Courseiva

Fortinet NSE 7 Advanced Security NSE7 (NSE7) — Questions 601–675

718 questions total · 10pages · All types, answers revealed

Page 8

Page 9 of 10

Page 10
601
MCQmedium

A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?

A.Use a dial-up VPN with a pre-shared key and set the remote gateway to the peer's public IP address.
B.Set the remote gateway to 0.0.0.0 and configure a peer ID with the remote peer's identifier.
C.Configure the remote gateway as a fully qualified domain name (FQDN) and enable dynamic DNS updates.
D.Set the remote gateway to 0.0.0.0 and disable peer ID verification, relying on pre-shared key only.
AnswerB

When the remote peer has a dynamic IP, setting the remote gateway to 0.0.0.0 allows the FortiGate to accept connections from any IP. The peer ID is used to authenticate the remote peer. This is the standard method for dynamic IP peers in IPsec VPN configurations on FortiGate.

Why this answer

For a remote peer with a dynamic IP, the FortiGate must listen for incoming connections from any IP. Setting the remote gateway to 0.0.0.0 achieves this. The peer ID is then used to uniquely identify and authenticate the remote peer, ensuring that only the legitimate peer can establish the tunnel.

This combination is the correct approach.

Exam trap

The trap here is assuming that an FQDN or a specific IP address can handle dynamic IP changes without additional configuration, overlooking the need for 0.0.0.0 and peer ID.

602
MCQmedium

An administrator is configuring a FortiGate in transparent mode for a data center segment. Which of the following is true about transparent mode operation in an enterprise environment?

A.The FortiGate requires an IP address on each interface to route between VLANs
B.Transparent mode operates at Layer 2, so no IP configuration is needed on the FortiGate interfaces
C.Transparent mode is only available on specific hardware models
D.Transparent mode supports NAT and VPN termination
AnswerB

Transparent mode forwards frames at Layer 2 between interfaces, so the FortiGate needs no IP addresses on its data plane interfaces; management access uses a separate management interface. This satisfies the data centre segment requirement of inserting inspection without re-addressing the existing subnet.

Why this answer

In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses rather than IP addresses. This means the FortiGate interfaces do not require IP addresses for traffic forwarding; a management IP is configured on a VLAN interface or the root VDOM for administrative access only. Option B correctly identifies that transparent mode functions at Layer 2, so no IP configuration is needed on the physical interfaces for data plane operation.

Exam trap

The trap here is that candidates assume a firewall always needs IP addresses on its interfaces to function, but in transparent mode the FortiGate acts as a bump-in-the-wire at Layer 2, requiring only a management IP for administrative access, not for traffic forwarding.

How to eliminate wrong answers

Option A is wrong because in transparent mode, the FortiGate does not route between VLANs; it bridges traffic at Layer 2, and inter-VLAN routing would require a Layer 3 device upstream or a separate VDOM in NAT/route mode. Option C is wrong because transparent mode is available on all FortiGate models that support the current FortiOS version, not limited to specific hardware. Option D is wrong because transparent mode does not support NAT or VPN termination; these features require the FortiGate to operate in NAT/route mode (Layer 3) with IP routing enabled.

603
MCQmedium

A network administrator notices that FortiGate is not blocking a known malicious file that was submitted to FortiSandbox and received a 'malicious' verdict. The firewall policy includes a FortiSandbox inline scan profile. What is the MOST likely cause?

A.The antivirus signature database is outdated
B.The FortiSandbox license has expired
C.The FortiSandbox is not configured as an inline scanner in the antivirus profile
D.The file is larger than the maximum file size allowed for scanning
AnswerC

An inline FortiSandbox profile only blocks when the sandbox is added as an inline scanner within the antivirus profile; otherwise verdicts are advisory. Without that scanner binding, the malicious verdict never triggers a block action, matching the observed failure to block.

Why this answer

The FortiGate uses an antivirus profile to define how files are scanned, including whether to send files to FortiSandbox for inline analysis. Even if the firewall policy references a FortiSandbox inline scan profile, the antivirus profile must have the 'FortiSandbox inline scan' option enabled to actually forward files to the FortiSandbox appliance. Without this setting, the FortiGate will not submit files for sandboxing, so a malicious verdict from FortiSandbox is never applied to the traffic.

Exam trap

The trap here is that candidates confuse the firewall policy's 'FortiSandbox inline scan profile' with the antivirus profile's inline scan setting, assuming that referencing a sandbox profile in the policy is sufficient to enable file submission, when in fact the antivirus profile must also have the inline scan option explicitly enabled.

How to eliminate wrong answers

Option A is wrong because an outdated antivirus signature database would affect signature-based detection, but the question states the file was submitted to FortiSandbox and received a 'malicious' verdict, indicating the sandbox analysis worked; the issue is that the verdict is not being enforced, not that signatures are missing. Option B is wrong because an expired FortiSandbox license would prevent the FortiSandbox from processing files or returning verdicts, but the scenario says the file received a malicious verdict, meaning the sandbox is operational and licensed. Option D is wrong because if the file were larger than the maximum file size allowed for scanning, the FortiGate would typically skip scanning or pass the file without sandboxing, but the question states the file was submitted to FortiSandbox and received a verdict, so size is not the blocking factor.

604
Multi-Selecthard

An administrator is configuring a FortiGate to use the external threat feed feature to block traffic from known malicious IP addresses. They want to ensure that the feed is automatically updated and that the firewall blocks traffic based on the feed. Which two actions must the administrator perform? (Choose two.)

Select 2 answers
A.Add the external threat feed object as a source or destination in a firewall policy with a deny action.
B.Enable FortiGuard antivirus scanning on the firewall policy.
C.Create an external threat feed object and specify the URL of the threat feed.
D.Set the threat feed object to 'monitor' mode in the firewall policy.
E.Configure a DNS filter profile to block the malicious IP addresses.
AnswersA, C

After creating the threat feed object, it must be used in a firewall policy. By adding it as a source or destination and setting the action to deny, FortiGate will block traffic matching the feed entries. This enforces the threat intelligence and prevents communication with malicious IPs.

Why this answer

To use an external threat feed for blocking, the administrator must first create the threat feed object with the feed URL, then reference that object in a firewall policy with a deny action. The FortiGate will download and update the feed automatically, and the policy will block matching traffic. Other options do not achieve IP-based blocking from a threat feed.

Exam trap

The trap here is thinking that enabling antivirus or DNS filtering will enforce a threat feed; threat feed blocking requires a dedicated object and a deny policy.

605
MCQeasy

What is the primary function of FortiDeceptor in a network security architecture?

A.To provide network access control for endpoints
B.To aggregate logs from multiple security devices
C.To lure attackers into interacting with decoys and generate alerts
D.To detect and block malware at the endpoint
AnswerC

FortiDeceptor deploys decoy services and endpoints that mimic real assets, luring attackers into interaction. Any engagement with these decoys generates high-fidelity alerts with near-zero false positives, satisfying the requirement to detect intrusions that evade signature-based controls.

Why this answer

FortiDeceptor is a deception-based threat detection solution that deploys decoys (fake assets) across the network to lure attackers. When an attacker interacts with a decoy, FortiDeceptor generates a high-fidelity alert, enabling early detection of lateral movement or reconnaissance without relying on signatures.

Exam trap

The trap here is that candidates confuse FortiDeceptor's deception-based detection with endpoint protection or log aggregation, but the exam specifically tests that its primary function is to lure attackers into interacting with decoys and generate alerts.

How to eliminate wrong answers

Option A is wrong because network access control for endpoints is the function of FortiNAC, not FortiDeceptor, which focuses on deception rather than admission control. Option B is wrong because log aggregation from multiple security devices is the role of FortiAnalyzer or a SIEM, not FortiDeceptor, which generates its own alerts from decoy interactions. Option D is wrong because detecting and blocking malware at the endpoint is the domain of FortiEDR or endpoint security solutions, whereas FortiDeceptor does not execute or block code on endpoints.

606
MCQmedium

An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?

A.The SP's metadata must be imported as a firewall address
B.User accounts must be synchronized with an LDAP server
C.A certificate for signing SAML assertions
D.A pre-shared key between FortiGate and the SP
AnswerC

SAML assertions must be digitally signed so the service provider can verify they genuinely originate from the FortiGate IdP. A signing certificate is therefore mandatory; without it, the SP rejects assertions and SSO fails during trust validation.

Why this answer

When FortiGate acts as a SAML IdP, it must sign SAML assertions to prove their authenticity to the SP. A certificate is required for this signing, as the SP will validate the assertion using the IdP's public key. Without a signing certificate, the SAML response cannot be cryptographically verified, breaking the trust model defined in the SAML 2.0 specification.

Exam trap

The trap here is that candidates confuse SAML's asymmetric signing requirement with symmetric pre-shared keys used in VPNs, or assume that external user synchronization is mandatory, when in fact local users or other identity stores suffice.

How to eliminate wrong answers

Option A is wrong because SP metadata is imported as a SAML service provider object, not as a firewall address; firewall addresses are used for network policies, not SAML identity federation. Option B is wrong because user accounts can be defined locally on the FortiGate or via other identity sources such as RADIUS or FSSO; LDAP synchronization is not mandatory for SAML IdP operation. Option D is wrong because SAML uses asymmetric cryptography (X.509 certificates) for signing and optionally encryption, not a pre-shared key; a PSK is used in protocols like IPsec or IKE, not in SAML.

607
MCQmedium

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?

A.diagnose firewall iprope list 100004
B.diagnose ip router lookup <remote_subnet>
C.diagnose sniffer packet any 'host <remote_peer_ip> and esp' 4
D.diagnose vpn ike log filter name <tunnel_name>
AnswerC

This command captures ESP packets between the local and remote peer, showing whether traffic is being encrypted and sent. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption. This directly verifies if traffic is being encrypted and transmitted.

Why this answer

When an IPsec tunnel is up but traffic is not passing, it is essential to verify whether packets are being encrypted and sent. The sniffer command with an ESP filter captures encrypted packets, confirming if encryption is occurring. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption domains.

Exam trap

The trap here is assuming that because the tunnel is up, traffic must be encrypted, but it could be dropped by policy or routing before encryption.

608
Multi-Selecthard

A FortiGate is configured with a site-to-site IPsec VPN to a remote office. Users at the remote office report that they cannot access resources at the main office. The administrator checks the VPN status and sees that the tunnel is up. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)

Select 2 answers
A.Run 'diagnose debug application ike -1' to check for IKE errors.
B.Run 'diagnose vpn tunnel list' to view the tunnel status.
C.Restart the IPsec VPN tunnel by clearing the IKE gateway.
D.Run 'diagnose debug flow' with filters for the source and destination IPs.
E.Check the IPsec phase2 selectors to ensure they match the interesting traffic.
AnswersD, E

The debug flow command traces packet processing and can show if traffic is being dropped by a policy, routing issue, or other problem. Since the tunnel is up, the issue is likely with data traffic not being encrypted or decrypted correctly. Using debug flow with appropriate filters will help identify where the packets are being dropped.

Why this answer

Since the IPsec tunnel is up, the issue is likely with data traffic not being properly routed or encrypted. Using diagnose debug flow with filters will trace the packet path and reveal where packets are dropped. Checking phase2 selectors ensures that the traffic matches the encryption domain; mismatched selectors are a common cause of connectivity failures even when the tunnel is established.

Exam trap

The trap here is assuming that a tunnel being up means all traffic will pass, but phase2 selector mismatches or policy issues can still block traffic.

609
Multi-Selecthard

An administrator configures ZTNA with FortiClient EMS. The goal is to restrict access to an internal application based on device posture. The administrator configures a ZTNA tag for 'Compliant' that checks antivirus and OS patch status. Which TWO additional steps are required on the FortiGate to enforce access based on this tag?

Select 2 answers
A.Enable SSL deep inspection on the firewall policy
B.Create a ZTNA policy that includes the 'Compliant' tag as a required condition
C.Create a ZTNA access proxy for the internal application
D.Import the FortiClient EMS certificate to FortiGate
E.Configure a firewall policy with source set to the EMS connector
AnswersB, C

The tag alone enforces nothing; a ZTNA policy on the FortiGate must reference the 'Compliant' tag as a matching condition so posture status drives the allow or deny decision. Without this policy binding, the tag is merely reported by FortiClient EMS and never evaluated.

Why this answer

Option B is correct because the FortiGate enforces ZTNA tag-based posture by referencing the 'Compliant' tag as a matching condition inside a ZTNA policy (ztna-policy), which is what actually allows or denies the user's traffic based on device posture. Option C is correct because ZTNA on FortiGate requires a ZTNA access proxy (ztna access-proxy) that defines the protected internal application, its real server, and the listening/portal parameters; without it there is no ZTNA object for the policy to protect. Option A is not required because SSL deep inspection is a UTM/content-inspection feature and is not needed to match ZTNA tags.

Option D is not required because the FortiClient EMS certificate is used for EMS fabric authorization/connector trust, not for enforcing a ZTNA tag in the access policy. Option E is not required because a plain firewall policy with the EMS connector as source does not enforce ZTNA tag posture; tag enforcement is done through the ZTNA policy and access proxy.

Exam trap

NSE7 often tests the misconception that simply creating a ZTNA tag is sufficient, ignoring the need for a ZTNA policy and access proxy to enforce it.

610
MCQmedium

A FortiGate 600F is running in multi-VDOM mode with VDOMs named 'root', 'finance', and 'guest'. The administrator notices that a firewall policy created in the 'finance' VDOM does not appear when logging into the 'guest' VDOM and wants to confirm that policies, address objects, and routing tables are kept completely separate per VDOM. Which FortiGate feature provides this separation by default?

A.Per-VDOM configuration databases that store firewall policies, objects, and routing tables independently
B.Global VDOM configuration that synchronizes policies across all VDOMs
C.Virtual clustering that partitions the cluster into separate configuration domains
D.Administrative profiles that restrict which VDOMs an administrator can view
AnswerA

In multi-VDOM mode, each VDOM maintains its own independent configuration database, including firewall policies, address objects, services, and the routing table. This is why a policy created in the finance VDOM is invisible in the guest VDOM. The isolation is inherent to VDOM operation and requires no extra configuration, which matches what the administrator observed on the FortiGate 600F.

Why this answer

Each VDOM on a FortiGate keeps its own configuration database, so firewall policies, address objects, and routing tables are isolated by design. That is exactly why a policy built in the finance VDOM cannot be seen from the guest VDOM. Global configuration and administrative profiles affect management and shared objects but do not merge or split VDOM policy tables.

Exam trap

The trap here is assuming that global configuration objects synchronize firewall policies between VDOMs, when in fact global settings cover only a limited set of system and firewall objects, not per-VDOM policies.

611
Multi-Selecthard

A FortiGate administrator is implementing Zero Trust Network Access using ZTNA tags from FortiClient EMS to control access to internal applications. The administrator must ensure that devices losing compliance are denied access and that only managed endpoints can reach the applications. Which two configuration actions are required to meet these goals? (Choose two.)

Select 2 answers
A.Enable SSL VPN host checking and bind it to the same user group used by the ZTNA policy.
B.Configure a static route for the ZTNA application subnets pointing to the EMS connector interface.
C.Authorize the FortiGate on FortiClient EMS so it can receive endpoint compliance tags through the EMS connector.
D.Import the EMS server certificate into the FortiGate's local certificate store and set it as the ZTNA server certificate.
E.Create a ZTNA access-proxy policy that matches the EMS compliance tags and apply it to the ZTNA server rule.
AnswersC, E

The EMS connector on the FortiGate only receives dynamic endpoint tags after the FortiGate is authorized on FortiClient EMS. Without this authorization, the FortiGate cannot learn which endpoints are compliant, so tag-based ZTNA policies would never match. Authorizing the FortiGate is therefore a prerequisite for enforcing posture-driven access decisions in this scenario.

Why this answer

Enforcing posture-based ZTNA requires two things: the FortiGate must be authorized on FortiClient EMS so the EMS connector can deliver dynamic compliance tags, and a ZTNA access-proxy policy must match those tags to allow or deny application access. Together they ensure only compliant, managed endpoints reach the internal applications and that access is revoked when compliance is lost.

Exam trap

The trap here is focusing on certificates and routing for ZTNA when the actual enforcement depends on EMS authorization and tag matching in the access-proxy policy.

612
Multi-Selecthard

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which two actions should the administrator take to further diagnose and potentially resolve the issue? (Choose two.)

Select 2 answers
A.Run 'diagnose debug application ipsmonitor -1' to check for IPS engine restarts or errors.
B.Disable IPS inspection on all firewall policies to immediately reduce CPU usage.
C.Increase the FortiGate's memory allocation to the IPS engine via CLI.
D.Check the IPS sensor configuration for overly broad or resource-intensive signatures.
E.Restart the IPS engine using 'diagnose test application ipsmonitor 99' to clear the high CPU.
AnswersA, D

This command enables debugging for the IPS monitor daemon, which manages the IPS engine processes. It can reveal if the IPS engine is repeatedly restarting due to crashes or configuration issues, which would cause high CPU. The output may show messages about engine failures or memory problems, helping to identify the root cause.

Why this answer

To diagnose high CPU from the IPS engine, checking the ipsmonitor debug can reveal if the engine is crashing or restarting, which would cause repeated high CPU spikes. Additionally, reviewing the IPS sensor configuration for heavy signatures or excessive signatures can identify if the load is due to inspection complexity. Both actions target the root cause without compromising security.

Exam trap

The trap here is thinking that restarting the IPS engine or disabling IPS will solve the problem, when the real issue is often misconfiguration or signature overload that requires investigation.

613
MCQmedium

A FortiGate administrator uses FortiAnalyzer for log analysis and wants to identify all sessions that were blocked by a specific firewall policy ID 10. Which log filter should be applied?

A.Filter by 'action eq block' and then manually look for policy 10
B.Filter by 'policyid == 10'
C.Filter by 'policyid eq 10'
D.Filter by 'devid contains 10'
AnswerC

Correct. Using 'policy_id = 10' directly filters for all sessions handled by policy ID 10, including those blocked, using the accepted '=' operator.

Why this answer

The correct filter to identify sessions from a specific policy in FortiAnalyzer is 'policyid eq 10'. This uses the proper field name 'policyid' and the 'eq' operator. Option B uses '==' which is invalid, and option C uses the incorrect field name 'policy_id'.

614
MCQeasy

Which SD-WAN load balancing algorithm distributes new sessions based on the number of active sessions on each link?

A.Source-dest IP
B.Spillover
C.Volume
D.Sessions
AnswerD

The sessions algorithm counts currently active sessions per member and assigns each new session to the link with the fewest, directly satisfying the stem's requirement to balance on active session counts rather than bandwidth, volume or fixed hashing.

Why this answer

The Sessions algorithm distributes new sessions based on the current number of active sessions on each SD-WAN link. When a new session is initiated, the SD-WAN controller selects the link with the fewest active sessions, ensuring a balanced load across all available transport interfaces. This is distinct from algorithms that consider source/destination IP pairs, traffic volume, or bandwidth thresholds.

Exam trap

The trap here is that candidates often confuse 'Sessions' with 'Volume' because both involve load balancing, but Sessions counts active connections while Volume measures data throughput, leading to incorrect selection of Volume when the question explicitly mentions 'number of active sessions'.

How to eliminate wrong answers

Option A is wrong because Source-dest IP uses a hash of the source and destination IP addresses to consistently map sessions to a specific link, not the number of active sessions. Option B is wrong because Spillover is a bandwidth-based algorithm that shifts traffic to another link only when a predefined bandwidth threshold is exceeded, not based on session count. Option C is wrong because Volume distributes traffic based on the total volume of data (bytes) transmitted over each link, not the number of active sessions.

615
Drag & Dropmedium

Drag and drop the steps to configure a FortiGate as a DNS server (DNS proxy) into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Enable DNS proxy, set interface and port, configure upstream, set caching, then allow traffic.

616
MCQmedium

An admin wants to ensure that office documents (e.g., Word, Excel) downloaded from the internet are safe before users open them. Which feature should be used to remove potentially malicious macros and active content?

A.Machine learning engine
B.Content Disarm and Reconstruction (CDR)
C.Antivirus pattern matching
D.FortiSandbox file submission
AnswerB

CDR strips macros and active content from documents and rebuilds a clean, safe version, so users still receive usable files. This satisfies the requirement to neutralise malicious macros before opening, unlike signature-based scanning, which only detects known threats.

Why this answer

Content Disarm and Reconstruction (CDR) is the correct feature because it proactively removes potentially malicious macros, scripts, and active content from office documents by stripping the original file's active elements and rebuilding a safe, sanitized version. Unlike detection-based methods, CDR eliminates threats before the file reaches the user, ensuring that even unknown or zero-day macro-based attacks are neutralized.

Exam trap

The trap here is that candidates often confuse CDR with sandboxing or signature-based detection, mistakenly thinking that analyzing or scanning a file is sufficient to ensure safety, when in fact only CDR actively removes the threat vector (macros/active content) from the document itself.

How to eliminate wrong answers

Option A is wrong because the Machine Learning engine is a detection-based technology that identifies threats by analyzing file characteristics and behavior patterns, but it does not remove macros or active content from documents—it only flags or blocks files based on risk scores. Option C is wrong because Antivirus pattern matching relies on signature databases to detect known malware, which cannot protect against unknown or polymorphic macro-based attacks that have no existing signature. Option D is wrong because FortiSandbox file submission is a dynamic analysis tool that detonates files in a sandboxed environment to observe malicious behavior, but it does not sanitize or reconstruct the document; it only provides a verdict after execution, which still requires the user to open the original file if no threat is detected.

617
MCQmedium

You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?

A.The session has been idle for 7200 seconds
B.The session helper is interfering with the session
C.The session has been alive for 7200 seconds and will expire in 3600 seconds
D.The session has already expired
AnswerC

Session duration counts elapsed time since establishment, while expire time counts remaining seconds before teardown. A duration of 7200 with expire time of 3600 therefore means the session has existed for two hours and will close in one more.

Why this answer

The 'duration' field in the 'diagnose sys session filter' output shows how long the session has been active (7200 seconds), while the 'expire' field indicates the remaining time before the session times out (3600 seconds). Option C correctly interprets both values. This is standard FortiGate session table behavior, where each session has a configurable timeout (e.g., default TCP timeout is 3600 seconds for established sessions).

Exam trap

The trap here is confusing 'duration' with 'idle time' — candidates often assume duration measures inactivity, but FortiGate's session table uses separate fields for idle time and total session age.

How to eliminate wrong answers

Option A is wrong because 'duration' measures total session lifetime, not idle time; idle time is tracked separately via the 'idle' field in the session output. Option B is wrong because session helpers (e.g., ALG for SIP or FTP) do not cause a discrepancy between duration and expire time; they modify session behavior but are not indicated by these two fields alone. Option D is wrong because an expired session would not appear in the session list; the expire time of 3600 seconds means the session is still active and will expire in one hour.

618
Multi-Selectmedium

A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing an internal web application. The administrator wants to ensure that only users who have authenticated and whose devices meet posture requirements can reach the application, and that the application itself is never directly exposed to the internet. Which two FortiGate configuration steps are required to achieve this? (Choose two.)

Select 2 answers
A.Create a firewall policy that matches ZTNA traffic and enforces user authentication and device posture via EMS tags.
B.Configure a site-to-site IPsec VPN between the remote user's device and the FortiGate.
C.Publish the internal application through a public IP with a DNAT VIP so remote users can connect directly.
D.Enable inline CASB on the policy to inspect SaaS application usage.
E.Configure a ZTNA server that maps an external FQDN to the internal application and references a server certificate.
AnswersA, E

The firewall policy is where authentication and posture enforcement are applied. By matching ZTNA traffic and referencing user groups plus FortiClient EMS tags, the policy ensures only authenticated and compliant devices are permitted. This is the enforcement point that ties identity and posture to access, which is central to the Zero Trust requirement.

Why this answer

ZTNA requires a ZTNA server to define the external FQDN and internal application mapping with a server certificate, and a firewall policy to enforce authentication and device posture using user groups and FortiClient EMS tags. Together these broker access without exposing the application directly to the internet.

Exam trap

The trap here is thinking that publishing the application via a DNAT VIP is part of ZTNA, when ZTNA specifically avoids direct exposure.

619
MCQmedium

An administrator wants to use FortiManager to manage multiple FortiGates, each in a separate customer environment. The administrator needs to isolate configuration changes per customer and ensure each customer's admin can only see their own devices. What FortiManager feature should be used?

A.Administrative domains (ADOMs)
B.Administrator profiles
C.Policy packages
D.VDOMs on managed FortiGates
AnswerA

Administrative domains partition FortiManager into isolated management spaces, so each customer's devices, policies and objects stay separate. Per-ADOM administrator accounts then restrict visibility to that domain only, satisfying the requirement that each customer's admin sees solely their own FortiGates.

Why this answer

Administrative Domains (ADOMs) in FortiManager allow the administrator to logically partition the management plane, isolating configuration changes per customer. Each ADOM can contain a set of FortiGates, and administrators assigned to an ADOM can only see and manage devices within that ADOM, ensuring strict separation of customer environments.

Exam trap

The trap here is that candidates often confuse VDOMs (a FortiGate-level virtualization feature) with ADOMs (a FortiManager-level management isolation feature), assuming that VDOMs on the managed devices can provide the administrative separation required at the FortiManager level, but VDOMs only virtualize the firewall itself, not the management plane in FortiManager.

How to eliminate wrong answers

Option B (Administrator profiles) is wrong because administrator profiles define permissions (read/write/access control) for a user but do not isolate which devices or configurations the user can see; they work in conjunction with ADOMs but cannot provide device-level isolation alone. Option C (Policy packages) is wrong because policy packages are containers for firewall policies that can be assigned to ADOMs or devices, but they do not enforce administrative isolation between customers; they are a configuration object, not a management boundary. Option D (VDOMs on managed FortiGates) is wrong because VDOMs are a FortiGate feature for virtualizing a single FortiGate into multiple logical firewalls, not a FortiManager feature for isolating management of multiple FortiGates; FortiManager uses ADOMs to manage VDOMs across devices, but VDOMs themselves do not provide the administrative separation required at the FortiManager level.

620
MCQhard

A FortiGate with FortiExtender is using LTE as a backup WAN link. When the primary link fails, the LTE link does not take over. What could be the cause?

A.The primary link's performance SLA is still passing.
B.The FortiExtender is not configured in pass-through mode.
C.The FortiExtender firmware is out of date.
D.The LTE interface is not added as an SD-WAN member.
AnswerD

SD-WAN only steers traffic across members of the virtual WAN link. If the LTE interface is not added as an SD-WAN member, the failover rule cannot select it, so the backup link never activates when the primary fails.

Why this answer

For an LTE interface to be used as a backup WAN link in an SD-WAN setup, it must be explicitly added as an SD-WAN member. Without this, the FortiGate will not consider the LTE interface for traffic steering or failover, even if the primary link fails. The SD-WAN rules and performance SLA are only evaluated against interfaces that are members of the SD-WAN zone.

Exam trap

The trap here is that candidates often assume any working backup interface will automatically take over when the primary fails, but FortiGate SD-WAN requires explicit membership in the SD-WAN zone for failover to occur.

How to eliminate wrong answers

Option A is wrong because if the primary link's performance SLA is still passing, the SD-WAN logic would not trigger a failover to the backup link; the LTE link would not take over because the primary is considered healthy. Option B is wrong because pass-through mode is relevant for extending the FortiGate's interfaces via the FortiExtender, but it is not a prerequisite for LTE failover; the LTE interface can be used in normal mode as long as it is properly configured and added to SD-WAN. Option C is wrong while outdated firmware can cause various issues, the most direct and common reason for LTE not taking over is that the interface is not a member of the SD-WAN zone, not a firmware version problem.

621
MCQmedium

A FortiGate administrator is configuring a ZTNA rule to protect an internal web server. The administrator wants to ensure that only users who authenticate via SAML and whose devices have the latest antivirus signature are allowed access. Which FortiGate feature must be used to enforce this?

A.Firewall policy with user authentication and antivirus scanning.
B.ZTNA proxy policy with user group and device posture check.
C.SSL VPN with host checking and SAML authentication.
D.IPsec VPN with extended authentication (XAuth) and FortiClient compliance.
AnswerB

A ZTNA proxy policy allows the administrator to combine user authentication (via SAML) and device posture checks (such as antivirus signature version). This policy enforces access based on both identity and device compliance, meeting the requirement. It is the core component for ZTNA access control.

Why this answer

To enforce both SAML authentication and device posture checks for application access, the administrator must use a ZTNA proxy policy. This policy integrates with FortiClient EMS to receive device tags and enforces access based on user group and posture. Other options either provide broader network access or lack the granular application-level control required.

Exam trap

The trap here is assuming that SSL VPN host checking is equivalent to ZTNA posture checks, but ZTNA provides application-specific access with EMS integration.

622
MCQeasy

What is the purpose of FortiDeceptor in an enterprise security architecture?

A.To simulate real assets and detect attackers attempting to interact with decoys
B.To provide VPN access for remote users
C.To encrypt all data at rest on endpoints
D.To block all inbound traffic from suspicious IP addresses
AnswerA

FortiDeceptor deploys decoys that emulate genuine assets such as servers and services. Attackers interacting with these decoys trigger alerts, revealing compromise attempts early. This deception-based detection satisfies the requirement to simulate real assets and detect attackers engaging with them.

Why this answer

FortiDeceptor is a deception-based threat detection solution that deploys decoys (simulated real assets like servers, databases, or IoT devices) across the network. When an attacker probes or interacts with these decoys, FortiDeceptor generates high-fidelity alerts, enabling early detection of lateral movement or reconnaissance without relying on signatures. This aligns with the Advanced Threat Protection domain by shifting from reactive blocking to proactive deception.

Exam trap

The trap here is that candidates confuse FortiDeceptor's deception-based detection with traditional prevention mechanisms like firewalls or VPNs, assuming it blocks threats directly rather than detecting them through interaction with decoys.

How to eliminate wrong answers

Option B is wrong because FortiDeceptor does not provide VPN access; that is the function of FortiClient or FortiGate's IPsec/SSL VPN capabilities. Option C is wrong because FortiDeceptor does not encrypt data at rest on endpoints; endpoint encryption is typically handled by solutions like FortiClient with full disk encryption or third-party tools. Option D is wrong because FortiDeceptor does not block inbound traffic from suspicious IPs; that is the role of FortiGate's firewall policies, IPS, or FortiGuard IP reputation filtering.

623
MCQmedium

A FortiGate administrator is configuring a web filter profile to block access to known malicious websites. The administrator wants to ensure that the firewall blocks sites based on FortiGuard category 'Malicious Websites' and also logs the blocked attempts. Which action should the administrator take?

A.Create a web filter profile with the 'Malicious Websites' category set to 'Block' and apply it to a firewall policy with logging enabled.
B.Enable 'Block malicious URLs' in the antivirus profile and apply it to the firewall policy.
C.Create a firewall address object for the malicious websites and add it to a deny policy.
D.Create a DNS filter profile with the 'Malicious Websites' category set to 'Block' and apply it to a firewall policy.
AnswerA

Setting the 'Malicious Websites' category to 'Block' in the web filter profile will block those sites. Applying it to a firewall policy enables enforcement. Enabling logging on the policy or profile ensures blocked attempts are recorded. This directly fulfills both requirements.

Why this answer

Using a web filter profile with the 'Malicious Websites' category set to block, applied to a firewall policy with logging, ensures both blocking and logging of attempts. DNS filter is not the right profile for this category, antivirus does not handle URL blocking, and static address objects cannot replace dynamic FortiGuard categories.

Exam trap

The trap here is confusing DNS filter with web filter for category-based blocking, or thinking antivirus handles URL blocking.

624
MCQmedium

An administrator configures SD-WAN with two members (wan1, wan2) and a performance SLA for ICMP to 1.1.1.1. The SD-WAN rule is set to 'Best Quality' with 'latency' metric. The admin notices that traffic sometimes switches to the other link even when the current link has acceptable latency. Which action can reduce unnecessary flapping?

A.Configure a hysteresis value for the SLA
B.Increase the SLA probe interval
C.Use 'manual' strategy instead
D.Increase the 'update-cascade-interface' setting
AnswerA

Hysteresis adds a buffer so the SLA must degrade beyond a threshold before traffic moves, and must improve beyond another before it returns. This dampens metric jitter around the latency boundary, preventing unnecessary link flapping.

Why this answer

Configuring a hysteresis value for the SLA introduces a buffer or deadband around the latency threshold. This prevents the SD-WAN from switching links when latency fluctuates slightly above and below the threshold, which is the root cause of flapping. Without hysteresis, even a minor transient spike in latency can trigger a switch, even if the link's overall performance is acceptable.

Exam trap

The trap here is that candidates often confuse 'hysteresis' with 'increasing the probe interval' (Option B), thinking that less frequent measurements will reduce flapping, but hysteresis is the correct mechanism because it introduces a deadband to prevent switching on minor fluctuations, whereas a longer interval only delays detection and does not prevent the oscillation.

How to eliminate wrong answers

Option B is wrong because increasing the SLA probe interval reduces the frequency of measurements, which can delay the detection of actual link degradation but does not prevent flapping caused by minor latency fluctuations around the threshold. Option C is wrong because using a 'manual' strategy would disable automatic link selection based on SLA metrics entirely, which is an overreaction and does not address the flapping issue while sacrificing the benefits of dynamic path selection. Option D is wrong because 'update-cascade-interface' is a FortiGate setting related to updating routing tables when an interface's status changes, not a mechanism to dampen SLA-triggered path switching.

625
MCQmedium

An admin receives an email from FortiMail regarding a message that was rejected due to SPF failure. What does this indicate about the email?

A.The email's From address domain does not match the sending server's IP per the domain's SPF record
B.The email's DKIM signature is invalid
C.The email contains a virus
D.The email is missing a Message-ID header
AnswerA

SPF checks the envelope sender domain against the sending IP.

Why this answer

SPF (Sender Policy Framework) validation checks whether the sending mail server's IP address is authorized to send mail for the domain in the envelope 'From' (RFC 5321.MailFrom) or the header 'From' address. When FortiMail rejects a message due to SPF failure, it means the IP of the connecting server does not match any of the authorized IPs listed in the domain's SPF TXT record (as defined in RFC 7208). This is a direct authentication failure, not a content-based or signature-based issue.

Exam trap

The trap here is that candidates often confuse SPF with DKIM or assume SPF validates the 'From' header domain, when in fact SPF validates the envelope sender domain (Return-Path) against the connecting IP, and a failure does not imply the message is malicious—only that it failed an authorization check.

How to eliminate wrong answers

Option B is wrong because DKIM (DomainKeys Identified Mail) uses a digital signature to verify message integrity and domain association, not the sending server's IP; an SPF failure is unrelated to DKIM signature validity. Option C is wrong because SPF failure indicates a sending server authorization problem, not the presence of a virus; antivirus scanning is a separate content inspection process. Option D is wrong because a missing Message-ID header is a formatting issue that may affect message threading or compliance but is not checked by SPF; SPF operates at the transport level, not on header completeness.

626
MCQhard

An administrator is troubleshooting a FortiGate that is dropping traffic from a specific VLAN. The administrator runs 'diagnose debug flow' with a filter for the VLAN's subnet and sees the trace terminate with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?

A.The FortiGate is dropping the traffic because the destination route is missing from the routing table.
B.The traffic is being dropped because the VLAN interface is administratively down.
C.The traffic is being dropped by the NP7 processor because the session is not offloaded.
D.The traffic is being denied by a firewall policy or by the implicit deny, because no matching policy was found during the ingress policy check.
AnswerD

The 'iprope_in_check() check failed, drop' message appears when the ingress policy lookup finds no matching policy to permit the traffic, so it falls through to the implicit deny. This is a policy-ordering or policy-matching problem, often caused by a wrong address object, service, or missing policy for that VLAN subnet. The administrator should verify policy order and object definitions.

Why this answer

The iprope_in_check failure in the flow trace indicates the ingress policy lookup found no matching policy, so the packet hit the implicit deny. The administrator should inspect policy order, address objects, and service definitions for the VLAN subnet. Routing, NP7 offload, and interface state produce different symptoms and would not yield this specific message.

Exam trap

The trap here is reading any flow-trace drop as a routing problem, when iprope_in_check specifically points to a firewall policy match failure.

627
MCQeasy

What is the primary benefit of using FortiClient with ATP features in conjunction with FortiGate?

A.It allows users to bypass security policies
B.It replaces the need for a firewall
C.It enables endpoint detection and response with automated quarantine through FortiGate
D.It provides a single sign-on portal for all users
AnswerC

FortiClient's ATP integration feeds endpoint telemetry to FortiGate, which correlates it with network traffic to detect compromised hosts. On detection, FortiGate enforces automated quarantine, isolating the endpoint at the network layer. This satisfies the stem's requirement for coordinated endpoint detection and response, rather than standalone antivirus or manual remediation.

Why this answer

FortiClient with ATP (Advanced Threat Protection) features, such as Antivirus, Web Filtering, and Vulnerability Scan, integrates with FortiGate via the FortiTelemetry protocol. This integration enables endpoint detection and response (EDR) capabilities, allowing FortiGate to automatically quarantine compromised endpoints based on telemetry and threat intelligence from FortiClient, thereby containing threats at the network edge.

Exam trap

The trap here is that candidates often confuse FortiClient's ATP features with basic VPN or compliance-only modes, overlooking the automated quarantine and EDR integration that requires FortiTelemetry and Security Fabric coordination.

How to eliminate wrong answers

Option A is wrong because FortiClient with ATP does not bypass security policies; instead, it enforces and augments them by providing endpoint compliance and threat telemetry to FortiGate. Option B is wrong because FortiClient does not replace the need for a firewall; it works as a complementary endpoint security agent, while FortiGate remains the core network firewall enforcing access control and inspection. Option D is wrong because FortiClient does not provide a single sign-on portal; SSO is typically handled by FortiAuthenticator or FSSO agents, not by FortiClient ATP features.

628
MCQmedium

An administrator wants to detect lateral movement and early stages of an attack using decoy systems that mimic production assets. Which Fortinet product should they deploy?

A.FortiSIEM
B.FortiEDR
C.FortiNDR
D.FortiDeceptor
AnswerD

FortiDeceptor deploys decoy systems that mimic production assets, luring attackers into revealing themselves during reconnaissance and lateral movement. Its deception-based detection satisfies the requirement to catch early-stage attack activity, unlike signature or behaviour-based tools that only flag known or anomalous traffic after compromise.

Why this answer

FortiDeceptor is specifically designed to detect lateral movement and early-stage attacks by deploying decoy systems (honeypots) that mimic production assets. It uses deception technology to lure attackers away from real targets and trigger alerts when decoys are probed or compromised, enabling early threat detection without impacting production systems.

Exam trap

The trap here is that candidates may confuse FortiDeceptor with FortiNDR or FortiEDR because all three involve threat detection, but only FortiDeceptor uses active decoy systems to mimic production assets for deception-based detection.

How to eliminate wrong answers

Option A is wrong because FortiSIEM is a security information and event management solution that aggregates logs and correlates events, but it does not deploy decoy systems or actively mimic production assets for deception. Option B is wrong because FortiEDR is an endpoint detection and response solution that protects endpoints via behavioral analysis and threat hunting, but it does not create decoy systems or honeypots to simulate production assets. Option C is wrong because FortiNDR is a network detection and response solution that analyzes network traffic for anomalies and threats using machine learning, but it does not deploy decoy systems or mimic production assets for deception-based detection.

629
MCQhard

A company uses FortiWeb to protect its web application. They want to block SQL injection attempts. Which FortiWeb feature should be configured to inspect HTTP requests for malicious SQL patterns?

A.URL Access Rule
B.Web Application Firewall (WAF) Signatures
C.HTTP Protocol Constraint
D.IP List
AnswerB

WAF signatures match known SQL injection patterns such as UNION SELECT and tautologies within HTTP request parameters, blocking those requests before they reach the application. This satisfies the requirement to inspect requests for malicious SQL patterns, which generic firewall rules cannot parse.

Why this answer

FortiWeb's WAF Signatures (option B) are specifically designed to inspect HTTP request payloads for known attack patterns, including SQL injection signatures. This feature uses a regularly updated signature database to match malicious SQL syntax (e.g., UNION, OR 1=1) within GET/POST parameters, cookies, or headers, making it the correct choice for blocking SQL injection attempts.

Exam trap

The trap here is that candidates confuse 'HTTP Protocol Constraint' (which only checks protocol compliance) with content inspection features like WAF Signatures, leading them to select option C instead of B.

How to eliminate wrong answers

Option A is wrong because URL Access Rules control access based on URL patterns or source IPs, not by inspecting request content for SQL injection patterns. Option C is wrong because HTTP Protocol Constraints enforce RFC compliance (e.g., header length, method restrictions) and do not perform content-level pattern matching for SQL injection. Option D is wrong because IP Lists allow or block traffic based on source IP addresses, with no capability to analyze the payload for malicious SQL syntax.

630
Multi-Selectmedium

An administrator is configuring FortiDeceptor to detect threats within the network. Which TWO statements about FortiDeceptor are correct?

Select 2 answers
A.It requires a separate hardware appliance for each network segment
B.It sends alerts to FortiSIEM or FortiSOAR for automated response
C.It uses decoys and lures to attract attackers
D.It uses signature-based detection to identify malware
E.It can replace firewall functionality
AnswersB, C

Integration with SIEM/SOAR enables automated response to detected threats.

Why this answer

FortiDeceptor integrates with FortiSIEM and FortiSOAR to automatically trigger incident response workflows when a threat is detected. This integration allows security teams to quickly contain and remediate attacks without manual intervention, leveraging the Fortinet Security Fabric's automation capabilities.

Exam trap

The trap here is that candidates may confuse FortiDeceptor's deception-based detection with traditional signature-based IDS/IPS, leading them to incorrectly select option D, or assume it requires dedicated hardware per segment (option A) due to misunderstanding its deployment flexibility.

631
Multi-Selectmedium

A FortiGate administrator is troubleshooting a scenario where traffic between two VDOMs is not working. The admin has configured inter-VDOM routing. Which TWO steps should the administrator verify? (Choose two.)

Select 2 answers
A.Check that NAT is enabled on the policies
B.Check that there is a firewall policy in the destination VDOM allowing the return traffic
C.Check that the inter-VDOM link is configured as a physical interface
D.Check that there is a firewall policy in the source VDOM allowing traffic to the destination VDOM
E.Check that both VDOMs are in the same administrative VDOM
AnswersB, D

Because FortiGate evaluates policies in both directions, the destination VDOM requires a policy allowing the return traffic back toward the source VDOM across the inter-VDOM link. Missing it breaks the reply path, so the session fails despite correct forward routing.

Why this answer

Inter-VDOM routing requires firewall policies in both the source and destination VDOMs to permit traffic. The destination VDOM must have a policy allowing the return traffic (from the destination to the source) for the session to be established. Without this, the FortiGate will drop the return packets, breaking the bidirectional flow.

Exam trap

The trap here is that candidates assume a single policy in the source VDOM is sufficient, overlooking that inter-VDOM routing requires explicit policies in both VDOMs to allow the forward and return traffic.

632
MCQeasy

A FortiGate is configured with OSPF multi-area. The administrator wants to ensure that routes from area 0 are redistributed into area 1. Which OSPF configuration is required?

A.Enable 'redistribute connected' on the ABR
B.Set the 'area type' to 'nssa' on area 1
C.Configure a route redistribution policy under OSPF
D.No additional configuration is needed; ABRs automatically advertise inter-area routes
AnswerD

Area Border Routers automatically generate and advertise inter-area routes, including those from the backbone, into attached non-backbone areas. Because area 0 routes are injected into area 1 by default, no redistribution or extra OSPF configuration is required to satisfy the stem.

Why this answer

OSPF ABRs (Area Border Routers) automatically advertise inter-area routes between areas by default. In a multi-area OSPF setup, the ABR learns Type 3 LSAs from area 0 and floods them into other areas (like area 1) without any additional redistribution configuration. No explicit redistribution policy is needed for inter-area route advertisement.

Exam trap

The trap here is that candidates confuse route redistribution (importing external routes) with the automatic inter-area route advertisement performed by ABRs, leading them to select options involving redistribution policies or area type modifications.

How to eliminate wrong answers

Option A is wrong because 'redistribute connected' is used to inject directly connected routes into OSPF, not to advertise routes between areas; inter-area routes are handled natively by ABRs via Type 3 LSAs. Option B is wrong because setting area 1 as NSSA would actually restrict Type 5 LSAs and require special handling for external routes, but it does not affect the automatic advertisement of inter-area routes from area 0; in fact, NSSA still allows Type 3 LSAs by default. Option C is wrong because a route redistribution policy under OSPF is used for importing routes from other protocols (e.g., BGP, static) or from different OSPF processes, not for inter-area route propagation within the same OSPF domain.

633
MCQmedium

A FortiGate is configured with SD-WAN and multiple members. The administrator notices that traffic to a critical application is consistently routed over a low-quality link, even though a better link is available. The SD-WAN rule uses the 'Best Quality' strategy with a performance SLA. What is the most likely reason?

A.The better link is failing its SLA probes
B.The better link is in 'standby' mode
C.The SD-WAN rule is using source-based routing
D.The application traffic is not matching the SD-WAN rule
AnswerA

Under Best Quality, SD-WAN selects members by measured SLA performance. If the superior link fails its performance SLA probes, it is marked out of SLA and excluded, so traffic falls back to the remaining member despite that link's better raw capacity.

Why this answer

When an SD-WAN rule uses the 'Best Quality' strategy with a performance SLA, the FortiGate selects the member link that best meets the SLA targets (e.g., jitter, latency, packet loss). If the better link is failing its SLA probes, it is considered out of compliance and will not be selected, even if it is physically available and has higher bandwidth. This causes traffic to be routed over the lower-quality link that still passes the SLA.

Exam trap

The trap here is that candidates assume 'Best Quality' always picks the link with the highest bandwidth or lowest cost, when in fact it strictly selects based on SLA compliance, not raw capacity or administrative preference.

How to eliminate wrong answers

Option B is wrong because a link in 'standby' mode is only used for failover when all active links fail; it would not be considered a 'better link' that is available for selection under normal SD-WAN rules. Option C is wrong because source-based routing is a different strategy that ignores SLA performance; the question explicitly states the rule uses 'Best Quality' with a performance SLA, so source-based routing is not in effect. Option D is wrong because if the application traffic were not matching the SD-WAN rule, it would be handled by the regular routing table or policy-based routing, not consistently routed over a low-quality link via the SD-WAN rule.

634
MCQeasy

In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?

A.FortiClient agent
B.FortiAnalyzer
C.FortiGate ZTNA gateway
D.FortiClient EMS
AnswerC

The FortiGate ZTNA gateway terminates the client tunnel and enforces access policy per session, granting or denying each request to internal applications. It is the enforcement point, while the EMS or fabric connector supplies identity and posture context used in those decisions.

Why this answer

In a Zero Trust Network Access (ZTNA) architecture, the FortiGate ZTNA gateway acts as the policy enforcement point (PEP). It terminates encrypted ZTNA tunnels from FortiClient agents, inspects traffic against configured access policies, and enforces decisions based on identity, device posture, and context. This is distinct from the control plane (FortiClient EMS) or logging (FortiAnalyzer).

Exam trap

The trap here is that candidates confuse the ZTNA gateway (PEP) with the EMS (controller) or FortiClient (client), but only the gateway sits inline and enforces access decisions based on the ZTNA access proxy protocol.

How to eliminate wrong answers

Option A is wrong because FortiClient is the ZTNA client that initiates connections and reports device posture, not the enforcement point. Option B is wrong because FortiAnalyzer is a logging and analytics platform that collects logs and generates reports, not a real-time policy enforcement component. Option D is wrong because FortiClient EMS is the management server that distributes ZTNA configurations and verifies device compliance, but it does not enforce access decisions inline.

635
MCQeasy

A company wants to ensure that only company-managed laptops with up-to-date antivirus can access the internal file server remotely. Which Fortinet solution integrates with FortiGate to enforce device compliance before granting ZTNA access?

A.FortiClient EMS
B.FortiAnalyzer
C.FortiSandbox
D.FortiWeb
AnswerA

FortiClient EMS integrates with FortiGate to enforce ZTNA device compliance, checking endpoint posture such as antivirus status and management ownership before granting access. It satisfies the stem's constraint that only company-managed laptops with up-to-date antivirus reach the internal file server remotely, using endpoint telemetry tags rather than network location.

Why this answer

FortiClient EMS is the endpoint management server that maintains compliance posture (antivirus status, OS patch level, running processes) for managed endpoints and shares that information with FortiGate via the ZTNA fabric. FortiGate consults EMS tags and compliance rules before allowing a device to reach the internal file server, so only compliant company-managed laptops pass the ZTNA access check.

Exam trap

NSE7 often tests the confusion between logging/analytics appliances (FortiAnalyzer), sandboxing (FortiSandbox), and WAFs (FortiWeb) versus the actual endpoint compliance authority — candidates who pick based on 'security product' familiarity rather than the specific ZTNA role will choose wrong.

How to eliminate wrong answers

Option B is wrong because FortiAnalyzer is a logging, analytics, and reporting appliance — it stores and correlates logs but does not manage endpoint compliance or participate in ZTNA access decisions. Option C is wrong because FortiSandbox is a threat-detection and sandboxing platform for suspicious files and URLs, not an endpoint compliance authority. Option D is wrong because FortiWeb is a web application firewall that protects published web apps from Layer 7 attacks; it does not enforce endpoint posture for ZTNA.

636
MCQmedium

An administrator is deploying a FortiGate in transparent mode to seamlessly integrate into an existing network. The administrator needs to manage the FortiGate remotely over the network. Which configuration is required?

A.Configure a management IP address under the VDOM settings
B.Create a VLAN interface and assign an IP
C.Assign an IP address to the physical interfaces
D.Enable DHCP client on the interfaces
AnswerA

Transparent mode forwards traffic without altering IP addressing, so the FortiGate has no routable interface for management access. Assigning a management IP under the VDOM settings provides a dedicated address reachable over the network, enabling remote administration without disrupting the transparent bridging path.

Why this answer

In transparent mode, FortiGate operates as a Layer 2 bridge and does not route traffic, so physical interfaces cannot have IP addresses. To enable remote management, a dedicated management IP must be configured under the VDOM settings, which allows the FortiGate to be reachable via protocols like HTTPS, SSH, or SNMP without participating in Layer 3 forwarding.

Exam trap

The trap here is that candidates often assume transparent mode still requires an IP on an interface (like a VLAN or physical port) for management, but FortiGate transparent mode uses a VDOM-level management IP that is not tied to any specific interface, which is a key distinction from routed mode.

How to eliminate wrong answers

Option B is wrong because creating a VLAN interface and assigning an IP is used in transparent mode only if the management IP is placed on a specific VLAN, but the question asks for the general requirement, and the management IP is configured under VDOM settings, not as a separate VLAN interface. Option C is wrong because assigning an IP address to physical interfaces is not allowed in transparent mode; interfaces remain unnumbered and operate at Layer 2. Option D is wrong because enabling DHCP client on interfaces is not applicable in transparent mode, as interfaces do not have IP addresses and the FortiGate does not obtain an IP via DHCP for management; the management IP is statically configured under VDOM settings.

637
Multi-Selectmedium

A company has deployed FortiClient with advanced threat protection (ATP) features. Which TWO capabilities does FortiClient ATP provide beyond basic antivirus?

Select 2 answers
A.Exploit prevention and vulnerability scanning
B.Application control and inventory
C.Real-time malware protection using machine learning
D.VPN connectivity
E.Web filtering and URL rating
AnswersA, C

FortiClient ATP includes exploit prevention and vulnerability assessment.

638
MCQeasy

An administrator is setting up a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own set of administrators and that administrators of one VDOM cannot view or modify settings in another VDOM. Which feature should the administrator configure to achieve this?

A.Role-based access control (RBAC) at the global level.
B.VDOM-specific administrator accounts with restricted profiles.
C.Administrative domains (ADOMs) on FortiManager.
D.Virtual clustering with separate management IPs per VDOM.
AnswerB

FortiGate allows you to create administrator accounts that are restricted to specific VDOMs. By assigning an administrator to a VDOM and using a profile with limited permissions, you can ensure that the administrator can only view and modify settings within that VDOM. This provides the required isolation. Each VDOM can have its own administrators, and they cannot access other VDOMs unless explicitly granted.

Why this answer

To isolate administrators per VDOM, you create administrator accounts that are restricted to specific VDOMs. Each administrator account can be assigned a profile that limits their permissions to only the VDOM they are responsible for. This ensures that administrators cannot view or modify settings in other VDOMs.

This is the standard method for achieving per-VDOM administrative separation on a FortiGate.

Exam trap

The trap here is confusing FortiManager ADOMs with FortiGate VDOM administrator restrictions; ADOMs manage devices, not VDOM-level admin access on a single FortiGate.

639
MCQmedium

An admin wants to block malicious files detected by FortiSandbox at the FortiGate level. Which configuration is required on the FortiGate to automatically block files based on FortiSandbox verdict?

A.Enable Threat Feeds on FortiGate and subscribe to FortiSandbox feeds
B.Enable 'FortiSandbox inline prevention' in the antivirus profile
C.Configure an Automation Stitch that triggers on malware detected events and blocks the source IP
D.Configure a security policy with a Web Filter profile that blocks malware categories
AnswerB

This setting allows the FortiGate to block files immediately based on FortiSandbox verdicts.

Why this answer

Enabling 'FortiSandbox inline prevention' in the antivirus profile allows FortiGate to automatically block files based on the verdict received from FortiSandbox. When this option is enabled, the FortiGate will hold the file until the sandbox analysis completes, then either allow or block the file based on the verdict (e.g., malware detected). This is the direct configuration for automatic file blocking at the gateway level.

Exam trap

The trap here is that candidates confuse reactive automation (Option C) with proactive inline prevention, or mistake web filtering (Option D) for file-based sandbox verdict enforcement.

How to eliminate wrong answers

Option A is wrong because Threat Feeds are used to consume external threat intelligence (e.g., IP reputation lists), not to block files based on FortiSandbox verdicts; FortiSandbox feeds are not a standard subscription for file blocking. Option C is wrong because an Automation Stitch that blocks the source IP after malware detection is a reactive, post-infection response, not a real-time file blocking mechanism at the FortiGate level. Option D is wrong because a Web Filter profile blocks URLs or web categories, not individual files based on sandbox verdicts; malware categories in web filtering are URL-based, not file-based.

640
MCQhard

In FortiManager, what is the purpose of an automation stitch?

A.To combine multiple ADOMs into a single management domain
B.To trigger automated actions based on predefined events
C.To automatically deploy configuration changes to devices
D.To stitch together multiple policy packages into one
AnswerB

An automation stitch pairs a trigger event with one or more automated actions, such as running a CLI script or sending an alert. It reacts to predefined events rather than scheduling or manually invoking tasks.

Why this answer

An automation stitch in FortiManager is a sequence of automated actions triggered by a predefined event, such as a log message, SNMP trap, or schedule. It allows administrators to define a set of actions (e.g., run a script, send an alert, or change a policy) that execute in response to specific conditions, streamlining incident response and network management without manual intervention.

Exam trap

The trap here is that candidates confuse automation stitches with FortiManager's automatic policy deployment or ADOM management features, mistakenly thinking the stitch is about pushing configurations or merging domains rather than event-driven reaction.

How to eliminate wrong answers

Option A is wrong because combining multiple ADOMs into a single management domain is not a function of an automation stitch; that is achieved through ADOM federation or merging, not through event-driven automation. Option C is wrong because automatically deploying configuration changes to devices is a broader capability of FortiManager's provisioning and policy installation workflows, not the specific purpose of an automation stitch, which focuses on reactive actions based on events. Option D is wrong because stitching together multiple policy packages into one is not a feature of automation stitches; policy package consolidation is done via policy import/export or manual merging, not through event-triggered automation.

641
MCQeasy

Which FortiClient feature is specifically designed to prevent the execution of unknown malware by analyzing behavior in real-time?

A.FortiClient Vulnerability Scan
B.FortiClient Application Firewall
C.FortiClient Web Filter
D.FortiClient AI Engine
AnswerD

FortiClient's AI Engine applies machine-learning behavioural analysis to executables in real time, detecting previously unknown malware by its runtime actions rather than static signatures. That satisfies the stem's requirement to block unknown malware through behaviour, which signature-based antivirus cannot do.

Why this answer

FortiClient AI Engine uses machine learning and behavioral analysis to detect and prevent unknown malware in real-time, without relying on signatures. Options A, B, and C address vulnerability scanning, application control, and web filtering respectively, none of which focus on real-time behavior analysis for unknown threats.

642
Multi-Selectmedium

An administrator wants to protect against zero-day malware that has not yet been discovered by signature-based detection. Which TWO technologies can help mitigate such threats?

Select 2 answers
A.Machine Learning Engine
B.Outbreak Prevention
C.Signature-based antivirus
D.Web filtering
E.Application control
AnswersA, B

ML engine analyzes file characteristics to detect unknown malware.

Why this answer

The Machine Learning Engine (A) is correct because it uses behavioral analysis and static file analysis to detect previously unknown malware based on patterns and anomalies, without relying on signatures. This allows it to identify zero-day threats by analyzing file characteristics and runtime behavior in real time.

Exam trap

The trap here is that candidates often confuse Outbreak Prevention with signature-based antivirus, but Outbreak Prevention uses cloud-based reputation and sandboxing, not static signatures, to block emerging threats.

643
MCQhard

A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?

A.The remote peer is rekeying the VPN tunnel
B.The local FortiGate has a mismatched pre-shared key
C.A dead peer detection timeout occurred
D.The remote peer has rebooted or restarted its VPN service
AnswerD

INITIAL_CONTACT is sent when an IKE peer starts without existing security associations, so repeated notifications mean the branch device or its VPN daemon is restarting, tearing down and renegotiating the tunnel. This directly explains the frequent outages observed on that branch VPN.

Why this answer

An INITIAL_CONTACT notification is sent by an IKE peer when it establishes a new IKE SA and wants the remote peer to delete any existing IKE SAs associated with the same identity. This is standard behavior after a reboot, VPN service restart, or when the peer loses its state and re-initiates from scratch. Repeated INITIAL_CONTACT messages therefore indicate the remote branch device is repeatedly restarting or flapping its VPN daemon, not a normal rekey or DPD event.

Exam trap

NSE7 often tests the distinction between IKE notification types, so candidates confuse INITIAL_CONTACT with rekey or DPD events and pick the wrong cause of tunnel flapping.

How to eliminate wrong answers

Option A is wrong because rekeying is signaled by CREATE_CHILD_SA or QUICK_MODE exchanges (or IKEv2 CREATE_CHILD_SA with REKEY_SA), not by INITIAL_CONTACT; rekeys preserve the existing IKE SA and do not trigger deletion of peer SAs. Option B is wrong because a pre-shared key mismatch causes AUTHENTICATION_FAILED or INVALID_ID_INFORMATION notifications during IKE_AUTH, not INITIAL_CONTACT. Option C is wrong because DPD timeouts produce DPD/R_U_THERE or IKEv2 liveness failures and eventual SA deletion, not an INITIAL_CONTACT from the remote peer.

644
MCQhard

A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?

A.Port2 is configured with a higher link priority value, causing it to be preferred over port1.
B.The 'lowest-cost (SLA)' strategy always selects the first member in the list when costs are equal.
C.Port2 is administratively down or has no active route, so it is excluded from the SD-WAN rule.
D.The SD-WAN rule is configured with 'set gateway enable', which forces traffic through the first member.
AnswerC

If port2 is administratively down or lacks a valid route, it cannot be used for traffic, even if it is within SLA. The FortiGate would then use only port1. This is a common reason for traffic to be sent exclusively over one member despite equal costs and SLA status.

Why this answer

In lowest-cost (SLA), traffic is distributed among members with the lowest cost that meet SLA. If port2 is down or has no route, it is removed from consideration, leaving port1 as the only viable member. Equal costs alone do not guarantee load sharing; operational status and routing must be valid.

Exam trap

The trap here is assuming that equal cost and SLA compliance automatically result in load balancing, ignoring the operational state of the interface or its routing.

645
MCQmedium

A FortiGate administrator is configuring ZTNA to protect an internal application and wants to ensure that only users who authenticate with a valid client certificate and whose devices pass posture checks can connect. The administrator has configured FortiClient EMS integration and a ZTNA access proxy rule. During testing, users without client certificates are still able to reach the application after providing username and password. Which setting should the administrator verify to enforce certificate-based authentication?

A.The firewall policy from the ZTNA server to the application must include a certificate-based user group.
B.The SSL VPN settings must be configured to require client certificates for ZTNA users.
C.The ZTNA access proxy rule must require client certificate authentication in its authentication settings.
D.The FortiClient EMS connector must be configured to issue client certificates to endpoints.
AnswerC

To enforce client certificates, the access proxy rule’s authentication configuration must explicitly require certificate authentication, typically by selecting the client certificate option and referencing the trusted CA. If only password authentication is enabled, users without certificates can still authenticate, so the certificate requirement is not enforced at the proxy.

Why this answer

Client certificate enforcement for ZTNA is controlled by the access proxy rule’s authentication settings. The rule must be configured to require certificate authentication and reference the trusted CA that signed the client certificates. If the rule only permits password authentication, users without certificates can still authenticate, so the certificate requirement is effectively absent regardless of EMS or backend policy configuration.

Exam trap

The trap here is conflating EMS posture management or SSL VPN certificate settings with ZTNA client certificate enforcement, which lives in the access proxy rule’s authentication configuration.

646
MCQeasy

An administrator wants to use FortiManager to push a new firewall policy to a managed FortiGate. Before installing, the administrator wants to review what changes will be applied. Which FortiManager feature should be used?

A.Install Preview
B.Policy & Objects - Install Wizard
C.Configuration Rollback
D.Revision History
AnswerA

Install Preview compares the policy package on FortiManager against the managed FortiGate's current configuration, displaying exactly which changes the install would apply. This lets the administrator review the diff before committing, satisfying the requirement to inspect changes prior to installation.

Why this answer

Install Preview (Option A) is the correct feature because it allows the administrator to see a detailed, side-by-side comparison of the current configuration on the managed FortiGate versus the pending changes that FortiManager will push. This preview is generated by FortiManager's policy compilation engine, which calculates the exact CLI commands and object modifications required to synchronize the device database (ADOM) with the managed FortiGate. It provides a safe, non-disruptive way to validate changes before committing them, reducing the risk of misconfiguration.

Exam trap

The trap here is that candidates often confuse the Install Wizard (which guides the installation process) with Install Preview (which shows the actual changes), leading them to select Option B thinking it includes a review step, but the Install Wizard does not generate a detailed diff of pending modifications.

How to eliminate wrong answers

Option B (Policy & Objects - Install Wizard) is wrong because the Install Wizard is used to select the target devices and initiate the actual installation of policies and objects, not to preview the specific changes that will be applied; it does not provide a granular diff view. Option C (Configuration Rollback) is wrong because rollback is a recovery mechanism used to revert a FortiGate to a previous configuration revision after an installation has occurred, not a tool for previewing pending changes. Option D (Revision History) is wrong because Revision History stores past configuration snapshots for audit and rollback purposes, but it does not show the delta between the current device state and the pending changes in FortiManager's database.

647
MCQhard

An administrator is troubleshooting a FortiGate that is experiencing intermittent packet loss for traffic passing through an IPsec VPN tunnel. The administrator wants to capture packets on the VPN interface to analyze the issue. Which command should the administrator use to capture packets on the IPsec tunnel interface named 'vpn1'?

A.diagnose debug application ike -1
B.diagnose sniffer packet port1 'host 10.1.1.1' 4
C.diagnose sniffer packet vpn1 'host 10.1.1.1' 4
D.diagnose sniffer packet any 'host 10.1.1.1' 4
AnswerC

This command captures packets on the 'vpn1' interface with a filter for host 10.1.1.1 and verbosity level 4, which provides detailed packet information including interface names. This is the correct syntax to capture traffic on a specific IPsec tunnel interface for troubleshooting packet loss.

Why this answer

To capture packets on a specific IPsec tunnel interface, the administrator should use 'diagnose sniffer packet <interface>' with the appropriate filter and verbosity. This allows capturing the decrypted traffic inside the tunnel, which is essential for analyzing packet loss. Capturing on the physical interface would only show encrypted packets.

Exam trap

The trap here is capturing on the physical interface or 'any' and assuming it will show the tunneled traffic, when in fact the VPN interface must be specified to see the decrypted packets.

648
MCQhard

An administrator runs the following CLI output: 'diagnose sys session filter dport 443' and sees 'proto=6 proto_state=01 duration=3600 expire=3599'. Which statement BEST describes the session?

A.The session is in the process of being torn down
B.The session is established and has been active for one hour
C.The session is a UDP session incorrectly classified as TCP
D.The TCP session is still in the SYN-SENT state
AnswerB

The `proto_state=01` flag confirms a TCP session in the established state, while `duration=3600` records 3600 seconds of activity — exactly one hour. The `expire=3599` value shows the session remains live with nearly its full idle timeout remaining, satisfying the stem's requirement to describe the session accurately.

Why this answer

The session shows 'proto=6' (TCP), 'proto_state=01' (TCP_ESTABLISHED), and 'duration=3600' seconds, which equals one hour. The 'expire=3599' indicates the session has 3599 seconds left before timeout, confirming it is active and established. Option B correctly identifies this as an established session that has been active for one hour.

Exam trap

The trap here is that candidates may misinterpret 'proto_state=01' as a starting state or teardown state, when in Fortinet's session table it specifically represents TCP_ESTABLISHED, and the combination of duration and expire values confirms the session is active and not in transition.

How to eliminate wrong answers

Option A is wrong because 'proto_state=01' indicates TCP_ESTABLISHED, not a teardown state; a session being torn down would show a state like TCP_FIN_WAIT or TCP_CLOSE. Option C is wrong because 'proto=6' explicitly indicates TCP, not UDP (which would be proto=17), and the state '01' is a valid TCP established state, not a misclassification. Option D is wrong because 'proto_state=01' corresponds to TCP_ESTABLISHED, not SYN-SENT (which would be state '02' or '03' depending on the Fortinet implementation); the session has already completed the three-way handshake.

649
MCQmedium

An administrator has configured an SD-WAN rule with the 'lowest-cost' strategy. The rule includes two members: port1 and port2. The administrator notices that all traffic is being sent over port1, even though port2 has a lower latency. Which factor is most likely causing this behavior?

A.The SD-WAN rule is configured with 'maximize-bandwidth' instead of 'lowest-cost'.
B.The cost of port1 is configured lower than the cost of port2.
C.Port2 is administratively down.
D.The performance SLA is not configured for port2.
AnswerB

In the 'lowest-cost' strategy, the FortiGate selects the member with the lowest cost. If port1 has a lower cost than port2, it will be chosen regardless of latency. The cost is a manual setting that can override performance metrics. This is the most likely reason for all traffic going over port1.

Why this answer

The 'lowest-cost' strategy selects the member with the lowest configured cost. Even if another member has better performance metrics like latency, the cost takes precedence. Therefore, if port1 has a lower cost than port2, it will be selected for all traffic.

Administrators must ensure costs are set appropriately to reflect the desired priority.

Exam trap

The trap here is assuming that the lowest-cost strategy considers latency, when it actually uses a manually configured cost value.

650
MCQmedium

An administrator has a FortiGate 600E running multiple VDOMs. The administrator wants to ensure that when a VDOM is deleted, all associated firewall policies, addresses, and routes are also removed to avoid orphaned objects. Which action should the administrator take?

A.Ensure the VDOM is not in use by any inter-VDOM links or management services, then delete it; associated objects are removed automatically.
B.Enable the 'vdom-delete-cascade' setting under system global.
C.Export the VDOM configuration, delete the VDOM, then re-import the configuration without the unwanted objects.
D.Manually delete all firewall policies, addresses, and routes in the VDOM before deleting the VDOM.
AnswerA

When you delete a VDOM on a FortiGate, FortiOS automatically deletes all configuration objects that belong to that VDOM, including firewall policies, addresses, and routes. However, you must first remove any dependencies such as inter-VDOM links or management services that reference the VDOM. This ensures a clean deletion without orphaned objects.

Why this answer

Deleting a VDOM in FortiOS automatically removes all associated configuration objects, but you must first eliminate dependencies like inter-VDOM links. This ensures no orphaned objects remain. The other options either invent non-existent settings, suggest unnecessary manual steps, or propose inefficient workarounds that do not align with FortiGate's native behavior.

Exam trap

The trap here is assuming that a global setting or manual cleanup is needed, when FortiOS automatically handles object deletion upon VDOM removal.

651
MCQmedium

A FortiGate is configured with two WAN interfaces in an SD-WAN zone. The administrator wants to ensure that Voice over IP (VoIP) traffic uses the link with the lowest latency, while all other traffic uses the link with the highest available bandwidth. The performance SLA 'VoIP_SLA' monitors latency to a VoIP provider. Which SD-WAN configuration should the administrator implement to meet these requirements?

A.Create an SD-WAN rule with the 'lowest-latency' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'lowest-cost' algorithm for all other traffic.
B.Create an SD-WAN rule with the 'lowest-cost' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'maximize-bandwidth' algorithm for all other traffic.
C.Create an SD-WAN rule with the 'lowest-latency' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'maximize-bandwidth' algorithm for all other traffic.
D.Create an SD-WAN rule with the 'lowest-jitter' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'maximize-bandwidth' algorithm for all other traffic.
AnswerC

The 'lowest-latency' algorithm selects the member with the lowest latency based on the performance SLA measurements. This directly meets the VoIP requirement. The second rule with 'maximize-bandwidth' selects the link with the highest bandwidth for other traffic, which also matches the requirement.

Why this answer

The correct configuration uses an SD-WAN rule with the 'lowest-latency' algorithm for VoIP traffic, which selects the WAN member with the lowest latency as measured by the performance SLA. For all other traffic, a rule with the 'maximize-bandwidth' algorithm selects the member with the highest available bandwidth. This combination satisfies both requirements.

Exam trap

The trap here is confusing latency with jitter or cost, and assuming that 'lowest-cost' is equivalent to 'lowest-latency'.

652
MCQhard

A FortiGate administrator is implementing ZTNA to control access to internal web applications. The administrator wants to ensure that only devices with a valid FortiClient EMS tag can access the applications. Which ZTNA component must be configured on the FortiGate to enforce this?

A.Firewall policy with a source user group synchronized from EMS.
B.SSL VPN portal with a host-check profile referencing the EMS tag.
C.ZTNA proxy policy with a device posture check referencing the EMS tag.
D.IPsec VPN tunnel with extended authentication using EMS tags.
AnswerC

ZTNA proxy policies on FortiGate can enforce device posture by referencing tags from FortiClient EMS. By configuring a proxy policy that includes a device posture check, the FortiGate verifies that the connecting device has the required EMS tag before granting access. This ensures that only compliant devices can reach the internal web applications, aligning with zero-trust principles.

Why this answer

ZTNA on FortiGate uses proxy policies to enforce access control at the application level. To restrict access based on device compliance, the administrator must configure a ZTNA proxy policy that includes a device posture check referencing the FortiClient EMS tag. This ensures that only devices with the correct tag are allowed, aligning with zero-trust access principles.

Exam trap

The trap here is assuming that SSL VPN host-check or firewall user groups can enforce device posture for ZTNA, when only ZTNA proxy policies with device posture checks provide that capability.

653
MCQmedium

An administrator has a FortiGate with multiple VDOMs in NAT mode. The administrator wants to configure a global policy that applies to all VDOMs to block traffic from a known malicious IP block. Which statement is correct about global policies?

A.Global policies are only evaluated after VDOM-specific policies, and they can only deny traffic.
B.Global policies require that all VDOMs are in transparent mode.
C.Global policies can only be applied to traffic entering the management VDOM.
D.Global policies are configured in the global VDOM and are evaluated before VDOM-specific policies.
AnswerD

Global policies are configured under the global settings, not within a specific VDOM, and they are evaluated before any VDOM-specific policies. This allows the administrator to enforce a consistent security rule across all VDOMs, such as blocking a malicious IP block, without having to replicate the policy in each VDOM.

Why this answer

Global policies are configured at the global level and are evaluated before any VDOM-specific policies. This allows an administrator to enforce a uniform security rule, such as blocking a malicious IP block, across all VDOMs without duplicating the policy in each VDOM. They can be used in both NAT and transparent mode VDOMs and can allow or deny traffic.

Exam trap

The trap here is assuming that global policies are evaluated after VDOM policies or that they can only deny traffic, when in fact they are processed first and can permit or block traffic.

654
Multi-Selectmedium

A FortiGate administrator is deploying a multi-VDOM setup for a service provider. The provider wants each customer VDOM to have its own administrative access, yet the overall device management (including firmware upgrades) should be centralized from the management VDOM. Which TWO statements are true regarding administrative VDOMs?

Select 2 answers
A.The management VDOM can be used to manage all other VDOMs
B.Traffic VDOMs cannot have any administrative access
C.Each VDOM must have a separate management IP address
D.The management VDOM is responsible for device-level functions like firmware upgrades
E.An administrator assigned to one VDOM can automatically view configurations of other VDOMs
AnswersA, D

A management VDOM centralises device-wide administration, letting the provider perform firmware upgrades and global configuration from one place while each customer VDOM retains its own separate administrative access. This satisfies the stem's requirement for centralised device management alongside per-customer administrative isolation, since the management VDOM holds the administrative scope over subordinate VDOMs.

Why this answer

Option A is correct because in a multi-VDOM FortiGate, the management VDOM is specifically designed to centrally administer and manage all other VDOMs, allowing the provider to oversee the entire device from one administrative domain. Option D is correct because device-level functions such as firmware upgrades, global settings, and system-wide operations are handled by the management VDOM, which is why centralized device management is possible. Option B is incorrect because traffic VDOMs can be configured with administrative access (for example, HTTPS, SSH, or Telnet on their interfaces) so each customer can manage its own VDOM.

Option C is incorrect because a separate management IP address per VDOM is not mandatory; administrative access can be enabled on existing interfaces, and the management VDOM itself provides centralized access. Option E is incorrect because administrators are scoped to their assigned VDOM and cannot automatically view other VDOMs' configurations unless they have the appropriate multi-VDOM or super-admin privileges.

Exam trap

The trap here is that candidates often assume traffic VDOMs cannot have any administrative access, but FortiGate allows per-VDOM admin accounts for delegated management, as long as the administrator is assigned to that specific VDOM.

655
Multi-Selecthard

A FortiGate is deployed in multi-VDOM mode with two VDOMs: VDOM-1 and VDOM-2. The administrator needs to enable communication between these VDOMs using a VDOM link. Which TWO statements about VDOM link configuration are correct? (Choose two.)

Select 2 answers
A.Firewall policies must be configured in each VDOM to allow traffic to traverse the VDOM link.
B.A VDOM link consists of a pair of interfaces, one in each VDOM, and they are automatically created when the link is configured.
C.The VDOM link interfaces must be assigned IP addresses in the same subnet for routing to work.
D.Only one VDOM link can exist between two VDOMs at a time.
E.The VDOM link interfaces are always in transparent mode and cannot be assigned IP addresses.
AnswersA, B

Even though the VDOM link provides a path between VDOMs, firewall policies in each VDOM are required to permit traffic. By default, inter-VDOM traffic is denied. You must create policies that allow traffic from the VDOM link interface to the destination network in each VDOM. This ensures security and control over inter-VDOM communication.

Why this answer

Creating a VDOM link automatically generates a pair of interfaces, one in each VDOM, and firewall policies must be configured in both VDOMs to allow traffic. These two statements are correct. The other options contain misconceptions about subnet requirements, operational modes, or link limitations.

Exam trap

The trap here is assuming VDOM link interfaces must be in the same subnet or that only one link is allowed, when in fact they can be in different subnets and multiple links are possible.

656
MCQeasy

What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?

A.To establish a backup tunnel in case the primary tunnel fails.
B.To detect if a VPN peer is alive by sending periodic probes and bringing down the tunnel if no response is received.
C.To automatically renegotiate IKE phase1 keys before they expire.
D.To verify the integrity of encrypted packets using HMAC authentication.
AnswerB

DPD sends periodic encrypted probes (IKE notify payloads) to the peer; if no response arrives within the configured retry and idle intervals, FortiGate tears down the IPsec SA and routes traffic elsewhere, preventing black-holed packets over a silently failed peer.

Why this answer

Dead Peer Detection (DPD) sends periodic R-U-THERE probes (RFC 3706) to a VPN peer and expects an R-U-THERE-ACK response. If no response arrives within a configured threshold, DPD declares the peer dead and tears down the tunnel, allowing failover or renegotiation. This prevents traffic from being black-holed into a dead tunnel.

Exam trap

NSE7 often tests the confusion between DPD and IKE/IPsec keepalive or rekey timers — candidates pick the key renegotiation answer because both involve timers, missing that DPD specifically detects peer liveness.

How to eliminate wrong answers

Option A is wrong because DPD detects peer failure; it doesn't establish backup tunnels — that's the role of redundant tunnel configurations or routing protocols like BGP. Option C is wrong because IKE key renegotiation is handled by lifetime timers (IKE SA and IPsec SA lifetimes), not DPD. Option D is wrong because packet integrity via HMAC is provided by IPsec's authentication header (AH) or ESP authentication, not DPD.

657
MCQmedium

A network admin runs 'diagnose sys top' on a FortiGate and sees that the process 'httpsd' is consistently using 95% CPU. Which of the following actions is MOST appropriate to troubleshoot this issue?

A.Restart the FortiGate firewall engine with 'diagnose test application fgwbd 255'
B.Disable the antivirus profile on all policies to reduce processing load
C.Increase the log rate to capture more details about the httpsd process
D.Check the number of active admin sessions and consider stopping the web GUI service temporarily
AnswerD

httpsd handles web management; high CPU may be due to many admin sessions or a stuck process.

Why this answer

The httpsd process handles the FortiGate web GUI (HTTPS) and API requests. High CPU usage by httpsd typically indicates excessive admin sessions or web GUI activity. Option D is correct because checking active admin sessions and temporarily stopping the web GUI service (e.g., via 'config system global set admin-https-redirect disable' or stopping the service) directly addresses the likely cause without disrupting firewall processing or requiring policy changes.

Exam trap

The trap here is that candidates may confuse the httpsd process with the firewall engine (fgwbd) and attempt to restart the firewall engine, or assume high CPU is always due to security profiles, when in fact httpsd is a management-plane process that requires a different troubleshooting approach.

How to eliminate wrong answers

Option A is wrong because 'diagnose test application fgwbd 255' restarts the firewall engine (fgwbd), which handles firewall processing, not the httpsd process; this would disrupt traffic without addressing the root cause. Option B is wrong because disabling antivirus profiles on all policies reduces security and does not affect the httpsd process, which is a web server process unrelated to AV scanning. Option C is wrong because increasing the log rate adds overhead to the system and does not provide diagnostic details specific to httpsd; logs for httpsd are already captured in the event log and increasing rate would worsen CPU usage.

658
MCQmedium

A FortiGate administrator wants to implement Content Disarm and Reconstruction (CDR) for email attachments. Which security profile must be configured to enable CDR?

A.Web Filter profile
B.Antivirus profile
C.IPS profile
D.Application Control profile
AnswerB

CDR is enabled within the FortiGate antivirus profile, which inspects and reconstructs supported email attachment types before delivery. Configuring it there satisfies the requirement to disarm and rebuild attachments rather than merely detect known signatures.

Why this answer

Content Disarm and Reconstruction (CDR) is a security feature that removes active content (e.g., macros, scripts, embedded objects) from files and reconstructs them into a safe version. In FortiOS, CDR is configured within the Antivirus profile because it operates as part of the antivirus scanning engine, specifically under the 'File Filter' or 'Content Disarm' tab, where you can enable CDR for supported file types like Office documents and PDFs.

Exam trap

The trap here is that candidates mistakenly associate CDR with Web Filter (thinking it's a web content sanitization feature) or IPS (confusing it with file-based exploit prevention), when in fact CDR is a file-level sanitization feature tightly integrated with the antivirus engine and configured within the Antivirus profile.

How to eliminate wrong answers

Option A is wrong because Web Filter profiles control HTTP/HTTPS URL access and content categorization, not email attachment processing or file-level content sanitization. Option C is wrong because IPS profiles focus on network-based intrusion prevention by inspecting traffic for exploit signatures and anomalies, not on file reconstruction or active content removal. Option D is wrong because Application Control profiles manage application visibility and usage policies (e.g., blocking or allowing specific apps like Skype or Dropbox), not file attachment scanning or CDR operations.

659
MCQhard

An admin configures a FortiManager ADOM for a customer with multiple FortiGates. The admin wants to use meta fields to group firewalls by location. After defining a meta field 'Location' and assigning values to devices, where can the admin use the meta field for policy targeting?

A.Meta fields are automatically synced to FortiGate and used in firewall policies
B.In the ADOM level policy package, meta fields are used as variables in policy names
C.Meta fields are only used for generating reports in FortiAnalyzer
D.In the installation target of a policy package, the admin can filter devices by meta field values
AnswerD

Meta fields assigned to devices become available as filters within the installation target of a policy package, letting the admin scope installation to FortiGates sharing a Location value. This satisfies the requirement to target policies by location grouping.

Why this answer

In FortiManager, meta fields are used within ADOM-level policy packages to filter devices during installation targeting. This allows the admin to select only FortiGates with a specific 'Location' meta field value, enabling policy targeting based on location without manual device grouping.

Exam trap

The trap here is that candidates often assume meta fields are automatically propagated to FortiGate devices or used in policy definitions, but FortiManager treats them strictly as administrative metadata for filtering and targeting during installation, not as runtime variables on the FortiGate.

How to eliminate wrong answers

Option A is wrong because meta fields are not automatically synced to FortiGate devices; they remain within FortiManager for administrative grouping and targeting, and are not used directly in FortiGate firewall policies. Option B is wrong because meta fields cannot be used as variables in policy names; they are used for filtering devices in installation targets, not for naming policies. Option C is wrong because meta fields are not limited to FortiAnalyzer reporting; they are primarily used in FortiManager for device grouping and policy targeting.

660
MCQeasy

An administrator wants to monitor real-time CPU usage per process on a FortiGate. Which command should be used?

A.diagnose hardware sysinfo cpu
B.get system performance status
C.diagnose sys top
D.show system performance monitor
AnswerC

The diagnose sys top command displays a live, refreshing list of running processes with their CPU and memory consumption, letting the administrator identify which process is consuming resources in real time. It is the FortiGate diagnostic equivalent of a Unix top utility.

Why this answer

The 'diagnose sys top' command on FortiGate displays real-time CPU usage per process, similar to the Linux 'top' command. This is the standard diagnostic tool for monitoring per-process CPU and memory consumption in real time, which directly meets the administrator's requirement.

Exam trap

The trap here is that candidates may confuse 'diagnose sys top' with 'get system performance status' or 'diagnose hardware sysinfo cpu', which provide aggregate CPU data but not per-process granularity, leading to an incorrect choice when the question explicitly asks for per-process monitoring.

How to eliminate wrong answers

Option A is wrong because 'diagnose hardware sysinfo cpu' shows overall CPU utilization and hardware information, not per-process breakdown. Option B is wrong because 'get system performance status' provides a summary of system performance metrics (e.g., CPU, memory, sessions) but does not list individual processes. Option D is wrong because 'show system performance monitor' is not a valid FortiGate CLI command; the correct command for a performance monitor view is 'diagnose sys perf' or 'diagnose sys top'.

661
Multi-Selectmedium

A FortiGate administrator is troubleshooting an IKEv2 VPN tunnel that fails to establish. The remote peer logs show 'no acceptable proposal' error. Which TWO possible causes should the administrator check?

Select 2 answers
A.The remote peer's IP address is unreachable
B.The phase1 encryption algorithm or integrity algorithm is mismatched
C.The local FortiGate has the wrong IKE version configured
D.The remote peer's pre-shared key is incorrect
E.The Diffie-Hellman group configured is not supported by both peers
AnswersB, E

A mismatch in phase1 encryption or integrity algorithms causes the responder to reject the initiator's proposal, producing the 'no acceptable proposal' error. IKEv2 requires both peers to agree on identical encryption and integrity algorithms during SA negotiation, so verifying these settings on both gateways resolves the failure.

Why this answer

Option B is correct because the 'no acceptable proposal' error in IKEv2 specifically indicates that the responder could not find a matching proposal in the IKE_SA_INIT exchange, which is typically caused by a mismatch in the phase1 encryption algorithm (e.g., AES256 vs 3DES) or integrity algorithm (e.g., SHA256 vs SHA1) between the two peers. Option E is also correct because the Diffie-Hellman group is part of the IKEv2 SA proposal; if one peer offers a DH group (e.g., group 14) that the other peer does not support or has not configured, the responder rejects the proposal with the same 'no acceptable proposal' error. Option A is not correct because an unreachable peer would produce timeout or no-response errors rather than a proposal rejection, since the IKE exchange would never reach the proposal comparison stage.

Option C is not correct because an IKE version mismatch (IKEv1 vs IKEv2) would cause the peers to fail to parse each other's messages entirely, resulting in different errors such as 'invalid major version' or no response, not 'no acceptable proposal'. Option D is not correct because an incorrect pre-shared key is detected during the IKE_AUTH exchange after the proposal has already been accepted, producing an authentication failure error rather than a proposal rejection.

Exam trap

NSE7 often tests the distinction between Phase 1 proposal failures ('no acceptable proposal') and Phase 2 or authentication failures (PSK mismatch, proxy-ID mismatch), so candidates wrongly pick PSK or reachability for a proposal error.

662
Multi-Selectmedium

An administrator is configuring SD-WAN and wants to ensure that voice traffic uses the lowest latency link. Which two configurations are required to achieve this? (Choose TWO.)

Select 2 answers
A.Configure a static route for the voice subnet
B.Configure a performance SLA with latency threshold
C.Set the SD-WAN rule to use 'manual' strategy
D.Create an SD-WAN rule that matches voice traffic and uses 'best quality' strategy
E.Enable NAT on the SD-WAN interface
AnswersB, D

A performance SLA with a latency threshold continuously probes each member link, measuring jitter and packet loss against the configured latency limit. SD-WAN then steers voice traffic onto the link satisfying that threshold, directly meeting the requirement for lowest-latency path selection.

Why this answer

A performance SLA with a latency threshold allows FortiGate to measure real-time latency to a target server and mark the link quality. Option D is correct because an SD-WAN rule using the 'best quality' strategy will dynamically select the link with the lowest latency (as determined by the SLA) for voice traffic, ensuring optimal voice quality.

Exam trap

The trap here is that candidates often confuse 'manual' strategy with 'best quality', assuming manual allows manual selection of the best link, but manual actually forces a fixed interface without dynamic SLA feedback.

663
MCQeasy

An administrator wants to create a separate virtual firewall instance on a FortiGate to isolate a DMZ environment. The DMZ must have its own routing table, firewall policies, and administrators. Which FortiGate feature should be used?

A.Virtual Domains (VDOMs)
B.Virtual Router Redundancy Protocol (VRRP)
C.Virtual LANs (VLANs)
D.Security Fabric
AnswerA

VDOMs create independent virtual firewall instances within one FortiGate, each with its own routing table, firewall policies, and administrators. This satisfies the DMZ isolation requirement, separating management and traffic from other environments on the same device.

Why this answer

Virtual Domains (VDOMs) are the FortiGate feature that allows the creation of multiple independent virtual firewalls within a single physical appliance. Each VDOM operates with its own separate routing table, firewall policies, and administrative domains, making it the correct choice for isolating a DMZ environment with dedicated administrators and routing.

Exam trap

The trap here is that candidates often confuse VLANs (Layer 2 segmentation) with VDOMs (full virtual firewall instances), mistakenly thinking VLANs alone can provide independent routing tables and administrative domains, which they cannot.

How to eliminate wrong answers

Option B (VRRP) is wrong because VRRP is a first-hop redundancy protocol (RFC 5798) that provides high availability for default gateways, not a mechanism to create separate virtual firewall instances with independent routing and policies. Option C (VLANs) is wrong because VLANs operate at Layer 2 to segment broadcast domains and do not provide separate routing tables, firewall policies, or administrative domains; they require a VDOM or similar construct to achieve full isolation at Layer 3 and above. Option D (Security Fabric) is wrong because the Security Fabric is a framework for centralized management and threat sharing across multiple FortiGate devices, not a feature that creates isolated virtual firewall instances on a single unit.

664
MCQhard

A FortiGate has two equal-cost paths to a destination network. ECMP is enabled. The administrator notices that all traffic uses the first path. What is the most likely cause?

A.ECMP is configured with 'spillover' mode
B.The second path is administratively down
C.ECMP is configured to use 'source-dest-ip' hash and all sessions are from same source to same destination
D.The route metric is not equal
AnswerC

With the source-dest-ip hash, FortiGate selects a path from the source and destination IP pair. Identical pairs always hash to the same interface, so every session between the same endpoints traverses one path, leaving the second equal-cost link idle.

Why this answer

When ECMP is configured with the 'source-dest-ip' hash algorithm, traffic is load-balanced based on a hash of both source and destination IP addresses. If all sessions originate from the same source IP and go to the same destination IP, the hash value is identical for every session, causing all traffic to be forwarded over the same path. This is the most likely cause because the administrator sees all traffic using the first path despite ECMP being enabled.

Exam trap

The trap here is that candidates assume ECMP always distributes traffic evenly across all paths, but they overlook that the hash algorithm's behavior depends on the diversity of source-destination pairs; when all sessions share the same IP pair, the hash produces the same result, causing all traffic to follow one path.

How to eliminate wrong answers

Option A is wrong because 'spillover' mode is an SD-WAN feature that shifts traffic to another path only when a bandwidth threshold is exceeded, but it does not cause all traffic to use a single path by default; it would still distribute traffic until the threshold is reached. Option B is wrong because if the second path were administratively down, the route would not be present in the routing table as an equal-cost path, and ECMP would not consider it; the question states two equal-cost paths exist. Option D is wrong because the question explicitly states the paths have equal cost, so the route metric is equal; unequal metrics would prevent ECMP from load-balancing, but that contradicts the given condition.

665
MCQmedium

An IPS administrator wants to detect a new custom attack that sends malformed HTTP headers. The attack pattern is a specific sequence of bytes that is not covered by existing signatures. What is the BEST way to detect this attack on FortiGate?

A.Use an automation stitch to block traffic with unusual headers
B.Enable protocol anomaly detection in the IPS sensor
C.Deploy FortiWeb as a reverse proxy
D.Create a custom IPS signature
AnswerD

A custom IPS signature lets you define the exact byte sequence matching the malformed HTTP header, which no existing signature covers. FortiGate compares traffic against this user-defined pattern, so it detects the novel attack that standard signature sets miss.

Why this answer

Custom IPS signatures allow you to define a specific byte sequence or pattern (e.g., via a regular expression or hex pattern) that matches the malformed HTTP header. FortiGate's IPS engine can then inspect HTTP traffic at the application layer and trigger an alert or block when the custom pattern is found, even if no existing signature covers it.

Exam trap

The trap here is that candidates confuse protocol anomaly detection (which catches generic RFC violations) with the ability to detect a specific, custom byte sequence, leading them to choose Option B instead of understanding that custom signatures are required for precise pattern matching.

How to eliminate wrong answers

Option A is wrong because automation stitches are used to automate responses to detected events (e.g., quarantine a source IP), not to detect new attack patterns; they rely on existing detection mechanisms. Option B is wrong because protocol anomaly detection in the IPS sensor detects deviations from RFC standards (e.g., malformed HTTP headers in a generic sense), but it cannot match a specific, custom byte sequence that the administrator defines. Option C is wrong because deploying FortiWeb as a reverse proxy adds a separate web application firewall, which is not the most direct or efficient way to detect a custom attack on FortiGate; it also requires additional hardware or licensing and does not leverage the existing IPS engine.

666
MCQmedium

A FortiGate with SD-WAN enabled uses two members: MPLS (10 ms latency) and Internet (40 ms latency). The SD-WAN rule uses 'Best Quality' strategy with latency as the metric. Traffic to a critical application (10.1.1.0/24) is currently using the MPLS link. The MPLS link's latency increases to 60 ms due to a routing issue. How will FortiGate handle new sessions to 10.1.1.0/24?

A.New sessions will use the Internet link; existing sessions continue on MPLS.
B.FortiGate will wait for the MPLS link to recover before sending new traffic.
C.All sessions immediately switch to the Internet link.
D.Existing sessions continue on MPLS; new sessions will use MPLS until the next SLA probe.
AnswerA

Best Quality evaluates link metrics per new session, so once MPLS latency exceeds the Internet member's 40 ms, new sessions to 10.1.1.0/24 select the Internet link. FortiGate does not rebalance established sessions, so existing MPLS flows persist until they end.

Why this answer

The 'Best Quality' strategy with latency metric selects the link with the lowest latency for new sessions. When MPLS latency rises to 60 ms, it exceeds the Internet link's 40 ms, so new sessions will be steered to the Internet. However, SD-WAN does not preemptively rehash existing sessions; they remain on the original link (MPLS) until they expire or are torn down.

Exam trap

The trap here is that candidates assume SD-WAN automatically re-routes all traffic (including existing sessions) when link quality degrades, but in reality, only new sessions are affected unless a session-based failover mechanism like session TTL or manual intervention is configured.

How to eliminate wrong answers

Option B is wrong because FortiGate does not wait for link recovery; it actively selects the best link based on current SLA metrics. Option C is wrong because SD-WAN does not force an immediate failover of all sessions; only new sessions are affected by the updated latency measurement. Option D is wrong because new sessions are evaluated immediately based on the latest SLA probe results, not deferred until the next probe cycle.

667
Multi-Selectmedium

An administrator is planning a multi-VDOM deployment with a management VDOM. Which TWO statements about management VDOMs are correct? (Choose two.)

Select 2 answers
A.The management VDOM can be used for FortiGuard updates
B.The management VDOM cannot have firewall policies
C.The management VDOM requires a separate license
D.The management VDOM can host the GUI and SSH services
E.All user traffic must pass through the management VDOM
AnswersA, D

A management VDOM provides a dedicated administrative and out-of-band path, so FortiGuard update traffic can egress through it independently of production VDOMs. This satisfies the multi-VDOM requirement for segregated management-plane connectivity, letting signature and database downloads bypass data-plane routing and policy on the other VDOMs.

Why this answer

Option A is correct because in a multi-VDOM FortiGate deployment the management VDOM is specifically designed to carry out-of-band management functions, including FortiGuard update traffic (FortiGuard services such as AV/IPS signature and web-filter database downloads), which is why it is often given its own dedicated management interface and route. Option D is correct because the management VDOM is intended to host administrative access services such as HTTPS GUI and SSH, allowing administrators to log in and manage the device independently of the production VDOMs. The remaining options are incorrect: the management VDOM can still contain firewall policies (so B is false), it does not require a separate license since VDOMs are a built-in feature of the FortiGate platform (so C is false), and user traffic is not required to traverse the management VDOM—it is reserved for management-plane traffic, not data-plane forwarding (so E is false).

Exam trap

The trap here is that candidates often assume a management VDOM cannot have firewall policies or requires a separate license, but in reality, it can have policies for administrative access and does not incur additional licensing costs.

668
MCQmedium

An administrator configures a FortiGate in transparent mode for a VDOM. After switching to transparent mode, the administrator notices that the default route disappears and traffic fails. What must be configured to restore routing?

A.A static route on the upstream router
B.A management IP address and default gateway for the VDOM
C.Enable NAT mode to allow routing
D.Assign an IP address to each interface
AnswerB

Why this answer

In transparent mode, a FortiGate VDOM acts as a Layer 2 bridge and does not participate in Layer 3 routing. The default route disappears because the VDOM has no Layer 3 interface to host a routing table. To restore management connectivity and allow the FortiGate to reach remote networks (e.g., for firmware updates or logging), you must configure a management IP address and a default gateway for the VDOM.

This management IP is used solely for outbound management traffic and does not affect the bridged data plane.

Exam trap

The trap here is that candidates assume transparent mode still requires per-interface IPs or static routes for the data plane, when in fact only a single management IP and default gateway are needed for the FortiGate's own control-plane traffic.

How to eliminate wrong answers

Option A is wrong because configuring a static route on the upstream router does not provide the FortiGate itself with a default gateway; the FortiGate in transparent mode has no routed interfaces and cannot use an upstream router's route for its own management traffic. Option C is wrong because NAT mode is a separate operational mode (Layer 3) and cannot be enabled within a transparent-mode VDOM; transparent mode inherently disables routing and NAT. Option D is wrong because assigning an IP address to each interface in transparent mode is not supported; only a single management IP is assigned to the VDOM, not per-interface IPs.

669
MCQeasy

A FortiGate administrator is configuring a route-based IPsec VPN to a cloud provider. The provider requires that only traffic for the 10.20.0.0/16 network be sent through the tunnel, and that the FortiGate present a specific local subnet of 192.168.10.0/24 as its source. The administrator wants to avoid policy-based VPN configuration. Which configuration approach correctly defines the traffic selectors for this route-based tunnel?

A.Configure phase 2 selectors with local address 192.168.10.0/24 and remote address 10.20.0.0/16, and add a static route for 10.20.0.0/16 pointing to the tunnel interface.
B.Create a policy-based IPsec VPN with firewall policies referencing the tunnel and define the source and destination addresses in those policies.
C.Configure phase 2 selectors as 0.0.0.0/0 to 0.0.0.0/0 and rely on firewall policies to restrict traffic to the required subnets.
D.Set the tunnel interface IP to 192.168.10.1/24 and configure a route for 0.0.0.0/0 through the tunnel, allowing the provider to filter traffic.
AnswerA

For a route-based IPsec tunnel, the phase 2 selectors define the proxy IDs exchanged with the peer, while a static route directs matching traffic into the tunnel interface. Setting the local selector to 192.168.10.0/24 and the remote to 10.20.0.0/16 matches the cloud provider's requirement, and the route ensures only that destination is sent through the tunnel.

Why this answer

Route-based IPsec uses phase 2 selectors as proxy IDs and relies on routing to steer traffic into the tunnel interface. Configuring the local selector as 192.168.10.0/24 and the remote as 10.20.0.0/16 satisfies the provider, and a static route for 10.20.0.0/16 to the tunnel interface ensures only the intended destination is sent through the VPN.

Exam trap

The trap here is assuming that route-based tunnels ignore traffic selectors, when phase 2 proxy IDs are still negotiated and must match what the remote gateway expects.

670
MCQmedium

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator has created a VDOM link between VDOM-1 and VDOM-2 and assigned IP addresses to both ends. A server in VDOM-1 (10.1.1.10/24) needs to reach a server in VDOM-2 (10.2.2.10/24). The administrator has added a static route in VDOM-1 for 10.2.2.0/24 pointing to the VDOM-2 link interface IP, and a static route in VDOM-2 for 10.1.1.0/24 pointing to the VDOM-1 link interface IP. However, traffic is not passing. Which additional configuration is required on the FortiGate to allow the traffic to flow?

A.Enable inter-VDOM routing globally using the command config system settings, set allow-inter-vdom-traffic enable.
B.Assign the VDOM link interfaces to the same zone in both VDOMs to permit traffic between them.
C.Configure a static route in the global routing table that points to both VDOMs, enabling inter-VDOM routing.
D.Create firewall policies in VDOM-1 and VDOM-2 that allow traffic from the source subnet to the destination subnet on the respective VDOM link interfaces.
AnswerD

By default, inter-VDOM traffic is blocked by implicit deny policies. You must create a policy in VDOM-1 allowing traffic from 10.1.1.0/24 to 10.2.2.0/24 with the outgoing interface as the VDOM link, and a reciprocal policy in VDOM-2. Without these, traffic is dropped even if routes exist.

Why this answer

Inter-VDOM traffic is treated like traffic between two separate firewalls. Even with VDOM links and static routes in place, the implicit deny policy in each VDOM blocks the traffic. You must explicitly allow it with firewall policies in both VDOMs, specifying the source, destination, and VDOM link interface.

No global setting or zone configuration can override this requirement.

Exam trap

The trap here is assuming that adding routes and VDOM links automatically permits traffic between VDOMs, when in fact firewall policies are required in each VDOM to allow it.

671
MCQeasy

A FortiGate is configured as a ZTNA proxy for a web application. Users report that after authenticating, they receive a '502 Bad Gateway' error. What is the most likely cause?

A.The backend server is unreachable from the FortiGate.
B.The ZTNA proxy is not configured with a valid SSL certificate.
C.The user's device posture is not compliant.
D.The ZTNA rule is not using the correct source interface.
AnswerA

A 502 Bad Gateway means the FortiGate's ZTNA proxy could not establish a connection to the protected backend server. Authentication succeeded, so the failure lies upstream of the client, pointing to an unreachable or down backend.

Why this answer

A '502 Bad Gateway' error from a reverse proxy like FortiGate's ZTNA proxy indicates that the proxy successfully received the client request but could not reach the backend server. The most likely cause is that the backend server is unreachable from the FortiGate — due to network issues, firewall rules, or the server being down. This is the classic meaning of a 502 in proxy architectures.

Exam trap

NSE7 often tests whether candidates can distinguish HTTP error codes in proxy scenarios — 502 means the proxy cannot reach the backend, while 401/403 indicate auth/posture issues, and 503 indicates the service itself is unavailable.

How to eliminate wrong answers

Option B is wrong because an invalid SSL certificate would typically cause a certificate warning or a 503/SSL handshake error, not a 502 Bad Gateway — the proxy would still be able to reach the backend. Option C is wrong because a non-compliant device posture would result in an authentication or authorization failure (e.g., access denied page), not a 502 error after successful authentication. Option D is wrong because an incorrect source interface on the ZTNA rule would prevent the rule from matching, likely causing a connection timeout or access denied, not a 502 from the proxy.

672
MCQhard

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. The administrator then runs 'diagnose debug flow filter addr 10.1.1.1' (the remote subnet) and 'diagnose debug flow show function-name enable', and observes the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 10.1.1.1:80->192.168.1.100:12345) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-192.168.1.1 via port2"'. No further output appears. What is the MOST likely cause of the issue?

A.The FortiGate is routing the traffic to the default gateway instead of into the IPsec tunnel, likely due to a missing or incorrect route for the remote subnet.
B.The IPsec VPN tunnel is not included in the firewall policy that allows traffic from the local subnet to the remote subnet.
C.The IPsec tunnel is using a different encryption domain than the local subnet, causing the FortiGate to drop the traffic.
D.The remote subnet is not correctly configured in the phase 2 selectors, causing traffic to be routed incorrectly.
AnswerA

The debug flow output shows that the FortiGate performed a route lookup and found a route to 192.168.1.1 via port2, which is the default gateway, not the IPsec tunnel. This indicates that there is no specific route for the remote subnet 10.1.1.0/24 pointing to the IPsec interface. Without that route, the FortiGate sends the traffic out the default gateway, where it is likely dropped or not encrypted. The administrator should add a static route for the remote subnet with the IPsec interface as the outgoing interface.

Why this answer

The debug flow output shows that the FortiGate received the packet, allocated a session, and then performed a route lookup that resulted in a route via the default gateway (192.168.1.1) on port2. This means the FortiGate is not sending the traffic into the IPsec tunnel, which would be indicated by a route via the IPsec interface. The most likely cause is that there is no static route for the remote subnet pointing to the IPsec tunnel.

Without that route, traffic is routed to the default gateway and not encrypted. The administrator should verify the routing table and add the necessary route.

Exam trap

The trap here is assuming the VPN tunnel configuration is at fault, but the debug flow clearly shows the traffic is being routed out the default gateway instead of the tunnel.

673
MCQmedium

An email security administrator wants to prevent attackers from spoofing the company's domain. Which email authentication mechanism should be configured to allow receiving servers to verify that emails claiming to be from the domain are sent from authorized mail servers?

A.DMARC
B.SPF
C.TLS for SMTP
D.DKIM
AnswerB

SPF publishes a DNS TXT record listing the IP addresses and hosts authorised to send mail for the domain. Receiving servers query that record and reject or flag messages originating from unauthorised servers, directly blocking domain spoofing.

Why this answer

SPF (Sender Policy Framework) is the correct answer because it allows domain owners to publish DNS records specifying which mail servers are authorized to send email on behalf of their domain. Receiving servers can then verify the envelope sender (Return-Path) against the SPF record to detect spoofed messages. This directly addresses the requirement to verify that emails claiming to be from the domain originate from authorized servers.

Exam trap

In Fortinet NSE7 exams, a common trap is confusing DMARC's policy enforcement with the actual verification of sending server authorization, leading candidates to select DMARC instead of SPF. Remember that SPF is the mechanism that explicitly lists authorized mail servers via DNS TXT records.

How to eliminate wrong answers

Option A is wrong because DMARC is a policy framework that builds on SPF and DKIM results to instruct receivers on how to handle authentication failures (e.g., quarantine or reject), but it does not itself verify the sending server's authorization. Option C is wrong because TLS for SMTP encrypts the communication channel between mail servers (RFC 3207) but provides no mechanism to verify the sender's domain or authorization. Option D is wrong because DKIM uses a digital signature linked to a domain to verify message integrity and signing domain, but it does not verify whether the sending server is authorized to send mail for that domain.

674
MCQmedium

An administrator has configured an SD-WAN zone named 'virtual-wan' containing two members: port1 and port2. They want to apply different SD-WAN rules based on the destination IP address. Which FortiGate configuration object should they use to define the destination IP address for matching traffic in an SD-WAN rule?

A.Policy route with destination address and outgoing interface
B.Address object referenced in the SD-WAN rule's destination field
C.Internet Service Database (ISDB) entry selected in the SD-WAN rule
D.Application control signature referenced in the SD-WAN rule
AnswerB

In FortiOS SD-WAN rules, the destination is specified by referencing a firewall address object. This allows granular matching based on IP subnet, FQDN, or geography. The address object is created under Firewall Objects > Addresses and then selected in the SD-WAN rule configuration. This is the correct method to match traffic by destination IP.

Why this answer

SD-WAN rules on FortiGate use firewall address objects to define destination criteria. These objects can represent IP subnets, FQDNs, or geographic locations. When configuring an SD-WAN rule, the destination field expects an address object, which is then used to match traffic.

This allows flexible and granular control over which traffic is routed through which SD-WAN member.

Exam trap

The trap here is confusing SD-WAN rule destination matching with policy routes or ISDB entries, which serve different purposes.

675
MCQhard

A FortiGate administrator configures a custom IPS signature with the pattern 'attack' in the HTTP request URI. After applying the signature, no alerts are generated even though the traffic matches. What is the MOST likely cause?

A.The signature's protocol decoder is set to 'HTTP'
B.The signature action is set to 'pass'
C.The signature's protocol decoder is not set to 'HTTP'
D.The signature severity is too low
AnswerC

A custom signature only inspects traffic handled by its assigned protocol decoder. Without the HTTP decoder, the pattern 'attack' is never evaluated against the request URI, so matching traffic passes uninspected and generates no alerts.

Why this answer

The custom IPS signature pattern 'attack' will only be inspected against the HTTP request URI if the signature's protocol decoder is explicitly set to 'HTTP'. Without this decoder assignment, the IPS engine does not know which protocol layer to parse, and the pattern is never matched against the URI, resulting in no alerts despite matching traffic.

Exam trap

The trap here is that candidates often assume a signature will automatically inspect all traffic or that the 'pass' action suppresses alerts, when in fact the protocol decoder is a mandatory prerequisite for any application-layer pattern matching in FortiGate IPS.

How to eliminate wrong answers

Option A is wrong because setting the protocol decoder to 'HTTP' is exactly what is required for the signature to inspect HTTP request URIs; this would enable alerts, not prevent them. Option B is wrong because a 'pass' action would allow the traffic but still generate a log entry (alert) by default unless logging is disabled; the question states no alerts are generated, so action alone is not the cause. Option D is wrong because signature severity does not affect whether an alert is generated; severity only influences the event's priority in logs and reports, not the detection or alerting process.

Page 8

Page 9 of 10

Page 10

All pages