device posture checks allow the FortiGate to evaluate the security posture of the endpoint, including whether antivirus software is installed and running. These tags are then used in firewall policies to grant or deny access to sensitive applications based on compliance. This directly enforces the requirement.

Exam trap

NSE7 often tests the confusion between ZTNA tags and other access control methods like NAC, leading candidates to choose NAC when the requirement is specifically for application access based on device posture.

How to eliminate wrong answers

Option A is wrong because ZTNA inline CASB is for cloud access security broker functions, not device posture checks. Option B is wrong because NAC with FortiNAC is for network access control, typically for on-premises devices, and does not integrate directly with ZTNA for application access. Option D is wrong because IPsec VPN with DPD is for VPN connectivity and dead peer detection, not for endpoint posture assessment.

329
MCQhard

A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?

A.Change the IPS action from block to monitor
B.Add the VoIP servers to an IP exemption list in the IPS sensor
C.Disable protocol anomaly detection entirely
D.Tune the protocol anomaly thresholds to be more lenient for SIP
AnswerD

Protocol anomaly detection flags SIP deviations from strict RFC behaviour, and legitimate VoIP implementations often violate these expectations. Raising the anomaly thresholds for SIP reduces sensitivity to benign variation, cutting false positives while retaining signature-based IPS coverage for actual attacks.

Why this answer

Protocol anomaly detection in IPS sensors uses predefined thresholds to identify abnormal traffic patterns. When legitimate SIP traffic is being blocked, tuning the protocol anomaly thresholds to be more lenient for SIP allows the sensor to accommodate normal variations in SIP behavior without triggering false positives, while still maintaining protection against actual anomalies.

Exam trap

The trap here is that candidates may think disabling or bypassing detection (options A, B, or C) is the simplest fix, but the exam tests the understanding that protocol anomaly detection should be tuned rather than disabled to preserve security while reducing false positives.

How to eliminate wrong answers

Option A is wrong because changing the IPS action from block to monitor would stop blocking but also disable protection, which is not a targeted fix for false positives and leaves the network vulnerable to real threats. Option B is wrong because adding VoIP servers to an IP exemption list would bypass all IPS inspection for those IPs, which is overly broad and could allow actual attacks to go undetected. Option C is wrong because disabling protocol anomaly detection entirely removes a valuable security layer and is an extreme measure that does not address the root cause of false positives.

330
Multi-Selectmedium

A company uses FortiManager to manage multiple FortiGates. The admin wants to use a global ADOM to manage certain policies across all devices while allowing local customization. Which two statements about global ADOM are true? (Choose two.)

Select 2 answers
A.Header/footer policies can only be configured in the global ADOM
B.Global ADOM supports per-device policy objects
C.Regular ADOMs can import policy packages from the global ADOM
D.Global ADOM requires a separate FortiManager license
E.Global ADOM policies are installed on all managed FortiGates in all ADOMs
AnswersA, C

Header and footer policies are typically defined in the global ADOM to enforce consistent security baselines.

Why this answer

Header and footer policies are global constructs that can only be created and managed within the global ADOM. These policies are automatically applied to all policy packages across all regular ADOMs, ensuring consistent enforcement at the top and bottom of the policy list without local modification.

Exam trap

The trap here is that candidates often assume global ADOM policies are automatically installed on all devices, but in reality they only apply to policy packages that are explicitly imported from the global ADOM into a regular ADOM.

331
Multi-Selectmedium

A security analyst wants to use automation stitches on FortiGate to automatically block an IP address when a critical severity event is logged. Which TWO components are essential to create this automation stitch? (Choose two.)

Select 2 answers
A.A FortiGuard subscription
B.A FortiAnalyzer to store logs
C.An action that adds the source IP to a firewall address group
D.A static route to the internet
E.A trigger that matches critical severity logs
AnswersC, E

The action defines the response, such as blocking the IP.

Why this answer

An automation stitch in FortiGate requires an action to execute a specific task, such as adding a source IP to a firewall address group, which effectively blocks the IP. This action is essential for enforcing the security response triggered by the stitch.

Exam trap

The trap here is that candidates often confuse optional components (like FortiGuard or FortiAnalyzer) with essential ones, mistakenly thinking external services or connectivity are required for the stitch's core trigger and action logic.

332
MCQeasy

A FortiGate administrator wants to check if the device is experiencing high CPU usage due to a specific process. Which command should they use to display real-time process CPU usage?

A.show system resource
B.diagnose sys top
C.get system performance status
D.diagnose debug application crashlog read
AnswerB

The diagnose sys top command displays a live, refreshing list of running processes ranked by CPU and memory consumption, letting the administrator identify the specific process driving high CPU. It also supports interval and sort options for real-time monitoring.

Why this answer

The 'diagnose sys top' command provides a real-time, top-like view of FortiGate processes, showing CPU and memory usage per process. This allows the administrator to identify which specific process is consuming high CPU, making it the correct choice for this diagnostic task.

Exam trap

The trap here is that candidates often confuse 'show system resource' (overall stats) with per-process diagnostics, or they mistakenly think 'get system performance status' provides process-level detail, when it only shows aggregate performance metrics.

How to eliminate wrong answers

Option A is wrong because 'show system resource' displays overall system resource usage (CPU, memory, disk) but does not break down usage by individual process. Option C is wrong because 'get system performance status' shows aggregate performance statistics (e.g., sessions, CPU load average) without per-process detail. Option D is wrong because 'diagnose debug application crashlog read' is used to read crash logs for debugging crashes, not for monitoring real-time process CPU usage.

333
MCQmedium

An administrator needs to deploy a honeypot solution to detect and deceive attackers inside the network. Which Fortinet product is BEST suited for this purpose?

A.FortiDeceptor
B.FortiSandbox
C.FortiEDR
D.FortiNAC
AnswerA

FortiDeceptor deploys decoys, lures and honeypots that mimic real assets, detecting and deceiving attackers who interact with them while generating high-fidelity alerts. This directly satisfies the stem's requirement for an in-network honeypot, unlike FortiGate, FortiAnalyzer or FortiSIEM, which provide enforcement, logging or correlation rather than deception.

Why this answer

FortiDeceptor is a dedicated deception-based security solution that deploys decoys (honeypots) and lures across the network to detect and misdirect attackers. It integrates with FortiGate and FortiSIEM to provide automated threat isolation and forensic data collection, making it the best choice for a honeypot deployment.

Exam trap

The trap here is that candidates may confuse FortiSandbox's file analysis with deception technology, but FortiSandbox does not deploy decoys or lures within the network for attacker interaction.

How to eliminate wrong answers

Option B (FortiSandbox) is wrong because it focuses on analyzing suspicious files and URLs in a sandboxed environment, not on deploying honeypots or decoys for attacker deception. Option C (FortiEDR) is wrong because it provides endpoint detection and response capabilities, including behavioral analysis and threat hunting, but does not include honeypot or deception technology. Option D (FortiNAC) is wrong because it is a network access control solution that manages device authentication and compliance, not a deception-based detection tool.

334
MCQeasy

In FortiGate's ZTNA, what is the purpose of a 'ZTNA tag'?

A.To identify a device's compliance status and attributes for policy enforcement.
B.To mark packets for quality of service (QoS) prioritization.
C.To label network interfaces for traffic steering.
D.To assign a security level to application traffic.
AnswerA

A ZTNA tag is a dynamic attribute, typically populated by FortiClient EMS, describing device compliance and posture. FortiGate ZTNA rules match these tags to decide whether a device is permitted, enforcing zero-trust access based on verified device state rather than network location.

Why this answer

ZTNA tags are dynamic attributes (e.g., OS type, antivirus status) assigned to devices based on posture checks. They are used in firewall policies to grant access based on device compliance, not for routing or QoS.

335
Multi-Selectmedium

A network administrator is troubleshooting a scenario where remote users can connect via FortiClient VPN but cannot access internal resources. The FortiGate has a valid IPsec VPN configuration. Which THREE checks should the administrator perform to resolve the issue?

Select 3 answers
A.Check if there is a route on the internal network pointing back to the VPN subnet
B.Ensure that NAT is disabled on the VPN policy
C.Increase the MTU on the VPN interface
D.Disable DPD on the VPN phase 1
E.Verify that the firewall policy allows traffic from the VPN IP pool to the internal network
AnswersA, B, E

The internal hosts must know how to reach the VPN client subnet. Without a return route pointing back to the VPN IP pool, replies are dropped or sent to the default gateway, so traffic never returns to the tunnel.

Why this answer

Option A is correct because remote-access IPsec VPN clients use a virtual IP pool subnet, and internal hosts or routers must have a return route for that VPN subnet; without it, return traffic is dropped and users cannot reach internal resources even though the tunnel is up. Option B is correct because NAT must be disabled on the VPN policy; if NAT is enabled, the FortiGate translates the source address of VPN traffic, which breaks routing and access to internal resources that expect the original VPN pool address. Option E is correct because the FortiGate requires an explicit firewall policy permitting traffic from the VPN IP pool (source) to the internal network (destination), and without this policy the tunnel establishes but no traffic is allowed through.

Option C is not appropriate because increasing MTU on the VPN interface is not a standard fix for access failures and can worsen fragmentation issues; MTU problems typically require lowering or adjusting MSS, not raising MTU. Option D is not appropriate because disabling Dead Peer Detection (DPD) on phase 1 does not resolve internal resource access problems and can prevent the FortiGate from detecting dead VPN peers.

Exam trap

The trap here is that candidates often focus on tunnel-level settings like MTU or DPD when the real issue is a missing return route or firewall policy, which are common misconfigurations in IPsec VPN deployments.

336
MCQmedium

A network security administrator is deploying a FortiSandbox appliance in a FortiGate environment. The administrator wants to ensure that when a zero-day malware sample is detonated, the FortiGate immediately blocks the file hash and the C2 callback. Which FortiSandbox integration method should the administrator configure on the FortiGate to achieve this?

A.Configure an external threat feed on the FortiGate using the FortiSandbox API to pull malicious IPs every 5 minutes.
B.Configure a syslog server on the FortiSandbox to send logs to the FortiGate, and create a firewall policy that denies traffic from the sandbox subnet.
C.Configure the FortiGate to send files to FortiSandbox via the 'fortisandbox' fabric connector and enable 'block malicious files' in the antivirus profile.
D.Enable 'Use FortiSandbox for unknown files' in the antivirus profile and set the action to 'monitor' for all protocols.
AnswerC

The FortiSandbox fabric connector allows the FortiGate to submit files and receive verdicts. Enabling 'block malicious files' in the antivirus profile ensures that once a verdict is returned, the FortiGate blocks the file hash and subsequent C2 traffic based on the sandbox's dynamic blocklist. This is the standard integration for automated threat blocking.

Why this answer

The FortiSandbox fabric connector on FortiGate enables seamless submission of files and retrieval of verdicts. When a file is deemed malicious, the FortiGate can block the file hash and C2 traffic via the antivirus profile's block action. This integrated approach automates threat protection without manual intervention, ensuring immediate response to zero-day threats.

Exam trap

The trap here is assuming that any connection to FortiSandbox automatically blocks threats, when in fact the antivirus profile must be configured to block malicious files and the fabric connector must be properly established.

337
MCQmedium

You want to use policy-based routing (PBR) to send traffic from a specific subnet to a different next-hop than the default route. Which configuration is required?

A.Configure a route map under 'config router policy'
B.Create a firewall policy with 'set policy-based-route enable'
C.Enable 'set pbr-enforce-symmetric' on the interface
D.Configure a prefix list and apply to the static route
AnswerA

PBR uses route maps with set-next-hop in the policy route configuration.

Why this answer

Policy-based routing (PBR) on FortiGate is configured under 'config router policy' using route maps. This allows you to match traffic based on criteria such as source subnet and set a specific next-hop, overriding the default route. Option A correctly identifies the required configuration path for PBR.

Exam trap

The trap here is that candidates confuse PBR configuration with firewall policy settings or static route modifications, but FortiGate requires the explicit 'config router policy' and route map syntax to define policy-based routing rules.

How to eliminate wrong answers

Option B is wrong because 'set policy-based-route enable' is not a valid command; firewall policies use 'set action accept' and policy-based routing is applied via route maps, not a firewall policy toggle. Option C is wrong because 'set pbr-enforce-symmetric' is used to enforce symmetric routing for PBR traffic on an interface, but it is not the configuration required to define the PBR rule itself. Option D is wrong because a prefix list applied to a static route can influence route selection but does not implement PBR, which requires a route map under 'config router policy' to match and set next-hop.

338
MCQmedium

A FortiGate administrator wants to use FortiManager to manage multiple FortiGates in different geographic regions. To isolate configuration changes, the administrator creates separate ADOMs for each region. Which type of ADOM should be used to allow some common objects (like address groups) to be shared across all regions?

A.Per-Device ADOM
B.Global ADOM
C.Regular ADOM
D.Meta ADOM
AnswerB

A Global ADOM sits above all other ADOMs and lets you create shared policy objects, such as address groups, that every regional ADOM can reference. This satisfies the requirement to isolate per-region configuration changes while still sharing common objects across all regions.

Why this answer

The Global ADOM is designed to store and share common objects, such as address groups, policies, and schedules, across all ADOMs in a FortiManager deployment. When an administrator creates separate ADOMs for each region, the Global ADOM acts as a central repository for objects that need to be consistent everywhere, allowing per-region ADOMs to reference these shared objects without duplicating them. This ensures configuration isolation for region-specific settings while maintaining a single source of truth for global resources.

Exam trap

The trap here is that candidates often confuse 'Global ADOM' with 'Regular ADOM' or assume that a 'Per-Device ADOM' can be configured to share objects, when in fact only the Global ADOM provides a centralized, cross-ADOM object repository in FortiManager.

How to eliminate wrong answers

Option A is wrong because a Per-Device ADOM is used when each managed FortiGate requires its own independent ADOM with no sharing of objects, which defeats the purpose of sharing common objects across regions. Option C is wrong because a Regular ADOM (also called a per-ADOM ADOM) is the default type that isolates all objects within that ADOM and does not inherently support sharing objects with other ADOMs; it would require manual duplication or import/export to share objects. Option D is wrong because Meta ADOM is not a valid ADOM type in FortiManager; the correct term is 'Global ADOM' for cross-ADOM object sharing, and 'Meta ADOM' is a distractor that does not exist in the FortiManager architecture.

339
MCQhard

A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?

A.Enable 'Treat Windows executable files as viruses' in the antivirus profile to block all executable downloads.
B.Configure FortiSandbox to send a verdict to FortiGate and set the action to 'Block' in the sandbox profile.
C.Enable the 'Block malicious URLs' option in the web filter profile so the download URL is blocked.
D.Add the file hash to a custom antivirus signature list or threat feed and enable it in the antivirus profile.
AnswerD

FortiGate antivirus can block files based on custom signatures or external threat feeds that include file hashes. Adding the hash to a custom list and referencing it in the antivirus profile ensures the file is detected and blocked on subsequent downloads, even if the URL changes. This directly addresses the known malicious hash and is the correct operational response.

Why this answer

When a specific malicious file hash is known, the most direct and reliable way to block it on FortiGate is to add that hash to a custom antivirus signature or external threat feed and enable it in the antivirus profile. This ensures detection regardless of the delivery URL or protocol, and it integrates with existing antivirus scanning. It also avoids overblocking legitimate executables and does not depend solely on sandbox verdict propagation.

Exam trap

The trap here is assuming that a FortiSandbox verdict automatically creates a hash-based block on FortiGate, when the administrator may need to explicitly add the hash to a custom list or threat feed.

340
MCQmedium

In a hub-and-spoke VPN, spokes cannot communicate with each other directly. The administrator wants to allow direct spoke-to-spoke traffic without routing through the hub. Which technology should be configured?

A.Static routes on spokes
B.IKEv1 with mode-config
C.GRE over IPsec
D.ADVPN with IKEv2
AnswerD

ADVPN with IKEv2 lets spokes establish on-demand shortcuts directly between themselves, bypassing the hub for spoke-to-spoke traffic. The hub still handles initial route exchange, but once traffic flows, spokes negotiate a direct tunnel, satisfying the requirement to avoid hub routing while retaining centralised policy control.

Why this answer

ADVPN (Auto-Discovery VPN) with IKEv2 is Fortinet's proprietary shortcut mechanism that allows spokes to dynamically establish direct tunnels to one another without permanent spoke-to-spoke configuration. The hub acts as a registration point and uses IKEv2 to negotiate shortcut tunnels between spokes on demand, so traffic no longer has to hairpin through the hub. This is the only option that provides dynamic, on-demand direct spoke-to-spoke connectivity.

Exam trap

NSE7 often tests the distinction between technologies that merely route traffic (static routes, GRE) and those that dynamically build tunnels (ADVPN), so candidates who focus only on routing rather than tunnel establishment pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because static routes on spokes only tell a spoke where to send traffic — they cannot create a tunnel to another spoke, so traffic still has to traverse the hub. Option B is wrong because IKEv1 with mode-config only provides dynamic IP assignment to remote peers; it does not enable spoke-to-spoke shortcut tunnels. Option C is wrong because GRE over IPsec creates a tunnel interface but still requires a full mesh of static GRE/IPsec peers to be configured — it does not dynamically discover or build spoke-to-spoke tunnels.

341
MCQmedium

An administrator has a FortiGate 600E running multiple VDOMs in NAT mode. The security team wants to inspect inter-VDOM traffic between VDOM-A and VDOM-B with a firewall policy that applies UTM profiles. The administrator has already created a VDOM link named vlink1 with interfaces vlink1-A in VDOM-A and vlink1-B in VDOM-B. What must the administrator do to ensure that inter-VDOM traffic is inspected by a security policy?

A.Enable UTM inspection on the VDOM link interface in VDOM-A only, because traffic is inspected once as it leaves the source VDOM.
B.Create a firewall policy in VDOM-A from the internal interface to vlink1-A and a matching policy in VDOM-B from vlink1-B to the internal interface, and apply UTM profiles to both policies.
C.Assign the VDOM link interfaces to a zone in each VDOM, then create a single global firewall policy that applies to both VDOMs and includes UTM profiles.
D.Create a single firewall policy in VDOM-A from the internal interface to vlink1-A, and rely on the implicit inter-VDOM link policy to allow return traffic without inspection.
AnswerB

Inter-VDOM traffic traverses the VDOM link and is subject to the firewall policies of each VDOM. To inspect traffic from VDOM-A to VDOM-B, a policy in VDOM-A must allow traffic from the source interface to vlink1-A, and a policy in VDOM-B must allow traffic from vlink1-B to the destination interface. UTM profiles are applied per policy, so both policies can inspect the traffic as it passes through each VDOM.

Why this answer

Inter-VDOM traffic is routed through VDOM link interfaces and is subject to the firewall policies of each VDOM it enters. To inspect traffic from VDOM-A to VDOM-B, a policy in VDOM-A must allow traffic from the source interface to vlink1-A, and a policy in VDOM-B must allow traffic from vlink1-B to the destination interface. UTM profiles can be applied to either or both policies, depending on where inspection is desired.

This ensures that inter-VDOM traffic is not implicitly allowed and can be inspected.

Exam trap

The trap here is assuming that inter-VDOM traffic is automatically allowed or that a single policy can inspect traffic across both VDOMs, when in fact each VDOM requires its own policy to permit and inspect the traffic.

342
MCQhard

An administrator configures an automation stitch in FortiManager to execute a CLI script on a FortiGate when a specific event is triggered. The automation stitch is enabled but does not run when the event occurs. What is the most likely cause?

A.The event trigger is set to high severity only
B.The FortiGate does not support automation stitches
C.The automation stitch has not been installed to the FortiGate
D.The CLI script contains an invalid command
AnswerC

Automation stitches must be installed to the managed FortiGate before they can execute; enabling the stitch in FortiManager alone leaves it uninstalled on the device. Installation pushes the configuration and triggers to the FortiGate, so the event cannot fire until this occurs.

Why this answer

In FortiManager, automation stitches are created and stored in the central management database but must be explicitly installed to the managed FortiGate via the 'Install Wizard' or a direct policy/object install. Until the stitch is installed, the FortiGate does not have the configuration locally, so even if the stitch is enabled in FortiManager and the event occurs, the FortiGate will not execute the CLI script. This is a common oversight where administrators assume enabling the stitch in FortiManager automatically pushes it to the device.

Exam trap

The trap here is that candidates assume enabling the automation stitch in FortiManager is sufficient for it to run on the FortiGate, overlooking the critical step of installing the configuration to the managed device, which is a common point of failure in centralized management workflows.

How to eliminate wrong answers

Option A is wrong because the event trigger in FortiManager can be configured for any severity level (low, medium, high, or any), and by default, triggers are not restricted to high severity only; if the trigger were set to high severity only, the event would still run if the event matched that severity, so this would not prevent the stitch from running entirely. Option B is wrong because FortiGate devices running FortiOS 6.0 or later fully support automation stitches, and the question states the stitch is configured in FortiManager, implying the FortiGate is a supported model. Option D is wrong because an invalid command in the CLI script would cause the script to fail during execution, not prevent the automation stitch from being triggered; the stitch would still run and attempt to execute the script, but the script would produce an error.

343
MCQmedium

When troubleshooting an IPsec VPN phase 1 negotiation failure, which debug command should the administrator run to see detailed IKE negotiation messages?

A.diagnose vpn ike log
B.diagnose debug application ike -1
C.get vpn ipsec tunnel details
D.diagnose debug application ipsec -1
AnswerB

`diagnose debug application ike -1` enables verbose IKE daemon logging, exposing phase 1 proposal exchanges, transform mismatches and vendor ID payloads. The `-1` level prints every negotiation message, satisfying the stem's demand for detailed IKE troubleshooting output rather than summary status or filtered event logs.

Why this answer

The command 'diagnose debug application ike -1' enables detailed IKE (Internet Key Exchange) debug messages in FortiOS, which are essential for troubleshooting Phase 1 negotiation failures. This command captures the full IKE negotiation exchange, including proposals, authentication, and Diffie-Hellman group selection, allowing the administrator to identify where the failure occurs.

Exam trap

The trap here is that candidates often confuse the IKE debug command with the IPsec debug command, mistakenly thinking 'diagnose debug application ipsec -1' will show Phase 1 negotiation details, when in fact it only shows kernel-level IPsec processing and not the IKE control-plane messages.

How to eliminate wrong answers

Option A is wrong because 'diagnose vpn ike log' is not a valid FortiOS command; the correct command uses 'diagnose debug application ike' with a debug level. Option C is wrong because 'get vpn ipsec tunnel details' only displays the current state and configuration of established tunnels, not the real-time IKE negotiation messages needed for troubleshooting Phase 1 failures. Option D is wrong because 'diagnose debug application ipsec -1' debugs the IPsec kernel-level processing (e.g., encryption/decryption), not the IKE control-plane negotiation, so it will not show Phase 1 messages.

344
Multi-Selectmedium

A FortiGate administrator is configuring a multi-VDOM deployment. The administrator wants to use a single physical interface for multiple VDOMs. Which TWO methods allow this?

Select 2 answers
A.Use the same physical interface in multiple VDOMs directly
B.Use NP6 virtual interfaces (e.g., virtual wire) on supported models
C.Configure VLAN subinterfaces and assign each to a different VDOM
D.Create a software switch interface and assign it to multiple VDOMs
E.Configure inter-VDOM routing to share the same IP subnet
AnswersB, C

NP6 virtual interfaces, such as virtual wire pairs, let a single physical interface's acceleration hardware present multiple logical interfaces, each assignable to a different VDOM. This satisfies the requirement to share one physical port across multiple VDOMs.

Why this answer

Option C is correct because a physical interface can be partitioned into VLAN subinterfaces (e.g., port1.10, port1.20), and each subinterface can be assigned to a different VDOM, allowing one physical port to serve multiple VDOMs. Option B is correct because on NP6-accelerated FortiGate models, NP6 virtual interfaces such as virtual wire pairs (and NP6 vlinks) can be created and mapped into different VDOMs, letting a single physical NP6 interface be shared across VDOMs. Option A is incorrect because a physical interface can belong to only one VDOM at a time; it cannot be directly assigned to multiple VDOMs.

Option D is incorrect because a software switch is a single interface object that resides in one VDOM and cannot be assigned to multiple VDOMs simultaneously. Option E is incorrect because inter-VDOM routing is used to pass traffic between VDOMs and does not allow sharing the same physical interface or the same IP subnet across VDOMs.

Exam trap

The trap here is that candidates often assume a physical interface can be directly shared among VDOMs (Option A), not realizing that FortiGate requires either VLAN subinterfaces or NP6 virtual interfaces to achieve this separation.

345
MCQhard

An administrator configured FortiGate to forward suspected malicious files to FortiSandbox. They set the action to 'block' for malicious verdicts. Some files are being blocked, but others with a 'clean' verdict are allowed. However, they notice that some files that should have been sent to FortiSandbox are not being forwarded. Which reason is MOST likely?

A.The FortiGate antivirus engine is set to proxy-based mode
B.The FortiGate has insufficient disk space for temporary files
C.The file size exceeds the maximum size configured for FortiSandbox scanning
D.The FortiSandbox device is overloaded and rejecting submissions
AnswerC

FortiGate only submits files to FortiSandbox when they fall within the configured scan size limit; oversized files bypass sandbox inspection entirely. This satisfies the scenario's symptom of files not being forwarded, since verdicts for those files are never produced and blocking cannot occur.

Why this answer

The most likely reason is that the file size exceeds the maximum size configured for FortiSandbox scanning. FortiGate has a configurable limit (default 10 MB) for files sent to FortiSandbox; files larger than this threshold are not forwarded, even if the antivirus engine would otherwise trigger a submission. This explains why some files are blocked or allowed based on verdicts, while others are never submitted.

Exam trap

The trap here is that candidates often assume network or resource issues (overloaded FortiSandbox or disk space) are the cause, but the question specifically describes files that 'should have been sent' but are not, pointing to a configuration-based filter like file size limits rather than transient failures.

How to eliminate wrong answers

Option A is wrong because proxy-based mode is a valid inspection mode for FortiGate antivirus and does not prevent file forwarding to FortiSandbox; it actually supports file submission. Option B is wrong because insufficient disk space for temporary files would cause local scanning or caching issues, but FortiSandbox submissions are streamed or queued, not dependent on local temporary storage for forwarding. Option D is wrong because an overloaded FortiSandbox may delay or queue submissions, but it does not cause files to be completely not forwarded; FortiGate will still attempt submission and handle timeouts gracefully.

346
MCQhard

Based on the exhibit, what can be concluded about the session?

A.The session is a one-way session with only outbound traffic.
B.The session is not being logged.
C.The session is offloaded to the NPU for hardware acceleration.
D.The session is in the 'npu' state, meaning it is being processed by the CPU.
AnswerC

The exhibit shows traffic matching a policy with NPU offloading enabled, so the session bypasses the main CPU and is processed by the network processor for hardware acceleration. This satisfies the stem's requirement to conclude the session's actual processing path, not merely its security profile or inspection state.

Why this answer

The session state 'npu' indicates that the session has been offloaded to the Network Processor Unit (NPU) for hardware acceleration. This is a normal and expected state for traffic that matches hardware-offloadable profiles, allowing the NPU to process packets at wire speed without CPU intervention.

Exam trap

The trap here is that candidates often confuse the 'npu' state with CPU processing, assuming it means 'NPU processing by CPU' rather than recognizing it as hardware offload, leading them to select Option D incorrectly.

How to eliminate wrong answers

Option A is wrong because the session state 'npu' does not imply one-way or only outbound traffic; it simply indicates hardware offload, and sessions can be bidirectional. Option B is wrong because the session state 'npu' does not indicate whether logging is enabled or disabled; logging is configured separately via firewall policies or session log settings. Option D is wrong because the 'npu' state means the session is offloaded to the NPU for hardware acceleration, not that it is being processed by the CPU; CPU processing would be indicated by states like 'tcp' or 'udp' without offload.

347
Multi-Selectmedium

An administrator is configuring a FortiGate with multiple VDOMs in NAT/route mode. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. Which TWO statements about VDOM links are correct? (Choose two.)

Select 2 answers
A.Each VDOM link interface must be assigned an IP address to enable routing.
B.Traffic over a VDOM link is not subject to firewall policies.
C.VDOM links are automatically created when a new VDOM is added.
D.A VDOM link is a virtual point-to-point interface that connects two VDOMs.
E.A VDOM link can connect more than two VDOMs simultaneously.
AnswersA, D

To route traffic over a VDOM link, each end of the link must have an IP address assigned. This allows the VDOMs to treat the link as a routed interface and to exchange routing information or forward packets based on routing tables. Without IP addresses, the link cannot be used for Layer 3 routing.

Why this answer

VDOM links are virtual point-to-point interfaces that require manual creation and IP address assignment on each end. They connect exactly two VDOMs and traffic over them is subject to firewall policies in both VDOMs. These characteristics make them suitable for controlled inter-VDOM routing.

Exam trap

The trap here is thinking that VDOM links are automatically created or that they bypass firewall policies, when in fact they are manual, point-to-point, and subject to policy enforcement.

348
MCQmedium

A FortiGate administrator is configuring an IPsec VPN tunnel to a remote site that is behind a NAT device. The administrator notices that the tunnel establishes, but traffic intermittently fails. Which setting should be adjusted to improve reliability?

A.Enable Dead Peer Detection (DPD) with a shorter interval.
B.Configure the remote gateway as a dynamic DNS hostname.
C.Enable NAT traversal (NAT-T) and set the keepalive frequency.
D.Set the IPsec phase-1 proposal to use AES-256 encryption.
AnswerC

NAT traversal (NAT-T) encapsulates IPsec packets in UDP to allow them to pass through NAT devices. The keepalive frequency setting sends periodic keepalive packets to maintain the NAT mapping and prevent the NAT session from timing out. This is crucial for reliability when a peer is behind NAT, as it keeps the UDP port open and avoids intermittent failures due to NAT session expiration.

Why this answer

When an IPsec peer is behind NAT, the NAT device may close the UDP session if no traffic is sent for a period. Enabling NAT traversal (NAT-T) encapsulates IPsec packets in UDP, and setting a keepalive frequency ensures that periodic packets are sent to keep the NAT mapping alive. This prevents intermittent tunnel failures caused by NAT session timeouts.

Exam trap

The trap here is attributing intermittent failures to DPD or encryption settings, when the root cause is often NAT session timeout that can be mitigated with NAT-T and keepalives.

349
MCQhard

An administrator manages a FortiGate with VDOMs 'prod' and 'dev' on a single HA pair. The administrator wants 'prod' to fail over independently from 'dev' so that maintenance on the dev environment does not trigger a failover of prod. Which FortiGate feature should be configured?

A.Configure a separate VDOM link between 'prod' and 'dev' and enable HA monitoring on that link
B.Configure VDOM partitioning with resource limits so each VDOM has dedicated CPU and memory
C.Set the HA override priority differently for each VDOM so 'prod' prefers one unit and 'dev' prefers the other
D.Enable virtual clustering and assign 'prod' and 'dev' to different virtual clusters within the HA pair
AnswerD

Virtual clustering splits an HA cluster into multiple HA groups, each with its own primary and its own monitored interfaces and heartbeat behavior. Assigning prod and dev to separate virtual clusters lets each group fail over independently, so maintenance affecting dev does not force prod to fail over. This is the feature designed for per-VDOM-group redundancy in multi-VDOM HA deployments.

Why this answer

Virtual clustering divides a FortiGate HA cluster into multiple HA groups, each maintaining its own primary and monitored interfaces. By placing prod and dev in separate virtual clusters, the administrator achieves independent failover, so an event affecting dev does not cause prod to switch over. This is the intended mechanism for per-VDOM-group redundancy.

Exam trap

The trap here is confusing per-VDOM resource limits or HA priority with independent failover, when only virtual clustering creates separate HA groups that fail over on their own.

350
MCQeasy

A FortiGate administrator is setting up a ZTNA rule to allow access to an internal application only for users who are members of the 'Finance' group in FortiClient EMS. The administrator has already configured the ZTNA server and access proxy. Which additional configuration is required on the FortiGate to enforce this group membership?

A.Configure a user group on the FortiGate that maps to the Finance group in EMS and reference it in the ZTNA rule.
B.Enable EMS tag synchronization and create a tag for the Finance group.
C.Create a firewall address object for the Finance group and reference it in the ZTNA rule.
D.Add the Finance group as a local user group on the FortiGate and manually add each user.
AnswerA

To enforce EMS group membership, the FortiGate must have a user group that corresponds to the Finance group in EMS. This is typically done by creating a user group and selecting the EMS connector as the source, then specifying the Finance group. The ZTNA rule then references this user group as a source condition. This ensures that only users in the Finance group can access the application. This is the required configuration.

Why this answer

To enforce EMS group membership, the FortiGate must have a user group that is synchronized with the EMS Finance group. This is done by creating a user group with the EMS connector as the source and specifying the Finance group. The ZTNA rule then uses this user group as a source condition.

This ensures that only users belonging to the Finance group in EMS are granted access, without manual user management.

Exam trap

The trap here is confusing EMS tags with user groups; tags are for endpoint compliance, while user groups are for identity-based access.

351
Multi-Selecthard

A security engineer wants to implement advanced threat protection for email using FortiMail. Which THREE features should be enabled to provide comprehensive protection against sophisticated email threats? (Choose three.)

Select 3 answers
A.URL rewriting and click-time protection
B.FortiSandbox integration for email attachments
C.Anti-Spam filter
D.DMARC verification
E.Attachment size limits
AnswersA, B, D

URL rewriting converts embedded links into redirected FortiMail URLs, so every click is inspected at click time against live threat intelligence. This blocks weaponised or time-delayed phishing links that pass initial scanning, directly satisfying the stem's requirement for advanced protection against sophisticated email threats.

Why this answer

URL rewriting and click-time protection (A) is correct because FortiMail rewrites embedded URLs and re-evaluates them when the user clicks, blocking advanced phishing and malicious links that were benign at delivery time. FortiSandbox integration for email attachments (B) is correct because it detonates suspicious attachments in an isolated sandbox to detect zero-day malware and advanced persistent threats that signature-based scanning misses. DMARC verification (D) is correct because it validates the alignment of SPF and DKIM with the From: domain, preventing domain spoofing and business email compromise.

Anti-Spam filter (C) is not among the marked answers because it addresses bulk unsolicited mail rather than sophisticated targeted threats. Attachment size limits (E) are not among the marked answers because they only enforce message size policy and provide no threat detection capability.

Exam trap

The trap here is that candidates often mistake basic anti-spam or administrative controls (like attachment size limits) for advanced threat protection features, overlooking that sophisticated threats require dynamic, behavior-based defenses such as URL rewriting, sandboxing, and email authentication protocols.

352
MCQhard

A FortiGate is deployed in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator creates an inter-VDOM link named IVL1 with interface ivl-1-0 in VDOM-1 and ivl-1-1 in VDOM-2. Static routes are configured in both VDOMs to route traffic across the link. However, traffic from VDOM-1 to VDOM-2 is dropped. What is the most likely reason?

A.The inter-VDOM link pair must be in the same VDOM; splitting them across VDOMs disables the link.
B.The inter-VDOM link interfaces must be assigned to a zone before they can pass traffic.
C.Firewall policies allowing traffic from VDOM-1 to VDOM-2 across the inter-VDOM link have not been created in both VDOMs.
D.Inter-VDOM links do not support static routing; dynamic routing protocols must be used.
AnswerC

Inter-VDOM link traffic is subject to firewall policies. Even with correct static routes, you must create a policy in VDOM-1 that allows traffic from the internal interface to ivl-1-0, and a policy in VDOM-2 that allows traffic from ivl-1-1 to the destination interface. Without these policies, the FortiGate drops the traffic. This is the most common oversight when configuring inter-VDOM routing. Both directions require policies because each VDOM inspects traffic independently.

Why this answer

Inter-VDOM links provide a virtual connection between two VDOMs, but they are not exempt from firewall inspection. After creating the link and configuring static routes, you must add firewall policies in each VDOM to permit traffic from the source interface to the inter-VDOM link interface, and from the inter-VDOM link interface to the destination interface. Without these policies, the FortiGate drops the packets even though routing is correct.

This is a common misconfiguration in multi-VDOM deployments.

Exam trap

The trap here is believing that inter-VDOM links bypass firewall policies or that routing alone is sufficient, when in fact policies are required in both VDOMs.

353
MCQhard

During a ZTNA deployment, an administrator notices that traffic from a specific internal application is being routed through the ZTNA gateway but is not reaching the destination server. The FortiGate policy allows the traffic, and the client has a valid ZTNA connection. What is the most likely cause of the issue?

A.The ZTNA proxy rule on the FortiGate is misconfigured, pointing to the wrong destination IP or port.
B.The client's FortiClient agent is not connected to the EMS server.
C.The destination server does not have internet connectivity.
D.The FortiGate policy is set to deny traffic from the client's subnet.
AnswerA

The ZTNA proxy rule defines the destination IP and port used when forwarding the client's request to the internal application. If these are wrong, the FortiGate accepts the session but forwards it to an unreachable or incorrect server, so traffic never arrives.

Why this answer

In a ZTNA deployment, the FortiGate acts as a reverse proxy for internal applications. If the ZTNA proxy rule is misconfigured with an incorrect destination IP or port, the FortiGate will forward the traffic to the wrong backend server or service, causing the connection to fail even though the client has a valid ZTNA connection and the firewall policy permits the traffic.

Exam trap

The trap here is that candidates often assume the issue is with the client's connectivity or the firewall policy, but the key is that a valid ZTNA connection and permissive policy do not guarantee correct proxy forwarding—the proxy rule itself must accurately point to the destination server.

How to eliminate wrong answers

Option B is wrong because the client already has a valid ZTNA connection, which requires the FortiClient agent to be connected to the EMS server for authentication and posture checks; if it were disconnected, the ZTNA connection would not be established. Option C is wrong because the destination server does not need internet connectivity; ZTNA traffic is proxied through the FortiGate, and the server only needs reachability from the FortiGate, not the public internet. Option D is wrong because the question explicitly states that the FortiGate policy allows the traffic, so a deny policy for the client's subnet would contradict that condition.

354
Multi-Selectmedium

A FortiGate is configured as a ZTNA proxy. The administrator wants to ensure that only devices with a specific ZTNA tag assigned by FortiClient EMS are allowed to access the application. Which two configuration steps are required? (Choose two.)

Select 2 answers
A.Configure a firewall policy with the ZTNA proxy as destination and enable 'allow only ZTNA'
B.Create a firewall policy allowing all traffic to the ZTNA proxy
C.Enable 'set ztna-tag' on the FortiGate interface
D.Create a ZTNA access rule with a condition matching the tag
E.Import the ZTNA tag from EMS into FortiGate
AnswersD, E

The access rule must include a condition matching the specific ZTNA tag so FortiGate only admits devices carrying that EMS-assigned attribute. Without this tag condition, the rule cannot distinguish compliant devices from others, defeating the zero-trust requirement.

Why this answer

Option E is correct because the FortiGate must first learn the ZTNA tags that FortiClient EMS assigns to endpoints; this is done by configuring the EMS connector (FortiClient EMS fabric connector) and importing/synchronizing the tags, which then appear under ZTNA tags on the FortiGate. Option D is correct because enforcement of a specific tag is performed by a ZTNA access rule (access-proxy rule) whose condition matches the imported tag, so only devices presenting that tag are granted access to the protected application. Option A is incorrect because simply setting the ZTNA proxy as the destination with an 'allow only ZTNA' style setting does not itself match a specific EMS tag; tag-based authorization requires the access rule in D.

Option B is incorrect because a policy allowing all traffic to the ZTNA proxy would not restrict access by tag and would undermine the requirement. Option C is incorrect because there is no 'set ztna-tag' interface command; tags are matched in ZTNA access rules, not enabled on an interface.

355
Multi-Selecthard

A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing internal applications. The administrator wants to ensure that only authenticated and compliant devices can access the applications, and that all traffic is inspected. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Set the ZTNA server to use 'transparent' mode instead of 'proxy' mode for all applications.
B.Create a firewall policy that allows all traffic from the ZTNA server to the internal network.
C.Enable device posture checking by integrating FortiClient EMS with the FortiGate.
D.Configure a ZTNA server with application mappings for each internal application.
E.Configure SSL VPN for remote users to connect before accessing ZTNA applications.
AnswersC, D

Integrating FortiClient EMS allows the FortiGate to receive device posture tags, such as compliance status. These tags can then be used in firewall policies to enforce that only compliant devices access applications. Without this integration, the FortiGate cannot verify device posture, and ZTNA would not be able to enforce Zero Trust principles based on device health. This is a critical component for compliance enforcement.

Why this answer

To implement ZTNA with Zero Trust principles, you must define the applications via a ZTNA server with application mappings, and integrate FortiClient EMS to enforce device posture. These two actions ensure that only authenticated and compliant devices can access the specified applications. The ZTNA server proxies the traffic, and the EMS integration provides the necessary compliance data for policy decisions.

Exam trap

The trap here is thinking that SSL VPN or a specific ZTNA mode is required, while the core requirements are application mappings and posture integration.

356
MCQhard

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and observes that the 'ipsengine' process is consuming a large amount of CPU. The administrator suspects that a specific IPS signature is causing the issue. Which command should the administrator use to identify which IPS signature is triggering the high CPU usage?

A.diagnose sys session full-stat
B.diagnose ips anomaly list
C.diagnose test application ipsengine 4
D.diagnose debug application ipsmonitor -1
AnswerC

The command 'diagnose test application ipsengine 4' displays the top IPS signatures by CPU usage, helping identify which signature is causing high CPU. This is the correct tool for pinpointing a specific signature that is consuming excessive CPU resources.

Why this answer

The 'diagnose test application ipsengine 4' command is specifically designed to show the top IPS signatures by CPU usage, allowing the administrator to identify which signature is causing high CPU. Other commands provide general IPS or session information but do not drill down to per-signature CPU consumption.

Exam trap

The trap here is confusing general IPS debugging commands with those that provide per-signature CPU statistics.

357
Multi-Selectmedium

An administrator is investigating a security incident where a workstation is communicating with a known command and control (C2) server. The FortiGate has IPS enabled but did not block the traffic. Which TWO configuration issues could explain why the IPS did not detect the C2 communication? (Choose two.)

Select 2 answers
A.The firewall policy does not have SSL deep inspection enabled
B.The IPS sensor is configured in 'Inline' mode
C.The IPS sensor has 'Logging' disabled
D.The IPS sensor does not include signatures for the C2 protocol or pattern
E.The FortiGate is operating in 'Transparent' mode
AnswersA, D

Without SSL inspection, encrypted C2 traffic is invisible to IPS.

Why this answer

Without SSL deep inspection, the FortiGate cannot decrypt HTTPS traffic to inspect the payload for C2 signatures. IPS operates on decrypted content; if the C2 communication uses TLS, the IPS engine only sees encrypted packets and cannot match application-layer signatures. Enabling SSL deep inspection with a valid CA certificate is required to decrypt and inspect the traffic.

Exam trap

The trap here is that candidates often assume 'Inline' mode or 'Transparent' mode inherently affect detection capability, when in fact they only affect traffic flow or logging, not the IPS engine's ability to inspect decrypted content.

358
MCQmedium

An administrator configures a route map on a FortiGate to redistribute connected routes into OSPF. The route map sets a metric of 100. After applying, the redistributed routes appear with metric 20. What is the most likely reason?

A.The route map is applied to the wrong direction
B.OSPF does not allow metric setting via route maps
C.The route map is not applied to the redistribution configuration
D.The metric type is set to type 1
AnswerC

Without the route map attached to the OSPF redistribute command, FortiGate ignores its set metric and applies the default OSPF external metric of 20. The stem's constraint — a configured metric of 100 appearing as 20 — is satisfied only because the map never filters or modifies the redistribution.

Why this answer

The most likely reason the redistributed routes appear with metric 20 instead of the configured 100 is that the route map was not applied to the redistribution configuration. In FortiGate OSPF redistribution, a route map must be explicitly referenced under the 'redistribute connected' command; otherwise, the route map is ignored, and OSPF uses its default metric of 20 for redistributed connected routes.

Exam trap

The trap here is that candidates assume creating a route map automatically applies it to redistribution, but FortiGate requires explicit application under the redistribution command, and the default metric of 20 is used if no route map is referenced.

How to eliminate wrong answers

Option A is wrong because route maps in OSPF redistribution do not have a 'direction' like in route filtering; they are applied as a filter or modifier during the redistribution process itself, so direction is not a factor. Option B is wrong because OSPF does allow metric setting via route maps using the 'set metric' action, which is a standard feature in FortiGate OSPF configuration. Option D is wrong because setting the metric type to type 1 does not affect the metric value; it changes how the metric is calculated (adding internal cost), but the base metric would still be set by the route map if applied correctly.

359
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel that is not coming up. The configuration uses IKEv2 with pre-shared keys. The administrator runs 'diagnose vpn ike log-filter' and sees no logs. What is the most likely cause?

A.IKE debug is not enabled
B.The pre-shared key does not match
C.The tunnel name is misspelled in the filter
D.The remote gateway is unreachable
AnswerA

IKEv2 negotiation events are only captured once the IKE log filter is applied and debug output is active; without enabling IKE debugging, 'diagnose vpn ike log-filter' produces no output, so the tunnel's failure remains invisible.

Why this answer

The diagnose vpn ike log-filter command sets a filter for which IKE negotiations to log, but it does not itself enable logging — the administrator must also run diagnose debug application ike -1 (or the equivalent debug enable command) to actually turn on IKE debug output. Seeing no logs after setting a filter is the classic symptom of debug not being enabled. The filter only narrows what would be logged if logging were active.

Exam trap

NSE7 often tests the two-step nature of FortiGate debugging, so the trap is assuming that setting the log-filter is sufficient and then misdiagnosing the silence as a PSK or reachability problem.

How to eliminate wrong answers

Option B is wrong because a PSK mismatch would still produce IKE logs (showing the negotiation failing at the authentication stage) — the absence of any logs points to logging being off, not to a credential problem. Option C is wrong because a misspelled tunnel name in the filter would simply filter out that tunnel's logs, but the administrator would typically still see logs for other negotiations or could correct the filter; the more fundamental issue is that debug is not enabled at all. Option D is wrong because an unreachable remote gateway would still generate IKE retransmission and timeout logs, so the administrator would see activity rather than silence.

360
MCQmedium

A FortiGate is configured with VRF. Which statement about VRF is true?

A.Interfaces can belong to multiple VRFs simultaneously.
B.VRF allows multiple routing tables to coexist on the same FortiGate.
C.Routes from different VRFs can be automatically redistributed without configuration.
D.VRF can only be used when OSPF is enabled.
AnswerB

VRF (virtual routing and forwarding) instantiates separate routing tables on one FortiGate, so overlapping IP subnets can be isolated per tenant or interface without leaking routes between them. This directly satisfies the stem's requirement that multiple routing tables coexist on the same device, which is the defining property of VRF.

Why this answer

VRF (Virtual Routing and Forwarding) allows a single FortiGate to maintain multiple independent routing tables, each with its own set of interfaces, routes, and forwarding decisions. This enables network segmentation and traffic isolation without requiring separate physical devices, making option B correct.

Exam trap

The trap here is that candidates often assume interfaces can belong to multiple VRFs (like VLAN sub-interfaces can belong to multiple VLANs), but in VRF, each interface is exclusively bound to a single VRF instance.

How to eliminate wrong answers

Option A is wrong because a physical or logical interface can belong to only one VRF at a time; an interface is assigned to a specific VRF instance and cannot be shared across multiple VRFs simultaneously. Option C is wrong because routes between VRFs are not automatically redistributed; explicit route leaking or inter-VRF routing policies (e.g., using route maps or VRF leak commands) must be configured to share routes between VRFs. Option D is wrong because VRF is independent of any specific routing protocol; it works with static routes, BGP, OSPF, RIP, or any combination, and does not require OSPF to be enabled.

361
MCQmedium

A security administrator is configuring a FortiGate to use an external threat intelligence feed to block malicious IP addresses. The administrator wants the FortiGate to automatically update the list of malicious IPs from a threat feed and use it in firewall policies. Which FortiGate feature should be used?

A.DNS filter with a threat feed category
B.Internet Service Database (ISDB) in firewall addresses
C.Threat feeds in Security Fabric > Fabric Connectors
D.Geo IP database in firewall addresses
AnswerC

FortiGate supports external threat feeds via Fabric Connectors, allowing the administrator to subscribe to a feed (e.g., TAXII, STIX, or plain text) and automatically update a dynamic firewall address. This address can then be used in firewall policies to block or allow traffic. This feature is designed for integrating external threat intelligence.

Why this answer

Threat feeds in Fabric Connectors allow FortiGate to subscribe to external threat intelligence sources and automatically update dynamic firewall addresses. These addresses can be used in policies to block malicious IPs. Other options either provide static or geographic-based lists, not dynamic external feeds.

Exam trap

The trap here is confusing threat feeds with Geo IP or ISDB, which are not dynamic external feeds for malicious IPs.

362
MCQmedium

An administrator configures inter-VDOM routing between VDOMs A and B using a VDOM link. The administrator can ping from VDOM A to an interface in VDOM B, but traffic from VDOM B to VDOM A times out. What is the most likely cause?

A.VDOM B has no traffic VDOM capability
B.The route back to the source subnet is missing in VDOM A
C.The firewall policy in VDOM B is blocking traffic
D.The VDOM link's MTU is set too high
AnswerB

For traffic from B to A to succeed, VDOM A must have a route back to the source subnet. Without it, return traffic is dropped.

Why this answer

Inter-VDOM routing requires a route in both directions. Since the administrator can ping from VDOM A to VDOM B, the forward path works, but the return traffic from VDOM B to VDOM A fails due to a missing route back to the source subnet in VDOM A. This is a classic asymmetric routing issue where the destination VDOM (A) does not know how to reach the source subnet of VDOM B.

Exam trap

The trap here is that candidates assume a successful ping in one direction implies full bidirectional connectivity, overlooking that each VDOM maintains an independent routing table and the return path must be explicitly configured.

How to eliminate wrong answers

Option A is wrong because VDOMs do not have a 'traffic VDOM capability' setting; all VDOMs can forward traffic by default, and the ability to ping in one direction proves VDOM B is capable of processing traffic. Option C is wrong because if a firewall policy in VDOM B were blocking traffic, the ping from VDOM A to VDOM B would also fail, as the policy would block the forward direction as well. Option D is wrong because an MTU mismatch would cause fragmentation issues or packet drops for large packets, but ICMP echo requests and replies are typically small and would not be affected by a high MTU setting; moreover, the symptom is a complete timeout, not partial or intermittent failure.

363
Multi-Selecthard

An administrator is troubleshooting an SD-WAN deployment where traffic is not being forwarded according to the configured SD-WAN rules. The FortiGate has two WAN interfaces, port1 and port2, both members of an SD-WAN zone. A performance SLA is configured and both members are within SLA. The administrator suspects that the SD-WAN rules are not being evaluated correctly. Which two statements about SD-WAN rule evaluation are correct? (Choose two.)

Select 2 answers
A.SD-WAN rules are evaluated in the order they appear in the configuration, and the first matching rule is applied.
B.If no SD-WAN rule matches, traffic is dropped by default.
C.SD-WAN rules can match traffic based on the application identified by the application control profile.
D.SD-WAN rules are evaluated only after a firewall policy has allowed the traffic.
E.SD-WAN rules are applied only to outbound traffic initiated from the internal network.
AnswersA, C

SD-WAN rules are processed sequentially from top to bottom. The first rule that matches the traffic's criteria (source, destination, application, etc.) is used for path selection. Subsequent rules are not evaluated. Therefore, rule order is critical; a broad rule placed before a specific one can prevent the specific rule from ever being matched.

Why this answer

SD-WAN rules are evaluated in a top-down order, and the first matching rule determines the path selection. They can match on various criteria, including applications identified by application control. If no rule matches, the FortiGate uses the regular routing table.

SD-WAN rules are part of the routing decision and are evaluated before firewall policies. They are not limited to outbound traffic; they can apply to any traffic that matches the criteria.

Exam trap

The trap here is assuming that SD-WAN rules are evaluated after firewall policies or that unmatched traffic is dropped, when in fact routing decisions precede policy enforcement and fallback to the routing table occurs.

364
MCQmedium

An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?

A.The SSL inspection profile is set to protect only the server, not the client.
B.The FortiGate is using a self-signed certificate for deep inspection.
C.The FortiGate is not configured to use SNI for SSL inspection.
D.The websites are using certificate pinning, which prevents deep inspection.
AnswerD

Certificate pinning is a security mechanism where the application or browser expects a specific certificate or public key. When FortiGate performs deep inspection, it re-signs the certificate, breaking the pin and causing an error. This is a common reason why some HTTPS sites fail under deep inspection.

Why this answer

Certificate pinning in applications or browsers causes certificate errors when deep inspection is used because the FortiGate presents a re-signed certificate that does not match the pinned certificate. Administrators should exempt such sites from deep inspection or use a different inspection method.

Exam trap

The trap here is assuming that any certificate error under deep inspection is due to an untrusted CA, when certificate pinning is a common and specific cause that cannot be resolved by simply trusting the CA.

365
MCQhard

You are troubleshooting BFD on a FortiGate SD-WAN deployment. BFD is configured on two WAN interfaces (wan1, wan2) with a minimum transmit interval of 100 ms and a multiplier of 3. The network experiences occasional jitter causing packet loss. After a brief outage, the BFD session does not recover. Which setting should be adjusted to improve BFD resilience without significantly increasing failover time?

A.Disable BFD and rely on route timers.
B.Enable BFD on the management interface.
C.Increase the BFD minimum transmit interval on both interfaces.
D.Increase the BFD multiplier to 4 or higher.
AnswerD

Raising the multiplier from 3 to 4+ tolerates more consecutive missed BFD packets before declaring the peer down, absorbing jitter-induced loss so sessions recover. Transmit interval changes would alter detection timing more drastically, so the multiplier is the precise resilience lever.

Why this answer

Increasing the BFD multiplier (from 3 to 4 or higher) allows the session to tolerate more lost BFD control packets before declaring a failure. This directly addresses the jitter-induced packet loss without changing the detection timing for sustained outages, as the multiplier only affects the number of missed packets required to trigger a failure. The minimum transmit interval remains at 100 ms, so the base detection time (multiplier × interval) increases only slightly, preserving fast failover for true link failures.

Exam trap

The trap here is that candidates mistakenly increase the transmit interval (Option C) thinking it reduces jitter sensitivity, but that actually increases failover time for all failures, whereas adjusting the multiplier provides resilience against intermittent loss without proportionally increasing detection time for sustained outages.

How to eliminate wrong answers

Option A is wrong because disabling BFD removes sub-second failure detection entirely, reverting to slower routing protocol timers (e.g., OSPF dead interval of 40 seconds), which would significantly increase failover time. Option B is wrong because enabling BFD on the management interface is irrelevant to SD-WAN WAN link resilience; BFD on the management interface monitors management-plane connectivity, not data-plane SD-WAN paths. Option C is wrong because increasing the minimum transmit interval (e.g., to 200 ms) would directly increase the base detection time for all failures, including sustained outages, thereby increasing failover time, which contradicts the requirement to not significantly increase failover time.

366
MCQeasy

A network administrator is configuring VDOMs on a FortiGate and wants to separate management traffic from production data traffic. What is the best practice when using a management VDOM?

A.Disable management access on all VDOMs except the root VDOM
B.Use inter-VDOM routing to route management traffic to the root VDOM
C.Create a dedicated management VDOM and assign only management interfaces to it
D.Assign all interfaces to the management VDOM
AnswerC

A dedicated management VDOM isolates administrative traffic from production data, satisfying the requirement to separate management from data planes. Assigning only management interfaces ensures administrative access terminates in its own routing and policy domain, preventing production traffic from reaching management services and containing any compromise of the management plane.

Why this answer

Creating a dedicated management VDOM and assigning only management interfaces to it is the best practice because it isolates management traffic from production data traffic, reducing the attack surface and preventing management access from being exposed to untrusted networks. This aligns with Fortinet's security best practices for VDOM administration, ensuring that management functions are logically separated from data-plane operations.

Exam trap

The trap here is that candidates often confuse the root VDOM's default management role with a best-practice isolation strategy, assuming that disabling management on other VDOMs is sufficient, when in fact a dedicated management VDOM provides true separation and is the recommended approach in the NSE7 curriculum.

How to eliminate wrong answers

Option A is wrong because disabling management access on all VDOMs except the root VDOM does not inherently separate management traffic from production data; the root VDOM itself may still carry production traffic, and this approach does not create a dedicated management plane. Option B is wrong because using inter-VDOM routing to route management traffic to the root VDOM mixes management and production traffic at the routing layer, defeating the purpose of isolation and introducing potential security risks. Option D is wrong because assigning all interfaces to the management VDOM would collapse all traffic—including production data—into the management domain, eliminating any separation and exposing management functions to production threats.

367
MCQmedium

A FortiGate administrator wants to use FortiManager automation stitches to automatically block an IP address when a specific threat is detected. Which components must be configured within the automation stitch?

A.A trigger and a connector to an external threat feed
B.An action only, since the trigger is predefined
C.A trigger, at least one action, and optionally conditions
D.A schedule and a script
AnswerC

Trigger defines when to run; action defines what to do; conditions filter.

Why this answer

An automation stitch in FortiManager requires a trigger (e.g., an event or log match) to start the workflow, at least one action (e.g., a CLI script to block an IP via firewall address creation), and optionally conditions to filter when the trigger fires. This three-part structure is mandatory because the trigger defines the event, the action executes the response, and conditions provide granular control without which the stitch would fire on every trigger occurrence.

Exam trap

The trap here is that candidates assume the trigger is implicit or predefined (like a schedule) and only an action is needed, but FortiManager requires explicit trigger configuration even for event-based automation, and conditions are optional but often necessary to avoid false positives.

How to eliminate wrong answers

Option A is wrong because a connector to an external threat feed is not a required component of an automation stitch; the stitch uses a trigger (like a log event) and actions, not an external feed connector. Option B is wrong because the trigger is not predefined; the administrator must configure a trigger (e.g., event handler or schedule) and at least one action, so an action alone is insufficient. Option D is wrong because a schedule is only one type of trigger (time-based) and a script is one type of action; the stitch requires a trigger and action, but not exclusively a schedule and script—other triggers (e.g., event-based) and actions (e.g., email, webhook) are valid.

368
MCQmedium

An administrator configures an automation stitch on FortiGate to automatically block an IP address when a specific IPS signature triggers. What must be configured as the trigger and action?

A.Trigger: 'Event Log' with filter for the IPS signature; Action: 'Add IP to Blocklist'
B.Trigger: 'Incoming Webhook'; Action: 'CLI Script'
C.Trigger: 'FortiOS CLI'; Action: 'Alert Email'
D.Trigger: 'Schedule'; Action: 'Banned IP'
AnswerA

An Event Log trigger with an IPS signature filter fires when the sensor logs that specific attack, and the Add IP to Blocklist action inserts the source address into the DoS policy blocklist, satisfying the requirement to block automatically on signature match.

Why this answer

An automation stitch in FortiGate requires a trigger that defines the event that starts the automation, and an action that defines what happens when the trigger fires. For automatically blocking an IP when a specific IPS signature triggers, the trigger must be 'Event Log' with a filter for that IPS signature, and the action must be 'Add IP to Blocklist', which directly adds the source IP to the FortiGate's blocklist (banned IP list). This combination ensures that when the IPS signature is logged, the stitch extracts the source IP and applies a block.

Exam trap

The trap here is that candidates confuse 'Banned IP' (a status or list) with the actual action name 'Add IP to Blocklist', or they mistakenly think a CLI script or webhook can directly react to an IPS event without the proper log-based trigger.

How to eliminate wrong answers

Option B is wrong because 'Incoming Webhook' is a trigger that waits for an external HTTP request, not for an IPS signature event; it cannot directly react to local IPS logs. Option C is wrong because 'FortiOS CLI' is not a valid trigger type in automation stitches; triggers are events like 'Event Log', 'Incoming Webhook', or 'Schedule', not CLI commands. Option D is wrong because 'Schedule' is a time-based trigger (e.g., daily at 2 AM), not an event-driven trigger for an IPS signature; 'Banned IP' is not a valid action name—the correct action is 'Add IP to Blocklist'.

369
MCQmedium

A FortiGate administrator is configuring an IPsec VPN with IKEv2. The remote peer is behind a NAT device and has a dynamic public IP. The administrator wants the FortiGate to act as the responder and allow the remote peer to initiate the tunnel, while ensuring that only the remote peer's unique ID (FQDN) is accepted. Which configuration on the FortiGate is required to achieve this?

A.Set the local gateway to 0.0.0.0 and configure the remote gateway as the remote peer's current public IP, then set the peer ID to the remote peer's FQDN.
B.Set the local gateway to the FortiGate's public IP and configure the remote gateway as 0.0.0.0, then set the peer ID to the remote peer's FQDN.
C.Set the local gateway to 0.0.0.0 and configure a pre-shared key with the remote peer's FQDN as the peer ID.
D.Set the local gateway to 0.0.0.0 and configure the remote gateway as 0.0.0.0, then set the peer ID to the remote peer's FQDN.
AnswerD

When the remote peer has a dynamic IP and is behind NAT, the FortiGate must listen on all interfaces (local gateway 0.0.0.0) and accept any remote gateway (remote gateway 0.0.0.0). The peer ID is then used to authenticate the remote peer by its FQDN, ensuring only that peer can connect. This is the correct configuration for dynamic IP with peer ID verification.

Why this answer

For a remote peer with a dynamic IP behind NAT, the FortiGate must listen on all interfaces and accept connections from any IP. Setting the local gateway to 0.0.0.0 and the remote gateway to 0.0.0.0 enables this. The peer ID is then used to authenticate the remote peer by its FQDN, providing security without relying on a static IP.

This configuration is standard for dynamic IP peers.

Exam trap

The trap here is assuming that the remote gateway must be set to the peer's current IP, but dynamic IPs require 0.0.0.0 to avoid tunnel failures when the IP changes.

370
MCQeasy

What is the purpose of a header policy in a FortiManager policy package?

A.To apply policies to the management VDOM
B.To create policies that bypass security profiles
C.To define policies that are inserted at the beginning of the policy list
D.To specify the name of the policy package
AnswerC

Header policies sit at the top of a policy package's list, so their rules are evaluated before all other policies. This satisfies the requirement to control traffic precedence, letting you enforce global restrictions or exemptions that must match first, rather than being shadowed by later, more specific rules.

Why this answer

A header policy in a FortiManager policy package is used to define policies that are inserted at the beginning of the policy list, before any other policies. This ensures that certain traffic matching criteria (e.g., from specific sources or to specific destinations) is evaluated first, which is critical for enforcing high-priority rules like allowlisting or blocking specific traffic before more general policies are applied.

Exam trap

The trap here is that candidates often confuse header policies with policies that bypass security profiles or think they apply only to the management VDOM, when in fact they are simply a mechanism to control policy order within any VDOM's policy list.

How to eliminate wrong answers

Option A is wrong because header policies apply to the policy list within a VDOM, not specifically to the management VDOM; the management VDOM is a separate administrative domain used for managing the FortiGate, not for applying traffic policies. Option B is wrong because header policies do not bypass security profiles; they are simply positioned at the top of the policy list and still enforce all configured security profiles (e.g., antivirus, IPS) unless explicitly disabled in the policy. Option D is wrong because the name of the policy package is defined when creating the package, not by a header policy; header policies are entries within the package, not a naming mechanism.

371
Multi-Selectmedium

A FortiGate in an HA cluster is experiencing intermittent session synchronization failures. The administrator runs 'diagnose sys ha dump sync-status' and sees that sessions are not being synchronized properly. Which TWO potential causes should the administrator investigate?

Select 2 answers
A.Mismatched HA group IDs
B.Excessive number of sessions exceeding the session sync limit
C.Incorrect BGP route advertisements
D.High packet loss or latency on the heartbeat interface
E.Mismatched HA passwords
AnswersB, D

FortiGate synchronises only a set number of sessions; once the session count exceeds that sync limit, additional sessions are not replicated to the secondary unit. This produces exactly the intermittent synchronisation failures observed, as only sessions beyond the threshold go unsynchronised.

Why this answer

FortiGate HA has a configurable session sync limit (default 500,000 sessions). When the number of concurrent sessions exceeds this limit, the FortiGate stops synchronizing new sessions to the backup unit, leading to intermittent synchronization failures. This can be verified by checking the 'ses_sync_limit' value in the HA configuration and comparing it to the current session count.

Option D is correct because high packet loss or latency on the heartbeat interface can cause session synchronization failures. The heartbeat interface carries synchronization traffic, and any degradation in its performance can lead to missed or delayed sync packets, resulting in intermittent sync failures. This can be diagnosed by checking heartbeat interface statistics such as packet loss and latency.

Exam trap

The trap here is that candidates often assume all HA synchronization failures are caused by network connectivity issues (high latency/packet loss) and overlook the session sync limit, which is a configuration-based threshold that can cause intermittent failures even with perfect heartbeat connectivity.

372
MCQmedium

An administrator has deployed a FortiGate at a branch with two WAN links: port1 (primary) and port2 (backup). They create an SD-WAN zone and a performance SLA named 'ISP-Health' that monitors 8.8.8.8 using ping. The SLA is configured with link-cost-factor latency and a threshold of 50 ms. After a week, they notice that the primary link is still being used for all traffic even though its latency frequently exceeds 150 ms. The backup link has 20 ms latency. What is the most likely reason the SD-WAN rule is not failing over?

A.The SD-WAN rule is using the 'lowest-cost' algorithm, which ignores SLA status and only uses link cost.
B.The performance SLA is not referenced in the SD-WAN rule, so the rule cannot use the SLA status to make decisions.
C.The SLA monitor uses ping, which is not supported for latency measurement; only HTTP and TCP echo are valid.
D.The link-cost-factor is set to latency, but the backup link must also have an SLA configured to be eligible for failover.
AnswerB

For an SD-WAN rule to react to SLA status, the rule must explicitly reference the performance SLA in its configuration. Without that reference, the FortiGate only uses static criteria like interface priority, ignoring the SLA results. This matches the symptom of the primary link remaining in use despite high latency. The administrator must edit the SD-WAN rule and select 'ISP-Health' as the SLA target.

Why this answer

The SD-WAN rule must explicitly reference the performance SLA for the FortiGate to use SLA results in path selection. Without that association, the rule falls back to static criteria such as interface priority or link cost, so the primary link continues to be used even when its latency exceeds the threshold. The administrator needs to edit the rule and select the SLA as a target.

Exam trap

The trap here is assuming that creating a performance SLA automatically makes all SD-WAN rules SLA-aware, when each rule must explicitly reference the SLA.

373
MCQeasy

Which FortiGate feature allows the creation of multiple virtual routing tables within a single VDOM?

A.VRF
B.Policy-based routing
C.VDOM
D.ECMP
AnswerA

VRF (virtual routing and forwarding) instantiates independent routing tables inside one VDOM, each with its own interfaces, routes and forwarding decisions. This separation satisfies the requirement for multiple virtual routing tables within a single VDOM without deploying additional VDOMs.

Why this answer

VRF (Virtual Routing and Forwarding) allows a single FortiGate VDOM to maintain multiple independent routing tables, each with its own forwarding decisions. This is achieved by creating separate VRF instances (identified by VRF IDs 1-255) within the same VDOM, enabling traffic isolation and overlapping IP address spaces without requiring separate VDOMs.

Exam trap

The trap here is confusing VDOM with VRF: candidates often think VDOMs are the only way to create multiple routing tables, but VRF achieves this within a single VDOM, which is a more granular and resource-efficient approach for network segmentation.

How to eliminate wrong answers

Option B (Policy-based routing) is wrong because it overrides the routing table for specific traffic based on policies, but does not create multiple independent routing tables; it only redirects traffic within a single routing table. Option C (VDOM) is wrong because VDOMs create separate virtual firewalls with their own routing tables, but the question asks for multiple routing tables within a single VDOM, not separate VDOMs. Option D (ECMP) is wrong because ECMP (Equal-Cost Multi-Path) is a load-balancing technique that distributes traffic across multiple paths within a single routing table, not a mechanism to create multiple routing tables.

374
MCQeasy

An administrator wants to isolate tenant traffic in a single FortiGate by creating separate virtual firewalls with independent routing tables, administrators, and policies. Which feature should the administrator use?

A.Virtual Domains (VDOMs)
B.Policy-based routing (PBR)
C.Virtual Router Redundancy Protocol (VRRP)
D.Virtual LANs (VLANs)
AnswerA

Virtual Domains partition a single FortiGate into independent virtual firewalls, each with its own routing table, administrators, policies and interfaces. This directly satisfies the requirement to isolate tenant traffic with separate routing and administrative boundaries on one appliance.

Why this answer

VDOMs (Virtual Domains) are the correct feature because they partition a single FortiGate into multiple independent virtual firewalls, each with its own routing table, administrator access, and security policies. This allows complete tenant isolation within one physical appliance, meeting the administrator's requirement for separate virtual firewalls with independent routing, administration, and policy control.

Exam trap

The trap here is confusing VLANs (Layer 2 segmentation) with VDOMs (Layer 3+ virtual firewall isolation), leading candidates to pick VLANs because they think network segmentation alone achieves tenant isolation, but VLANs lack independent routing tables and administrative domains.

How to eliminate wrong answers

Option B (Policy-based routing) is wrong because it only controls traffic forwarding based on policies, not creating separate virtual firewalls with independent routing tables and administrators. Option C (VRRP) is wrong because it provides high availability and redundancy between FortiGates, not isolation of tenant traffic within a single device. Option D (VLANs) is wrong because VLANs segment Layer 2 broadcast domains and can be used with VDOMs, but alone they do not provide independent routing tables, administrators, or security policies for each tenant.

375
MCQeasy

A FortiGate administrator is configuring an IPsec VPN to a remote peer behind a device that performs NAT. The administrator notices that the tunnel establishes but rekeys fail after the Phase 1 lifetime expires. Which setting should the administrator enable on the FortiGate to allow the IKE negotiation to survive NAT and pass through the NAT device reliably?

A.Dead Peer Detection (DPD) with an aggressive retry interval on Phase 1.
B.Aggressive mode for IKE Phase 1 instead of main mode.
C.NAT traversal (NAT-T) on the IPsec Phase 1 interface.
D.Perfect Forward Secrecy (PFS) on the IPsec Phase 2 interface.
AnswerC

NAT-T encapsulates IKE and ESP in UDP (typically port 4500) so that NAT devices can translate the traffic and maintain state. When a peer is behind NAT, enabling NAT-T on the Phase 1 interface allows the tunnel to establish and rekey reliably, because the NAT device can track the UDP flow. Without NAT-T, ESP packets may be dropped or mishandled, causing rekey failures.

Why this answer

NAT-T allows IKE and ESP to be encapsulated in UDP so NAT devices can translate and track the flow. Enabling NAT-T on the Phase 1 interface lets the tunnel establish and rekey reliably when a peer sits behind NAT, which directly addresses the rekey failures observed after the Phase 1 lifetime expires.

Exam trap

The trap here is confusing NAT traversal with other IPsec options such as PFS or aggressive mode, which do not solve NAT translation issues.

Page 4

Page 5 of 10

Page 6

All pages