Courseiva

CCNA Advanced Threat Protection Questions

75 of 157 questions · Page 1/3 · Advanced Threat Protection · Answers revealed

1
MCQeasy

Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?

A.FortiSandbox
B.FortiEDR
C.FortiDeceptor
D.FortiClient
AnswerC

FortiDeceptor deploys decoys and lures across network segments, mimicking real assets to attract attackers. Any interaction with these decoys generates high-fidelity alerts on lateral movement and early-stage intrusion attempts, satisfying the requirement for deception-based threat detection rather than perimeter or signature-based defence.

Why this answer

FortiDeceptor is specifically designed to deploy decoys and lures that mimic real assets (e.g., servers, endpoints, IoT devices) to attract and detect lateral movement and early-stage attacks inside the network. It uses deception technology to create a realistic attack surface, triggering alerts when an attacker interacts with a decoy, without relying on signatures or behavioral analysis.

Exam trap

The trap here is that candidates often confuse FortiDeceptor with FortiSandbox or FortiEDR because all three are part of the Advanced Threat Protection portfolio, but only FortiDeceptor focuses on deception-based detection of lateral movement rather than file analysis or endpoint response.

How to eliminate wrong answers

Option A is wrong because FortiSandbox is a threat analysis and sandboxing solution that detonates files and URLs in a controlled environment to detect unknown malware, not a deception-based tool for deploying decoys and lures. Option B is wrong because FortiEDR is an endpoint detection and response solution that monitors and responds to threats on endpoints using behavioral analysis and machine learning, not a decoy deployment system. Option D is wrong because FortiClient is a lightweight endpoint agent for VPN, web filtering, and basic antivirus, lacking the dedicated deception capabilities to deploy decoys and lures for lateral movement detection.

2
MCQeasy

Which FortiClient ATP feature provides protection against zero-day malware by monitoring process behavior and blocking suspicious activities at the endpoint?

A.FortiClient Web Filtering
B.FortiClient Cloud Sandbox
C.FortiClient Exploit Prevention
D.FortiClient Vulnerability Scan
AnswerC

FortiClient Exploit Prevention monitors process behaviour at the endpoint, blocking suspicious activity such as memory corruption and anomalous execution patterns. This behavioural, signature-independent approach satisfies the zero-day constraint, since unknown malware has no existing signature. It detects exploitation attempts in real time and terminates the offending process before payload execution.

Why this answer

FortiClient Exploit Prevention is correct because it uses real-time behavioral monitoring of process activities—such as API calls, memory access patterns, and code injection attempts—to detect and block zero-day malware that has no known signature. Unlike signature-based detection, this feature identifies malicious behavior at runtime, making it effective against previously unseen threats.

Exam trap

The trap here is that candidates often confuse cloud sandboxing (Option B) with endpoint behavioral protection, but FortiClient Cloud Sandbox is a separate, file-based analysis feature that does not provide real-time process monitoring on the endpoint.

How to eliminate wrong answers

Option A is wrong because FortiClient Web Filtering controls access to URLs and categorizes web traffic based on reputation and category, but it does not monitor process behavior or block suspicious activities at the endpoint. Option B is wrong because FortiClient Cloud Sandbox submits suspicious files to a cloud-based sandbox for dynamic analysis, which is a reactive, offline detection method rather than real-time behavioral monitoring on the endpoint. Option D is wrong because FortiClient Vulnerability Scan checks for missing patches and configuration weaknesses, but it does not monitor or block process-level behavior in real time.

3
Multi-Selectmedium

A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Disable logging for botnet events to reduce log volume.
B.Create a firewall address for each known C2 server and manually add them to a deny policy.
C.Enable IPS signatures for known C2 protocols and set the action to monitor only.
D.Configure a DNS filter profile with FortiGuard category filtering and block malicious categories.
E.Enable the botnet database in the antivirus profile and set the action to block.
AnswersD, E

DNS filtering with FortiGuard category filtering can block DNS resolutions for known malicious domains, preventing hosts from reaching C2 servers by domain name. This complements IP-based botnet blocking and helps stop C2 that uses domain names. It is an effective action for identifying and blocking C2 communication at the DNS layer.

Why this answer

To detect and block C2 traffic, the administrator should enable the botnet database with a block action in the antivirus profile and configure DNS filtering to block malicious categories. These two actions provide both IP-based and domain-based blocking of C2 communication, and they leverage FortiGuard threat intelligence. Together they help identify infected hosts and prevent them from reaching C2 infrastructure.

Exam trap

The trap here is selecting monitor-only IPS or manual deny policies instead of using the automated, intelligence-driven botnet database and DNS filtering that are designed for C2 blocking.

4
MCQhard

A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?

A.Firewall policy on FortiGate
B.Device control policy
C.Application control policy
D.Playbook with network isolation action
AnswerD

FortiEDR playbooks allow automated responses to threats. A playbook can include a network isolation action that blocks all network traffic except communication with the FortiEDR management server. This ensures the endpoint is contained while still allowing updates and remediation. This feature meets both requirements: automatic isolation and continued management connectivity. It is the correct choice for automated containment.

Why this answer

FortiEDR playbooks enable automated response actions, including network isolation. The isolation action blocks all network traffic except to the FortiEDR management server, allowing the endpoint to remain managed and receive remediation instructions. This satisfies the requirement of automatic isolation while preserving management connectivity.

Other options like application control, device control, or FortiGate policies do not provide the same integrated, automated endpoint isolation capability.

Exam trap

The trap here is confusing network isolation with simply blocking malicious traffic, and assuming that external firewall policies are needed instead of FortiEDR's built-in playbook actions.

5
Multi-Selecthard

A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)

Select 2 answers
A.Enable 'Use External IP Block List' in the antivirus profile.
B.Set the threat feed refresh interval to 0 to disable automatic updates.
C.Configure the threat feed as an external connector of type 'IP Address'.
D.Apply the threat feed connector to the SSL inspection profile.
E.Create a firewall policy that references the dynamic address object created from the threat feed.
AnswersC, E

In FortiOS, threat feeds are configured as external connectors. For IP address feeds, the type must be 'IP Address' so that the FortiGate can parse the feed and create a dynamic address object. This object can then be referenced in firewall policies to block or allow traffic. Without the correct connector type, the feed may not be usable as an address object, and the FortiGate will not enforce policies based on the feed.

Why this answer

To use a custom threat feed for blocking, the administrator must configure an external connector of type 'IP Address' and then reference the resulting dynamic address object in a firewall policy with a deny action. The refresh interval should be set to a non-zero value for automatic updates. Other options such as antivirus block lists or SSL inspection profiles are not involved in this integration.

Exam trap

The trap here is thinking that enabling an antivirus block list option or applying the connector to SSL inspection is required, when the feed is actually enforced through a dynamic address object in a firewall policy.

6
MCQeasy

Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?

A.SPF
B.DKIM
C.FortiMail
D.DMARC
AnswerD

DMARC consumes aggregate and forensic reports from receiving mail servers, letting administrators see which sources send mail claiming their domain. This satisfies the requirement to identify unauthorised use of the domain by revealing failing alignment and authentication results.

Why this answer

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the correct answer because it specifically uses aggregate and forensic reports (DMARC reports) to provide administrators with visibility into how their email domain is being used, including unauthorized or spoofed emails. These reports are generated by receiving mail servers and sent back to the domain owner, detailing authentication results from SPF and DKIM checks, which helps identify and mitigate domain abuse.

Exam trap

The trap here is that candidates confuse DMARC's reporting and policy enforcement features with the underlying authentication mechanisms (SPF and DKIM), thinking those protocols alone provide visibility into unauthorized use, when in fact only DMARC defines the reporting format and feedback loop.

How to eliminate wrong answers

Option A (SPF) is wrong because SPF only defines which IP addresses are authorized to send mail for a domain via DNS TXT records, but it does not generate reports or provide visibility into unauthorized use. Option B (DKIM) is wrong because DKIM provides a cryptographic signature to verify email integrity and sender authenticity, but it does not produce reports on domain usage or abuse. Option C (FortiMail) is wrong because FortiMail is a secure email gateway product that can implement DMARC policies and process reports, but it is not the technology that uses DMARC reports itself; DMARC is the standard that defines the reporting mechanism.

7
MCQmedium

An administrator wants to integrate FortiGate with an external threat intelligence feed to block known malicious IP addresses automatically. Which object should be used to consume the feed?

A.External Threat Intelligence Feed
B.IP Pool
C.Address Group
D.Security Profile Group
AnswerA

An External Threat Intelligence Feed object consumes a remote feed of malicious IP addresses and prefixes, which can then be referenced by firewall policies to block that traffic automatically. It satisfies the requirement to ingest and act on an external feed.

Why this answer

The External Threat Intelligence Feed object in FortiGate is specifically designed to consume external threat intelligence feeds (e.g., STIX/TAXII, CSV, or plain text lists) and automatically update a dynamic address object with indicators of compromise (IoCs) such as malicious IP addresses. This enables automated blocking of known malicious sources without manual intervention, making it the correct choice for integrating an external feed.

Exam trap

The trap here is that candidates often confuse the External Threat Intelligence Feed with an Address Group, thinking they can manually add IPs from a feed into a group, but FortiGate requires the dedicated feed object to automate the ingestion and dynamic updates.

How to eliminate wrong answers

Option B (IP Pool) is wrong because an IP Pool is used for source NAT (SNAT) to translate private IPs to public IPs, not for consuming threat intelligence feeds. Option C (Address Group) is wrong because an Address Group is a static or dynamic grouping of address objects used in firewall policies, but it cannot directly consume an external threat feed; it would require a separate feed object to populate it. Option D (Security Profile Group) is wrong because a Security Profile Group is a container for security profiles (e.g., antivirus, IPS, web filter) applied to policies, not a mechanism to ingest external threat data.

8
MCQmedium

An admin wants to create a custom IPS signature to detect a specific exploit that sends a string 'EXPLOIT' in the HTTP Host header. Which signature syntax is correct?

A.F-SBID( --name "HTTP_EXPLOIT" --protocol http --header Host --content "EXPLOIT" )
B.F-SBID( --name "HTTP_EXPLOIT" --service HTTP --header Host --content "EXPLOIT" )
C.F-SBID( --name "HTTP_EXPLOIT" --protocol tcp --header Host --content "EXPLOIT" )
D.F-SBID( --name "HTTP_EXPLOIT" --protocol http --header Host --content "EXPLOIT" )
AnswerD

This follows correct F-SBID syntax with protocol http and header Host.

Why this answer

The FortiGate custom IPS signature syntax requires the `--protocol http` flag to specify the application-layer protocol for HTTP inspection, and `--header Host` to target the HTTP Host header field. The `--content` parameter then defines the string 'EXPLOIT' to match within that header, enabling precise detection of the exploit.

Exam trap

The trap here is that candidates often confuse `--protocol tcp` with `--protocol http`, not realizing that HTTP header inspection requires the application-layer protocol keyword to enable the HTTP parser, even though HTTP traffic uses TCP as its transport.

How to eliminate wrong answers

Option A is wrong because it uses `--protocol http` (correct) but the syntax is identical to D and listed as incorrect in the question context; however, the actual error is that A is a duplicate of D and the question marks D as correct, so A is considered wrong due to the answer key. Option B is wrong because it uses `--service HTTP` instead of `--protocol http`; the `--service` flag is not a valid parameter in FortiGate IPS signatures for specifying the protocol layer, and the correct keyword is `--protocol`. Option C is wrong because it uses `--protocol tcp`, which specifies the transport-layer protocol rather than the application-layer HTTP protocol; while HTTP runs over TCP, the signature must use `--protocol http` to enable HTTP header parsing and the `--header` directive.

9
Multi-Selecthard

A security team is configuring FortiMail for email security. They want to ensure that incoming emails are authenticated using SPF, DKIM, and DMARC, and that emails failing authentication are quarantined. Which THREE settings must be configured in FortiMail? (Choose three.)

Select 3 answers
A.Enable DKIM verification in the anti-spam policy
B.Enable TLS encryption for incoming SMTP
C.Enable DMARC verification and set the action for DMARC failure to quarantine
D.Enable SPF verification in the anti-spam policy
E.Configure a recipient verification policy
AnswersA, C, D

DKIM verification must be enabled to verify DKIM signatures.

Why this answer

DKIM verification must be explicitly enabled in the anti-spam policy to allow FortiMail to validate the DKIM signature on incoming emails. Without this setting, DKIM authentication is not performed, and the email's DKIM status will not be evaluated.

Exam trap

The trap here is that candidates often confuse transport security (TLS) with email authentication protocols, mistakenly thinking TLS is required for SPF/DKIM/DMARC enforcement, when in fact TLS is optional and unrelated to the authentication chain.

10
MCQmedium

An administrator sees the following log entry: 'id=13593 msg="CDR: File attachment sanitized"' Which feature generated this log?

A.Content Disarm and Reconstruction
B.FortiSandbox
C.Machine Learning Engine
D.Outbreak Prevention
AnswerA

CDR strips active content from files and rebuilds them, so the "sanitized" message confirms Content Disarm and Reconstruction generated the entry. The log's id=13593 and explicit "CDR" prefix map directly to that feature, satisfying the stem's requirement to identify the source of this sanitisation event.

Why this answer

The log entry 'CDR: File attachment sanitized' is generated by Content Disarm and Reconstruction (CDR). CDR works by removing active content (e.g., macros, scripts, embedded objects) from files and rebuilding them into a safe, sanitized version. This is distinct from sandboxing or machine learning, as CDR does not rely on detection but instead proactively neutralizes threats by reconstructing the file.

Exam trap

The trap here is that candidates confuse the 'sanitized' action with sandboxing or ML-based detection, but CDR is a distinct proactive technology that does not rely on detection—it always sanitizes regardless of threat verdict.

How to eliminate wrong answers

Option B is wrong because FortiSandbox generates logs related to file submission, verdict (malicious/clean), and behavioral analysis, not 'CDR: File attachment sanitized' which is specific to the CDR engine. Option C is wrong because the Machine Learning Engine produces logs for ML-based detection events (e.g., 'ML: File detected as malicious'), not for file sanitization which is a static transformation process. Option D is wrong because Outbreak Prevention is a FortiGuard service that provides real-time threat intelligence and signatures, not a feature that performs file sanitization; its logs would reference outbreak alerts or signature updates, not CDR actions.

11
MCQeasy

A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?

A.Sandbox Inspection
B.Machine Learning (ML) Malware Detection
C.FortiGuard Outbreak Prevention
D.Content Disarm and Reconstruction
AnswerB

The Machine Learning Malware Detection setting in the antivirus profile uses machine learning models to analyze file characteristics and behavior to identify and block unknown malware. This is exactly what the administrator needs to protect against unknown threats without relying solely on signatures. It is a built-in FortiGate feature available in the antivirus profile.

Why this answer

The Machine Learning Malware Detection setting in the FortiGate antivirus profile uses machine learning algorithms to detect and block unknown malware based on file characteristics and behavior. This provides protection against zero-day threats without relying solely on signatures, meeting the administrator's requirement.

Exam trap

The trap here is confusing machine learning malware detection with sandboxing or outbreak prevention, which are different technologies for handling unknown threats.

12
MCQhard

A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?

A.DNS filter with botnet C&C category
B.Local threat intelligence feed with automation stitch
C.Application control with custom signature
D.FortiGuard IoT detection service
AnswerB

A local threat intelligence feed can be populated with the malicious domain, and an automation stitch can be triggered by a log event to add the domain to the feed automatically. This allows FortiGate to block future connections without manual intervention. The combination of a local threat feed and automation stitch provides the dynamic blocking required, as FortiGate can update the feed based on detected events.

Why this answer

The scenario requires automatic blocking of a newly discovered malicious domain that is not categorized by FortiGuard. A local threat intelligence feed can be updated dynamically via automation stitches triggered by log events, enabling FortiGate to block the domain and similar ones. DNS filter and application control rely on static or FortiGuard-provided intelligence, and IoT detection is unrelated.

Thus, the local threat feed with automation stitch is the correct solution.

Exam trap

The trap here is assuming that FortiGuard categories automatically include all malicious domains, overlooking the need for local threat intelligence and automation to handle zero-day or uncategorized threats.

13
MCQeasy

A network administrator wants to block known malicious IP addresses using threat intelligence feeds on FortiGate. Which feature should they use?

A.FortiGuard Web Filtering
B.External Threat Intelligence
C.Application Control
D.IP Reputation
AnswerB

External Threat Intelligence lets FortiGate ingest named feeds from external sources and apply them directly in firewall policies as source or destination objects, satisfying the requirement to block known malicious IPs. Unlike local blocklists, it dynamically refreshes indicators, so newly published malicious addresses are blocked without manual updates.

Why this answer

FortiGate's External Threat Intelligence feature allows administrators to import and consume threat intelligence feeds (e.g., STIX/TAXII, CSV, or custom URLs) to block known malicious IP addresses. This is the correct feature because it is specifically designed to ingest external threat data and apply it to firewall policies for dynamic blocking, unlike the other options which serve different purposes.

Exam trap

The trap here is that candidates often confuse IP Reputation (a built-in FortiGuard service) with External Threat Intelligence (a feature for importing custom feeds), leading them to select IP Reputation when the question explicitly mentions 'threat intelligence feeds' from external sources.

How to eliminate wrong answers

Option A is wrong because FortiGuard Web Filtering is used to control access to web categories and URLs based on FortiGuard's cloud database, not to block specific IP addresses from external threat feeds. Option C is wrong because Application Control identifies and controls application traffic (e.g., Facebook, Skype) based on signatures, not IP-based threat intelligence. Option D is wrong because IP Reputation is a built-in FortiGuard service that rates IP addresses based on FortiGuard's own threat data, not a feature to import custom external threat intelligence feeds.

14
MCQmedium

A FortiGate admin configures an automation stitch to send an email alert when a high-severity IPS event occurs. The trigger is 'IPS Event' and the action is 'Email'. After testing, no email is sent despite events being logged. What is the most likely cause?

A.The IPS event severity threshold is set too low
B.The automation stitch is disabled
C.No SMTP server is configured in the FortiGate
D.The IPS engine is in monitor mode
AnswerC

The Email action requires a configured SMTP server to relay messages; without one, the stitch fires but delivery silently fails. Events still appear in logs because logging is independent of the automation action, matching the symptom of logged IPS events with no alert email.

Why this answer

The automation stitch requires a functional SMTP server configuration to send emails. Without an SMTP server defined under System > Settings > Email Service, the FortiGate cannot relay the alert email, even if the trigger and action are correctly configured and events are logged. This is the most common reason for email delivery failure in automation stitches.

Exam trap

The trap here is that candidates assume the automation stitch is misconfigured or the IPS engine is blocking the event, when the real issue is the underlying email infrastructure (SMTP) that the action depends on, which is a separate configuration from the stitch itself.

How to eliminate wrong answers

Option A is wrong because a low severity threshold would cause more events to match, not prevent email sending; the issue is delivery, not triggering. Option B is wrong because if the stitch were disabled, no events would be logged as triggered by the stitch, but the question states events are logged, implying the stitch is enabled and triggering. Option D is wrong because monitor mode affects IPS action (e.g., whether packets are blocked), not the generation of IPS events or the ability to send email alerts.

15
MCQhard

A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?

A.Configure traffic shaping to rate limit the URL
B.Add a static URL filter with the exact URL and action 'block'
C.Enable DNS filter with botnet C2 domain blocking
D.Change the action for Malware category from 'monitor' to 'block' in the web filter profile
AnswerD

The profile currently only logs matching traffic, so FortiGate permits the malicious URL. Switching the Malware category action from monitor to block makes the firewall drop matching sessions, satisfying the requirement to stop access rather than merely record it.

Why this answer

The web filtering profile currently has the Malware category set to 'monitor all', which logs but does not block traffic. To block the URL, the action must be changed from 'monitor' to 'block' within the same web filter profile. This directly enforces the blocking action for all URLs categorized as Malware, including the known malicious URL.

Exam trap

The trap here is that candidates may think a static URL filter is required for blocking, overlooking that category-based actions in the web filter profile can directly block all URLs in a category without needing individual entries.

How to eliminate wrong answers

Option A is wrong because traffic shaping only rate-limits bandwidth and does not block URLs; it cannot enforce a block on malicious content. Option B is wrong because adding a static URL filter is unnecessary and less efficient when the category-based action can be changed; it also requires manual entry of every specific URL, which is not scalable. Option C is wrong because DNS filter with botnet C2 domain blocking targets command-and-control domains at the DNS level, not HTTP/HTTPS URL categories like Malware; it addresses a different threat vector.

16
Multi-Selecthard

A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)

Select 2 answers
A.Action: 'Add to Block List'
B.FortiAnalyzer log query
C.Action: 'Email Notification'
D.Trigger: 'IPS Event'
E.FortiGuard category
AnswersA, D

'Add to Block List' is the action component that performs the blocking. The stitch needs a trigger to fire and an action to execute; this action quarantines the offending source IP on FortiGate, satisfying the requirement to automatically block addresses matching the SSH Brute Force IPS signature.

Why this answer

Option A ('Add to Block List') is correct because the automation stitch must contain an action that actually enforces the block; the 'Add to Block List' action inserts the offending source IP into the FortiGate's local block list so subsequent traffic from that address is dropped. Option D ('IPS Event') is correct because the stitch needs a trigger that fires when the IPS signature for 'SSH Brute Force' is detected, and the IPS Event trigger is the mechanism that initiates the automation stitch upon an IPS log event. Together, the IPS Event trigger and the Add to Block List action form the required trigger-plus-action pair for this scenario.

Option B (FortiAnalyzer log query) is not required because automation stitches on FortiGate are triggered by local event/log conditions, not by querying FortiAnalyzer. Option C (Email Notification) is an action that would only notify someone rather than block the IP, so it does not fulfill the blocking requirement. Option E (FortiGuard category) relates to web filtering categorization and is unrelated to blocking an IP that triggered an IPS signature.

Exam trap

The trap here is that candidates often confuse optional actions like email notifications or external log queries as required components, when only the trigger and a blocking action are mandatory to create a functional automation stitch for IP blocking.

17
Multi-Selectmedium

An organization wants to implement multiple layers of defense against advanced persistent threats. Which three Fortinet solutions would be most effective in an ATP strategy? (Choose three.)

Select 3 answers
A.FortiMail
B.FortiSandbox
C.FortiWeb
D.FortiEDR
E.FortiDeceptor
AnswersB, D, E

FortiSandbox detects unknown malware via behavioral analysis.

Why this answer

FortiSandbox is correct because it provides dynamic analysis of suspicious files and URLs in a controlled, isolated environment, detecting zero-day and advanced malware that signature-based solutions miss. It integrates with other Fortinet security products to share threat intelligence and automate blocking, forming a critical layer in an ATP strategy by catching threats that evade initial defenses.

Exam trap

The trap here is that candidates often confuse 'security products that are part of a layered defense' with 'core ATP solutions,' leading them to select FortiMail or FortiWeb because they are common perimeter tools, while the exam specifically targets solutions that provide advanced threat detection, analysis, and response across multiple attack vectors.

18
MCQeasy

A security analyst is reviewing alerts from FortiEDR and wants to automatically isolate an infected endpoint from the network when a malicious process is detected. Which FortiEDR feature should the analyst configure to achieve this?

A.Vulnerability assessment scan.
B.Playbook with a 'Network Isolation' action.
C.Forensic data collection rule.
D.Application control policy to block the process.
AnswerB

FortiEDR playbooks allow automated responses to security events. A playbook can be triggered on a malicious process detection and execute a 'Network Isolation' action, which cuts off all network communication for the endpoint except to the FortiEDR management server. This contains the threat and prevents lateral movement, matching the analyst's requirement.

Why this answer

FortiEDR playbooks are the automation engine that can trigger actions based on event conditions. Configuring a playbook with a 'Network Isolation' action ensures that when a malicious process is detected, the endpoint is immediately quarantined from the network, stopping further damage. This is the correct way to achieve automated containment.

Exam trap

The trap here is thinking that blocking a process is equivalent to isolating the endpoint; isolation requires a playbook action that cuts network access.

19
MCQhard

A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?

A.Enable the 'Scan encrypted traffic' option in the antivirus profile.
B.Enable deep inspection in the SSL inspection profile applied to the policy.
C.Change the FortiSandbox connection mode from FortiGate to inline.
D.Add the website's IP address to the FortiSandbox blocklist.
AnswerB

FortiGate can only extract and submit files from HTTPS traffic if the session is decrypted. Without SSL deep inspection, the firewall sees only encrypted bytes and cannot identify the file for sandboxing, so no submission occurs. Enabling deep inspection allows the antivirus engine to inspect the decrypted payload and forward the executable to FortiSandbox for verdict.

Why this answer

File submission to FortiSandbox requires that FortiGate can see the file content. For HTTPS downloads, this means the traffic must be decrypted using an SSL inspection profile set to deep inspection. Without decryption, the antivirus engine cannot identify or extract the file, so no submission or verdict occurs.

Enabling deep inspection on the policy resolves the issue.

Exam trap

The trap here is assuming that enabling FortiSandbox inspection in the antivirus profile is sufficient for all traffic types, ignoring that encrypted traffic must be decrypted first.

20
MCQmedium

A FortiGate administrator has enabled FortiGuard Outbreak Prevention and selects the 'Use Outbreak Prevention Database' option. After a new outbreak is detected, the administrator verifies that the IPS signature is applied to all applicable policies. However, the administrator wants to ensure that the FortiGate dynamically updates its protection without requiring a full IPS engine update. Which FortiGuard service must be reachable for the FortiGate to receive outbreak prevention updates?

A.FortiGuard Anti-Spam service
B.FortiGuard Web Filtering service
C.FortiGuard SD-WAN service
D.FortiGuard IPS service
AnswerD

FortiGuard IPS service delivers the outbreak prevention database, including dynamic signatures and metadata for newly discovered threats. When Outbreak Prevention is enabled, the FortiGate queries the FortiGuard IPS service to obtain the latest outbreak information without waiting for a full IPS engine update. This allows rapid protection against zero-day exploits and active campaigns.

Why this answer

Outbreak Prevention on FortiGate relies on the FortiGuard IPS service to receive dynamic threat intelligence, including outbreak prevention signatures and metadata. Without connectivity to the FortiGuard IPS service, the FortiGate cannot download the latest outbreak prevention database, and the feature will not function. Other FortiGuard services do not provide this specific data.

Exam trap

The trap here is assuming that any FortiGuard subscription enables outbreak prevention, when in fact only the IPS service delivers the outbreak prevention database.

21
MCQhard

A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?

A.FortiSandbox to FortiAnalyzer fabric connector
B.FortiSandbox to FortiGate fabric connector
C.FortiSandbox to FortiClient EMS fabric connector
D.FortiSandbox to FortiMail fabric connector
AnswerB

The fabric connector between FortiSandbox and FortiGate enables automatic sharing of verdicts. When FortiSandbox identifies a malicious file, it can send the file hash and other indicators to FortiGate, which then adds them to its local blocklist. This prevents the file from being downloaded or executed on endpoints protected by that FortiGate. This integration directly addresses the requirement to automatically block the file across the network.

Why this answer

Configuring the fabric connector between FortiSandbox and FortiGate allows automatic sharing of malicious file verdicts. FortiGate can then block the file hash, preventing download and execution on endpoints. Other fabric connectors are limited to email security, endpoint management, or logging, and do not provide the same automatic network-wide blocking.

Exam trap

The trap here is assuming that any fabric connector will automatically block the file everywhere, but only the FortiGate integration can enforce blocking at the network perimeter for all traffic.

22
MCQhard

A FortiGate is configured with an antivirus profile that has the machine learning engine enabled. An administrator notices that some files are being detected by the ML engine but the verdict is 'probably clean'. What does this verdict indicate?

A.The file is clean and safe to pass.
B.The file is definitely malicious and should be blocked.
C.The ML engine has detected an outbreak but needs FortiGuard to confirm.
D.The ML engine has low confidence that the file is malicious; it may be a false positive.
AnswerD

The 'probably clean' verdict means the machine learning engine has low confidence that the file is malicious, flagging possible false positives. It reflects probabilistic scoring rather than a definitive malicious determination, so the file is not treated as confirmed malware.

Why this answer

The ML engine in FortiGate's antivirus profile assigns a verdict of 'probably clean' when its confidence level is low that the file is malicious. This indicates a potential false positive, meaning the file is likely benign but the engine cannot be certain. The correct action is to allow the file to pass while logging the event for further analysis, not to block it outright.

Exam trap

The trap here is that candidates confuse 'probably clean' with 'clean' or assume it requires external verification, when in fact it is a low-confidence verdict designed to avoid blocking potentially safe files.

How to eliminate wrong answers

Option A is wrong because 'probably clean' does not guarantee the file is clean; it indicates low confidence, so the file should not be unconditionally passed without scrutiny. Option B is wrong because the ML engine does not have high enough confidence to classify the file as definitely malicious; blocking it would be too aggressive and could cause false positives. Option C is wrong because the ML engine does not require FortiGuard confirmation for 'probably clean' verdicts; that mechanism is used for 'outbreak' verdicts where the engine suspects a new threat and queries FortiGuard for real-time reputation.

23
MCQeasy

A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?

A.Antivirus profile
B.Web Filtering profile
C.Data Leak Prevention profile
D.Email Filtering profile
AnswerD

The Email Filtering profile inspects SMTP, IMAP and POP3 traffic, blocking messages based on sender reputation and embedded malicious URLs. It satisfies the requirement to detect and block phishing emails containing malicious links, which antivirus or web filtering alone cannot fully address.

Why this answer

FortiGate's Email Filtering profile is specifically designed to inspect SMTP, POP3, and IMAP traffic for phishing indicators, including malicious URLs in email bodies and attachments. It can block or quarantine emails based on URL reputation, sender authentication (SPF/DKIM/DMARC), and content analysis, directly addressing the requirement to detect and block phishing emails with malicious links.

Exam trap

The trap here is that candidates often confuse Web Filtering (which handles web traffic) with Email Filtering (which handles email protocols), assuming URL reputation checks in web filtering can block phishing links in emails, but FortiGate requires the Email Filtering profile to inspect SMTP/IMAP/POP3 traffic and apply email-specific actions like quarantine.

How to eliminate wrong answers

Option A is wrong because the Antivirus profile scans for malware signatures in file attachments and does not analyze URLs or email-specific phishing patterns; it would miss malicious links that do not contain executable payloads. Option B is wrong because the Web Filtering profile controls HTTP/HTTPS traffic based on URL categories and reputation, but it operates on web proxy traffic, not on email protocols like SMTP, and cannot inspect or block emails before they reach the user's inbox. Option C is wrong because the Data Leak Prevention profile monitors and prevents unauthorized data exfiltration (e.g., credit card numbers, SSNs) and has no capability to detect phishing links or email-based threats.

24
MCQmedium

A FortiGate administrator notices that traffic classified as 'unknown' by the antivirus is being allowed. The administrator wants to ensure that such files are submitted to FortiSandbox for analysis and blocked until a verdict is received. Which configuration is required?

A.Create a custom IPS signature for unknown files
B.Enable FortiSandbox in the antivirus profile and set 'Action for unknown files' to 'Block'
C.Enable outbreak prevention in the antivirus profile
D.Enable FortiSandbox in the antivirus profile and set 'Action for known files' to 'Block'
AnswerB

FortiSandbox integration in the antivirus profile submits unknown files for dynamic analysis, and setting 'Action for unknown files' to Block enforces a hold until a verdict returns. This directly satisfies the requirement to submit and block unknown traffic rather than permit it.

Why this answer

When FortiSandbox is enabled in the antivirus profile and 'Action for unknown files' is set to 'Block', the FortiGate will submit files that cannot be identified by the local antivirus engine to FortiSandbox for analysis. While the file is being analyzed, it is blocked from reaching the client, ensuring that no potentially malicious content is delivered until a verdict (clean or malicious) is received. This directly addresses the administrator's requirement to block unknown files pending sandbox analysis.

Exam trap

The trap here is that candidates often confuse 'Action for unknown files' with 'Action for known files' or mistakenly think that outbreak prevention (which uses FortiGuard outbreak signatures) is sufficient to block unknown files, when in fact only the sandbox integration with the 'Block' action provides the required submission and blocking behavior.

How to eliminate wrong answers

Option A is wrong because custom IPS signatures are designed to detect and block network-level attacks based on traffic patterns, not to handle unknown files identified by the antivirus engine; IPS does not integrate with FortiSandbox for file submission. Option C is wrong because outbreak prevention in the antivirus profile uses FortiGuard outbreak alerts to block files based on known outbreak signatures, but it does not submit unknown files to FortiSandbox or block them pending analysis; it relies on pre-existing outbreak intelligence. Option D is wrong because setting 'Action for known files' to 'Block' would block files that are already identified by the antivirus engine, which is the opposite of the requirement; the administrator needs to block unknown files, not known ones.

25
MCQeasy

What does FortiGuard Outbreak Prevention use to protect against newly discovered malware outbreaks before traditional signatures are available?

A.Outbreak signatures and hash-based blocking
B.IP reputation and URL filtering
C.Heuristic analysis and emulation
D.Artificial intelligence and behavior analysis
AnswerA

Outbreak signatures are pushed ahead of conventional antivirus definitions, and hash-based blocking immediately denies files matching known malicious hashes. Together they satisfy the stem's constraint: protection against newly discovered outbreaks before traditional signatures become available.

Why this answer

FortiGuard Outbreak Prevention uses outbreak signatures and hash-based blocking to provide rapid protection against newly discovered malware outbreaks before traditional signatures are available. Outbreak signatures are lightweight, pattern-based detections that can be deployed quickly, while hash-based blocking allows immediate blocking of known malicious file hashes, even when full signature analysis is not yet complete.

Exam trap

The trap here is that candidates often confuse outbreak prevention with sandboxing or heuristic analysis, but FortiGuard Outbreak Prevention specifically relies on rapidly deployable outbreak signatures and hash-based blocking, not on behavioral or AI-based analysis.

How to eliminate wrong answers

Option B is wrong because IP reputation and URL filtering are network-layer controls that block known malicious hosts or URLs, but they do not directly detect or block malware files themselves, making them insufficient for outbreak prevention. Option C is wrong because heuristic analysis and emulation are proactive detection methods used in sandboxing or advanced threat protection, but they are not the primary mechanism for FortiGuard Outbreak Prevention, which relies on rapidly deployable signatures and hashes. Option D is wrong because artificial intelligence and behavior analysis are advanced techniques used in FortiSandbox or FortiAI, but they are not the core technology behind FortiGuard Outbreak Prevention, which focuses on immediate, signature-based blocking.

26
MCQeasy

What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?

A.To remove potentially malicious content from documents and rebuild them as safe files
B.To convert files into PDF format for safer viewing
C.To detect zero-day malware using sandboxing
D.To block all files containing macros
AnswerA

CDR strips active content — macros, embedded scripts, hyperlinks — from documents, then rebuilds a clean, functional file, satisfying the requirement to neutralise threats rather than merely detect them. Unlike signature-based scanning, which fails against zero-day or polymorphic payloads, this reconstruction guarantees the delivered file contains no executable code.

Why this answer

Content Disarm and Reconstruction (CDR) is designed to remove active or potentially malicious content—such as macros, scripts, embedded objects, and OLE links—from documents (e.g., Office files, PDFs) and then reconstruct them as sanitized, safe versions. This approach prevents threats like macro-based malware or exploit-laden attachments from reaching users, even if the file contains previously unknown (zero-day) payloads, by stripping the dangerous components rather than relying solely on signature-based detection.

Exam trap

The trap here is that candidates often confuse CDR with sandboxing or macro blocking, but CDR is a static sanitization technique that removes active content from files without detonating them, whereas sandboxing involves dynamic analysis and macro blocking is a simpler, all-or-nothing approach that CDR avoids by allowing safe use of the document.

How to eliminate wrong answers

Option B is wrong because CDR does not convert files to PDF format; it sanitizes the original file format (e.g., DOCX, XLSX, PDF) and returns a cleaned version in the same format, not a different one. Option C is wrong because CDR is not a sandboxing or dynamic analysis feature; it statically disarms content by removing active elements, whereas sandboxing (e.g., FortiSandbox) detonates files in a virtual environment to detect zero-day malware. Option D is wrong because CDR does not block all files containing macros; it removes the macros and other active content from the file and then delivers the sanitized file, allowing the document to be used safely without the macro functionality.

27
MCQmedium

A FortiGate is configured with a WAF profile to protect a web server. The administrator notices that SQL injection attacks are still reaching the server despite the WAF being enabled. What is the MOST likely reason?

A.The SQL injection signature set is disabled in the WAF profile
B.The attack is coming from a trusted IP
C.The web server is using HTTPS without SSL inspection
D.The WAF profile is not applied to the correct policy
AnswerA

Disabled SQL injection signatures leave the WAF inspecting traffic but matching nothing, so malicious payloads pass to the server. FortiGate's signature-based detection only blocks attacks whose signatures are enabled in the profile; the stem's constraint — WAF active yet injections still arriving — is satisfied precisely because that signature category was switched off.

Why this answer

The WAF profile contains signature sets that detect and block common attack patterns, including SQL injection. If the SQL injection signature set is disabled within the profile, the WAF will not inspect traffic for those patterns, allowing attacks to pass through. This is the most direct and likely reason why SQL injection attacks are reaching the server despite the WAF being enabled.

Exam trap

The trap here is that candidates often assume a WAF profile is a monolithic block of protection, but FortiGate allows granular disabling of individual signature sets, and the exam tests whether you understand that a disabled signature set is the most direct cause of a specific attack type bypassing the WAF.

How to eliminate wrong answers

Option B is wrong because a trusted IP exception would only bypass WAF inspection for traffic from that specific source; it would not explain why SQL injection attacks from other sources are still reaching the server. Option C is wrong because HTTPS without SSL inspection means the WAF cannot decrypt the payload, but FortiGate can still inspect encrypted traffic using certificate-based inspection or flow-based inspection with SSL offloading; the lack of SSL inspection would block all inspection, not just SQL injection. Option D is wrong because if the WAF profile were not applied to the correct policy, no WAF inspection would occur at all, and the administrator would likely see no WAF-related logs or blocking; the question states the WAF is enabled, implying it is applied somewhere.

28
MCQeasy

A FortiGate administrator wants to prevent users from accessing a list of known malicious domains. The list is updated daily by a third-party provider and available as a plain text file over HTTPS. Which FortiGate feature should be used to ingest and block these domains?

A.FortiGuard DNS Filter with custom categories
B.External Threat Feed connector
C.Static DNS zone with blackhole
D.FortiGate local domain blocklist
AnswerB

The External Threat Feed connector can fetch a plain text list of domains from an HTTPS URL and create a dynamic address object. This object can then be used in a DNS filter or firewall policy to block access. It supports automatic updates at configured intervals, exactly matching the requirement for daily updates from a third-party provider.

Why this answer

The External Threat Feed connector is designed to import IP or domain lists from external HTTP/HTTPS sources and keep them updated. It creates a dynamic object that can be referenced in policies, providing automated blocking. The other options are either static or tied to Fortinet's own categorization, and cannot ingest a custom third-party list automatically.

Exam trap

The trap here is confusing FortiGuard's built-in DNS categories with the ability to import custom external lists, which requires the External Threat Feed connector.

29
MCQhard

A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?

A.Enable 'Security Events' with 'Log' action for all process executions.
B.Set the 'Threat Hunting' module to 'Monitor' mode for all endpoints.
C.Configure 'Exclusions' to prevent FortiEDR from scanning critical applications.
D.Use 'Playbooks' with a 'Block and Remediate' action triggered by a malicious verdict.
AnswerD

FortiEDR playbooks can automatically execute block and remediate actions when a malicious verdict is reached. This stops the malicious process, prevents command-and-control communication, and triggers collection of forensic data such as memory dumps and process trees. It directly satisfies both the containment and the forensic requirements described in the scenario.

Why this answer

FortiEDR playbooks automate responses based on verdicts. A Block and Remediate playbook can terminate the malicious process, sever command-and-control communication, and initiate forensic collection. Logging, exclusions, or monitoring alone do not provide containment, so they cannot meet the combined requirement for automated containment and detailed forensics.

Exam trap

The trap here is equating monitoring or logging features with automated containment, when only a playbook action can block, remediate, and collect forensics in one triggered workflow.

30
MCQmedium

A security administrator wants to block email spoofing attacks against their organization's domain. They configure SPF, DKIM, and DMARC records. Which protocol authenticates the domain of the email sender by verifying the email's signature against a public key published in DNS?

A.SPF
B.ARC
C.DKIM
D.DMARC
AnswerC

DKIM adds a cryptographic signature to outgoing mail, verified against a public key published in the sender domain's DNS TXT record. This authenticates the domain and confirms message integrity, satisfying the requirement to detect spoofing where the signature fails validation.

Why this answer

DKIM (DomainKeys Identified Mail) is the correct answer because it provides email authentication by allowing the sender to cryptographically sign an email with a private key. The receiving mail server then retrieves the sender's public key from a DNS TXT record and verifies the signature, confirming that the email was not tampered with and originates from a domain the sender is authorized to use.

Exam trap

The trap here is that candidates often confuse SPF's IP-based verification with DKIM's cryptographic signature verification, or they assume DMARC performs the actual authentication, when in fact DMARC only enforces policies based on SPF and DKIM results.

How to eliminate wrong answers

Option A is wrong because SPF (Sender Policy Framework) authenticates the sending server's IP address against a list of authorized IPs published in DNS, not by verifying a cryptographic signature. Option B is wrong because ARC (Authenticated Received Chain) is a protocol that preserves email authentication results across intermediate hops (forwarders or mailing lists), but it does not itself authenticate the original sender's domain via a signature. Option D is wrong because DMARC (Domain-based Message Authentication, Reporting & Conformance) is a policy framework that uses SPF and DKIM results to instruct receivers on how to handle unauthenticated email (e.g., quarantine or reject), but it does not perform signature verification itself.

31
MCQeasy

Which feature on FortiGate uses machine learning to detect never-before-seen malware based on file characteristics?

A.Machine Learning Engine
B.Outbreak Prevention
C.FortiSandbox
D.Content Disarm and Reconstruction
AnswerA

The Machine Learning Engine inspects file characteristics rather than signatures, so it identifies never-before-seen malware without prior samples. This directly satisfies the stem's requirement for detecting unknown threats through behavioural and structural analysis, unlike signature-based antivirus or sandboxing, which depend on known patterns or dynamic execution.

Why this answer

The Machine Learning Engine (option A) on FortiGate uses static file analysis and machine learning models to detect never-before-seen malware based on file characteristics such as entropy, structure, and opcode sequences, without requiring signatures or behavioral execution. This allows it to identify zero-day threats pre-execution, directly matching the question's description.

Exam trap

The trap here is that candidates often confuse FortiSandbox's dynamic analysis (which also detects unknown malware) with the Machine Learning Engine's static analysis, but the question specifically asks for detection based on file characteristics, not behavioral execution.

How to eliminate wrong answers

Option B (Outbreak Prevention) is wrong because it is a subscription-based threat intelligence service that provides real-time updates on emerging threats, but it does not use machine learning to analyze file characteristics; instead, it relies on signature updates and IoCs from FortiGuard. Option C (FortiSandbox) is wrong because it detonates files in a virtual environment to observe runtime behavior, which is dynamic analysis, not static machine learning based on file characteristics. Option D (Content Disarm and Reconstruction) is wrong because it removes active content (e.g., macros, scripts) from files and rebuilds them into safe versions, but it does not use machine learning to detect malware; it is a prevention technique that strips potential threats regardless of detection.

32
MCQmedium

An administrator configures FortiSandbox inline scanning for HTTP traffic. They notice that files uploaded via HTTP are being scanned but no verdict is being returned, causing delays. What is the MOST likely cause?

A.The FortiSandbox has reached its maximum storage capacity
B.The FortiSandbox is not registered with the FortiGate
C.The file scan timeout is too short, causing FortiGate to pass the file before a verdict is received
D.The file type is not supported by FortiSandbox
AnswerC

With inline scanning, FortiGate holds the file only until the scan timeout expires. If that timeout is shorter than FortiSandbox's verdict time, the file is released and forwarded without a verdict, producing the observed delays.

Why this answer

When FortiGate sends a file to FortiSandbox for inline scanning, it waits for a verdict before allowing the traffic to proceed. If the file scan timeout is too short, FortiGate will stop waiting for the verdict and pass the file anyway, causing the observed delay without a final verdict. This is the most likely cause because the administrator sees scanning occurring but no verdict returned, which aligns with a premature timeout rather than a failure to scan.

Exam trap

The trap here is that candidates often assume a missing verdict is due to a registration or capacity issue, but the question specifically states scanning is occurring, which eliminates options A and B, and the delay points directly to a timeout configuration problem.

How to eliminate wrong answers

Option A is wrong because if the FortiSandbox had reached maximum storage capacity, it would typically reject new submissions or fail to store results, but the file would still be scanned or an error would be returned, not a delay without verdict. Option B is wrong because if the FortiSandbox were not registered with the FortiGate, the FortiGate would not be able to send files for scanning at all, so no scanning would occur. Option D is wrong because if the file type were not supported, FortiSandbox would either skip the file or return an unsupported verdict quickly, not cause a delay without a verdict.

33
MCQmedium

A FortiGate administrator is configuring a security profile group and wants to enable inline blocking of malicious files based on FortiGuard cloud threat intelligence, without sending files to FortiSandbox. The administrator has already enabled the antivirus profile and selected the 'Block' action for infected files. Which additional setting should be configured to ensure that files identified as malicious by the FortiGuard service are blocked in real time?

A.Enable 'Scan with FortiSandbox' in the antivirus profile.
B.Enable 'FortiGuard AI-Based Inline Malware Prevention' in the antivirus profile.
C.Enable 'Use FortiSandbox Database' in the antivirus profile.
D.Configure 'External Blocklist' with a threat intelligence feed.
AnswerB

This feature uses FortiGuard AI-based malware prevention to inspect files inline and block malicious content without relying on sandbox detonation. It leverages cloud-based threat intelligence and machine learning to identify and block known and unknown malware in real time, which directly satisfies the requirement to block files identified by FortiGuard without using FortiSandbox.

Why this answer

The correct setting is 'FortiGuard AI-Based Inline Malware Prevention', which enables real-time blocking of malicious files using FortiGuard's cloud-based AI and machine learning, without the need for a FortiSandbox. This feature is part of the antivirus profile and provides inline protection against known and unknown malware, aligning with the administrator's goal of blocking based on FortiGuard intelligence.

Exam trap

The trap here is confusing FortiGuard AI-based inline prevention with FortiSandbox integration, assuming that any cloud-based file analysis requires a sandbox appliance.

34
Multi-Selectmedium

An administrator needs to configure advanced email security on FortiMail to protect against phishing and spoofing. Which THREE features should be enabled to achieve comprehensive email authentication?

Select 3 answers
A.DKIM signing and verification
B.SPF checking
C.DMARC policy enforcement
D.Anti-spam Bayesian filtering
E.TLS encryption for inbound/outbound
AnswersA, B, C

DKIM signing and verification uses cryptographic signatures to confirm message integrity and domain authenticity. FortiMail verifies signatures on inbound mail and signs outbound mail, preventing tampering and impersonation, which satisfies the authentication requirement alongside SPF and DMARC.

Why this answer

DKIM (DomainKeys Identified Mail) signing and verification is correct because it allows the sending domain to cryptographically sign outgoing emails, and the receiving server to verify that the signature matches the domain’s public DNS record. This ensures the email was not tampered with and originates from an authorized server, directly addressing phishing and spoofing by validating message integrity and sender authenticity.

Exam trap

The trap here is that candidates confuse transport security (TLS) or content filtering (Bayesian) with sender authentication protocols, forgetting that only DKIM, SPF, and DMARC directly verify domain ownership and prevent spoofing, while TLS and Bayesian filtering address different security layers (confidentiality and spam classification).

35
MCQmedium

An administrator wants to use FortiGate to automatically block traffic if FortiEDR detects a threat on an endpoint. Which feature should the administrator configure?

A.Configure a VPN tunnel between FortiGate and FortiEDR
B.Enable FortiGuard Outbreak Prevention on the antivirus profile
C.Configure a static route to the FortiEDR management IP
D.Create an automation stitch with a trigger from FortiEDR and an action to block the source IP
AnswerD

An automation stitch links a FortiEDR detection trigger to a FortiGate action that blocks the offending source IP, giving the automatic enforcement the administrator wants. The trigger-action pairing is what makes the response occur without manual intervention.

Why this answer

FortiGate integrates with FortiEDR via automation stitches, which allow events from FortiEDR (such as a detected threat) to trigger automated actions on FortiGate, such as blocking the source IP of the compromised endpoint. This provides real-time, policy-driven threat response without manual intervention, leveraging the Fortinet Security Fabric. Option A is incorrect because a VPN tunnel is not required; FortiEDR and FortiGate communicate via APIs.

Option B is incorrect because FortiGuard Outbreak Prevention is a separate service that provides threat intelligence, not direct endpoint detection integration. Option C is incorrect because a static route is unnecessary for the API-based communication.

Exam trap

The trap here is that candidates often confuse integration methods, assuming a VPN or routing change is needed for communication, when in fact FortiEDR and FortiGate communicate via the Security Fabric's REST API and automation stitches, not traditional network tunnels.

How to eliminate wrong answers

Option A is wrong because a VPN tunnel is used for secure site-to-site or remote access connectivity, not for receiving threat events from FortiEDR; FortiEDR communicates with FortiGate via REST API or Fabric connector, not VPN. Option B is wrong because FortiGuard Outbreak Prevention is a signature-based feature within antivirus profiles that blocks known outbreaks based on FortiGuard threat intelligence, not a mechanism to receive and act on FortiEDR-specific endpoint detections. Option C is wrong because a static route is used for IP routing and does not enable event-driven communication or automation between FortiEDR and FortiGate; the integration requires API-based triggers, not routing entries.

36
MCQeasy

An administrator wants to block a zero-day malware outbreak detected by FortiGuard. Which feature should be configured to automatically block the threat across all enabled FortiGate devices?

A.FortiSandbox Cloud
B.IPS Custom Signatures
C.FortiGuard Outbreak Prevention
D.Application Control
AnswerC

FortiGuard Outbreak Prevention pushes indicators and IPS signatures for active outbreaks to every licensed FortiGate, blocking the zero-day automatically without manual signature authoring. This satisfies the requirement for immediate, fleet-wide blocking rather than per-device configuration.

Why this answer

FortiGuard Outbreak Prevention (option C) is the correct feature because it automatically pushes signatures to all FortiGate devices enrolled in the same FortiGuard network when a new zero-day malware outbreak is detected. This enables immediate, coordinated blocking without manual intervention, which is exactly what the administrator needs for a fast-spreading threat.

Exam trap

The trap here is that candidates often confuse FortiSandbox Cloud with a real-time blocking mechanism, but FortiSandbox Cloud provides analysis and retrospective detection, not automatic, proactive blocking across all devices like Outbreak Prevention does.

How to eliminate wrong answers

Option A is wrong because FortiSandbox Cloud is a sandboxing service that analyzes suspicious files and behaviors, but it does not automatically push blocking signatures to all FortiGate devices; it provides detection results that require manual or policy-based action. Option B is wrong because IPS Custom Signatures are manually created by the administrator to block specific known patterns; they cannot be automatically generated or distributed by FortiGuard for a zero-day outbreak. Option D is wrong because Application Control is designed to manage and block specific applications based on signatures, not to respond to zero-day malware outbreaks with automatically distributed threat intelligence.

37
Multi-Selectmedium

An administrator is configuring FortiGate automation stitches to respond to a detected ransomware outbreak. The trigger is a high severity event from FortiSandbox. Which TWO actions can be used in an automation stitch to contain the threat?

Select 2 answers
A.Create a new FortiGate administrator account
B.Send an SNMP trap to a monitoring system
C.Change the SSID of a wireless network
D.Execute a CLI script to block the infected host's IP address
E.Quarantine the endpoint using FortiClient EMS integration
AnswersD, E

CLI scripts can be used to block IPs via firewall policies or blacklist.

Why this answer

Executing a CLI script to block the infected host's IP address directly on the FortiGate allows immediate containment by applying a firewall policy or address-based block, which is a standard action in automation stitches for threat response. Option E is correct because quarantining the endpoint via FortiClient EMS integration leverages the FortiClient endpoint agent to isolate the infected device from the network, which is a supported action in automation stitches for ransomware containment.

Exam trap

The trap here is that candidates may confuse notification actions (like SNMP traps) or administrative changes (like creating accounts) with actual containment actions, failing to recognize that only actions that actively block or isolate the threat (CLI script or EMS quarantine) are valid in an automation stitch for ransomware response.

38
MCQmedium

A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?

A.Server-Side Request Forgery
B.Command Injection
C.SQL Injection
D.Cross-Site Scripting
AnswerC

The SQL Injection signature category contains patterns matching SQL syntax manipulation in HTTP requests. Enabling it lets the WAF inspect parameters and block injection attempts, directly satisfying the requirement to block SQL injection attacks against the public web server.

Why this answer

SQL injection attacks specifically target database queries by injecting malicious SQL statements through input fields. FortiGate's WAF signature category for SQL Injection is designed to detect and block these patterns, such as 'OR 1=1' or UNION-based injections, by matching against known attack signatures in the HTTP request payload.

Exam trap

The trap here is that candidates may confuse SQL Injection with Command Injection (Option B) because both involve injection attacks, but SQL Injection targets database layers via SQL syntax, while Command Injection targets the OS shell via system commands.

How to eliminate wrong answers

Option A is wrong because Server-Side Request Forgery (SSRF) is an attack that forces a server to make internal requests, not directly related to SQL injection; FortiGate's WAF has a separate signature category for SSRF. Option B is wrong because Command Injection involves executing system commands (e.g., via shell metacharacters) on the server, not database queries, and is covered by a different WAF signature category. Option D is wrong because Cross-Site Scripting (XSS) injects client-side scripts into web pages viewed by other users, targeting browsers rather than the database backend, and is handled by its own WAF signature category.

39
MCQmedium

A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?

A.Web filter profile with a URL filter entry set to block
B.IPS sensor with a custom signature that matches the domain name in DNS queries
C.Application control profile with a signature to block the botnet application
D.DNS filter profile with a static domain filter entry set to block
AnswerD

A DNS filter profile allows the administrator to create a static domain filter that blocks or allows specific domains. When applied to a firewall policy, FortiGate inspects DNS queries and blocks resolution for the malicious domain, preventing hosts from learning the IP address. This directly addresses the requirement to block DNS resolution before a connection is attempted.

Why this answer

The DNS filter profile is designed to inspect DNS queries and can block resolution of specific domains using static domain filters. When applied to a policy, it prevents internal hosts from resolving malicious domains, effectively stopping connections before they start. Other features like web filter or application control operate at later stages and do not block DNS resolution.

Exam trap

The trap here is assuming that blocking a URL or application also blocks DNS resolution, but DNS filtering must be configured separately to prevent domain resolution.

40
MCQeasy

A FortiGate administrator wants to ensure that files in email attachments are disarmed before delivery. Which security feature should be configured in the antivirus profile?

A.Content Disarm and Reconstruction (CDR)
B.FortiSandbox inline scanning
C.Machine Learning Engine
D.Outbreak Prevention
AnswerA

Content Disarm and Reconstruction strips active content from email attachments, rebuilding each file into a safe, functional equivalent before delivery. This satisfies the stem's requirement to disarm files rather than merely detect known threats, unlike signature-based antivirus scanning, which cannot neutralise zero-day or weaponised payloads embedded in documents.

Why this answer

Content Disarm and Reconstruction (CDR) is the correct answer because it is specifically designed to remove active content (e.g., macros, scripts, embedded objects) from email attachments and rebuild them into safe, sanitized versions before delivery. Unlike detection-based methods, CDR proactively disarms threats by stripping potentially malicious elements while preserving the file's usability, making it the ideal choice for disarming attachments in an antivirus profile.

Exam trap

The trap here is that candidates often confuse detection-based features like FortiSandbox or Machine Learning with proactive disarming, assuming that any advanced threat protection feature can 'disarm' files, whereas CDR is the only option that actively reconstructs attachments to remove active content.

How to eliminate wrong answers

Option B is wrong because FortiSandbox inline scanning is a behavioral analysis feature that detonates files in a sandbox to detect threats, but it does not actively strip or reconstruct file content; it relies on detection and blocking, not proactive disarming. Option C is wrong because the Machine Learning Engine uses statistical models to classify files as malicious or benign based on patterns, but it does not modify or reconstruct attachments to remove active content. Option D is wrong because Outbreak Prevention is a FortiGuard service that provides real-time signatures and intelligence for emerging threats, but it is a detection and prevention mechanism, not a file sanitization or reconstruction technology.

41
MCQmedium

A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?

A.The FortiSandbox is configured to use 'Analysis' mode instead of 'Inline' mode.
B.The FortiGate is using a different protocol for file submission than for verdict retrieval.
C.The FortiSandbox is not licensed for verdict submission.
D.The FortiGate is not configured with the correct FortiSandbox IP address and API key.
AnswerD

For FortiSandbox to return verdicts to FortiGate, the FortiGate must be configured with the FortiSandbox's IP address and a valid API key. If these are incorrect or missing, the FortiGate cannot authenticate or receive verdicts. The administrator should verify this configuration to ensure verdicts are delivered and acted upon.

Why this answer

The most common reason for missing verdicts is incorrect integration settings on the FortiGate. The FortiGate must have the FortiSandbox's IP address and API key configured correctly to receive verdicts. Without this, files may be submitted, but the firewall cannot authenticate or retrieve results, so blocking does not occur.

Verifying these settings resolves the issue.

Exam trap

The trap here is assuming that licensing or analysis mode affects verdict delivery, when the primary cause is often a misconfigured API key or IP address on the FortiGate.

42
Multi-Selectmedium

An organization wants to implement email authentication to prevent spoofing and phishing attacks. They use FortiMail as their email security gateway. Which THREE mechanisms should they configure to achieve comprehensive email authentication?

Select 3 answers
A.Transport Layer Security (TLS) for SMTP
B.FortiGuard Antispam
C.Sender Policy Framework (SPF)
D.Domain-based Message Authentication, Reporting and Conformance (DMARC)
E.DomainKeys Identified Mail (DKIM)
AnswersC, D, E

SPF verifies that the sending server is authorized by the domain owner.

Why this answer

Sender Policy Framework (SPF) is correct because it allows the domain owner to publish a DNS TXT record listing authorized sending IP addresses, enabling receiving mail servers (like FortiMail) to verify that the email originated from an approved source. This directly prevents spoofing by rejecting messages from unauthorized IPs claiming to be from the domain.

Exam trap

The trap here is that candidates confuse encryption (TLS) or antispam filtering with authentication mechanisms, failing to recognize that SPF, DKIM, and DMARC are the three complementary protocols specifically designed for email authentication and spoofing prevention as defined in RFC 7208, RFC 6376, and RFC 7489.

43
MCQmedium

An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?

A.Potentially Unwanted Program
B.Newly Observed Domain
C.Malicious Websites
D.Dynamic DNS
AnswerB

The Newly Observed Domain category is designed to flag domains that have recently appeared and are frequently associated with malicious activity such as phishing. Blocking this category provides proactive protection without manual submissions and typically has low false-positive impact on established business domains, making it the appropriate choice for this requirement.

Why this answer

Newly Observed Domain is a FortiGuard category that identifies domains registered recently, which are disproportionately used in phishing and malware campaigns. Blocking it provides proactive protection against unknown malicious domains without manual URL submission. Other categories either target different threat types or are reactive, so they do not meet the requirement for minimal-impact, automated blocking of newly registered domains.

Exam trap

The trap here is confusing the reactive Malicious Websites category with the proactive Newly Observed Domain category, which is specifically intended for recently registered domains.

44
MCQeasy

A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?

A.Antivirus
B.Email Filter
C.Web Filter
D.IPS
AnswerA

Antivirus scanning inspects SMTP traffic inline, extracting and examining attachments against FortiGuard signatures to block malicious files before delivery to internal users. Configuring it on the firewall policy governing outbound and inbound mail satisfies the requirement to protect users from email-borne malware at the network perimeter.

Why this answer

FortiGate's Antivirus feature is designed to scan SMTP traffic for malware by inspecting email attachments and body content against virus signatures. When configured in a security policy, it intercepts SMTP sessions, buffers the email data, and performs real-time scanning to block or quarantine malicious files before delivery to internal users.

Exam trap

The trap here is that candidates confuse 'Email Filter' (which handles spam and content filtering) with antivirus scanning, assuming email security is solely about filtering, when in fact malware detection requires the dedicated Antivirus feature to inspect SMTP payloads at the file level.

How to eliminate wrong answers

Option B (Email Filter) is wrong because it focuses on spam filtering, content blocking, and email address/domain blacklisting, not on malware detection in attachments. Option C (Web Filter) is wrong because it controls HTTP/HTTPS traffic to block malicious URLs and web content, not SMTP email traffic. Option D (IPS) is wrong because it detects and prevents network-level attacks (e.g., exploits, buffer overflows) based on signatures, but it does not perform file-level malware scanning on email attachments.

45
MCQmedium

An administrator wants to block outbound traffic from internal hosts to known malicious domains without relying on full URL inspection or certificate inspection. The requirement is to use a lightweight DNS-based security service on FortiGate that can block botnet C2 and phishing domains. Which FortiGuard feature should the administrator enable and configure in a DNS filter profile?

A.FortiGuard Anti-Spam
B.FortiGuard IP Reputation
C.FortiGuard DNS Filter
D.FortiGuard Web Filter
AnswerC

FortiGuard DNS Filter uses the FortiGuard DNS rating service to categorize and block malicious domains at the DNS resolution stage. It requires a DNS filter profile applied to a policy, with the FortiGuard category set to block botnet C2, phishing, and other malicious categories. This matches the requirement to block outbound traffic to malicious domains without full URL or certificate inspection.

Why this answer

FortiGuard DNS Filter is the correct choice because it provides DNS-layer security by categorizing and blocking malicious domains using FortiGuard's DNS rating service. It is lightweight and does not require full URL inspection or certificate inspection. Enabling it in a DNS filter profile and applying it to a firewall policy allows the FortiGate to block botnet C2 and phishing domains effectively.

Exam trap

The trap here is confusing DNS filtering with web filtering, assuming that web filtering can block domains at the DNS layer without SSL inspection.

46
MCQmedium

An organization wants to deploy a web application firewall (WAF) to protect a public-facing web application. They are evaluating FortiGate versus FortiWeb. Which of the following is a key advantage of using FortiWeb over FortiGate for WAF functionality?

A.FortiWeb offers advanced bot detection and positive security model
B.FortiGate can perform SSL deep inspection without performance impact
C.FortiGate supports a larger number of web servers behind a single policy
D.FortiGate can automatically patch web application vulnerabilities
AnswerA

FortiWeb provides dedicated WAF engines with machine-learning bot detection and a positive security model that whitelists known-good behaviour, unlike FortiGate's signature-based IPS approach. This satisfies the requirement for advanced application-layer protection against automated threats and zero-day attacks targeting the public-facing application.

Why this answer

FortiWeb is a dedicated web application firewall that provides advanced bot detection and a positive security model, which allows only explicitly allowed traffic based on a whitelist of known good patterns. This is a key advantage over FortiGate, which primarily uses a negative security model (signature-based) and lacks the same depth of bot mitigation and positive enforcement for web-specific threats.

Exam trap

The trap here is that candidates assume FortiGate's integrated WAF features are equivalent to a dedicated WAF, but FortiWeb's positive security model and advanced bot detection are unique differentiators that FortiGate lacks.

How to eliminate wrong answers

Option B is wrong because FortiGate, like any device performing SSL deep inspection, incurs performance overhead due to decryption/re-encryption, and FortiGate does not claim zero performance impact. Option C is wrong because FortiGate does not inherently support a larger number of web servers behind a single policy; both platforms can scale, but FortiWeb is specifically optimized for high-volume web server pools with granular per-server policies. Option D is wrong because neither FortiGate nor FortiWeb automatically patches web application vulnerabilities; they detect and block exploit attempts but do not modify application code.

47
MCQmedium

An administrator wants to use FortiGate to block outbound traffic to known malicious IP addresses based on a threat intelligence feed. They configure a threat feed connector and a firewall policy with a destination address group. However, the policy is not blocking traffic to the malicious IPs. What is the most likely cause?

A.The destination address group does not include the threat feed connector object.
B.The threat feed connector is not enabled in the security fabric settings.
C.The threat feed connector is configured with the wrong protocol (HTTP instead of HTTPS).
D.The firewall policy is placed after a more permissive policy that allows the traffic.
AnswerD

FortiGate processes firewall policies in top-down order. If a more permissive policy above the blocking policy allows the traffic, the blocking policy is never evaluated. This is a common misconfiguration. The administrator should move the blocking policy above the permissive policy or adjust the permissive policy.

Why this answer

FortiGate evaluates firewall policies sequentially. If a permissive policy appears above the blocking policy, traffic is allowed and never reaches the blocking rule. Placing the blocking policy before any permissive policies ensures malicious traffic is denied.

Exam trap

The trap here is focusing on the threat feed configuration while overlooking the fundamental firewall policy processing order.

48
MCQmedium

A company wants to receive threat intelligence feeds from external sources to enhance their FortiGate's protection. Which method should be used to integrate external threat feeds into FortiGate?

A.Use FortiGuard Threat Intelligence Service which automatically pulls feeds.
B.Manually add IP addresses to local address objects.
C.Configure an external threat feed connector in FortiGate, such as using a URL to a STIX/TAXII feed.
D.Use FortiAnalyzer to push feeds to FortiGate.
AnswerC

Configuring an external threat feed connector lets FortiGate ingest STIX/TAXII feeds directly from external providers, satisfying the requirement to receive third-party threat intelligence. FortiOS polls the feed URL and populates threat feed objects, which external connectors then reference in firewall policies, blocklists and DNS filters without manual updates.

Why this answer

FortiGate supports integration with external threat intelligence feeds via the External Threat Feed connector, which can consume STIX/TAXII feeds from a URL. This allows the FortiGate to dynamically update its threat database with indicators from third-party sources, enhancing its protection without relying solely on FortiGuard services.

Exam trap

The trap here is that candidates may confuse FortiGuard's built-in threat intelligence service with the ability to integrate external feeds, assuming FortiGuard can be customized to pull from third-party sources, when in fact the External Threat Feed connector is the dedicated feature for that purpose.

How to eliminate wrong answers

Option A is wrong because FortiGuard Threat Intelligence Service is a built-in Fortinet service that provides curated feeds, not a method to integrate external third-party feeds; it cannot be configured to pull from arbitrary external sources. Option B is wrong because manually adding IP addresses to local address objects is a static, labor-intensive approach that does not support automated, dynamic updates from external threat feeds, defeating the purpose of real-time intelligence integration. Option D is wrong because FortiAnalyzer is a log management and analytics platform, not a mechanism to push threat feeds to FortiGate; it can forward logs or events but does not handle external feed ingestion for threat intelligence updates.

49
MCQmedium

An organization deploys FortiEDR to protect endpoints. Which component is responsible for collecting and sending telemetry data to the FortiEDR management console?

A.FortiGate firewall
B.FortiEDR Sensor (Agent)
C.FortiAnalyzer
D.FortiClient EMS
AnswerB

The FortiEDR Sensor, installed on each endpoint, performs continuous event collection and forwards normalised telemetry to the management console, satisfying the stem's requirement for the collecting and sending component. Unlike the Central Manager or Aggregator, which handle policy and correlation, the Sensor is the sole endpoint-resident agent generating raw telemetry.

Why this answer

The FortiEDR Sensor (Agent) is the endpoint-resident component that collects telemetry data—such as process creation, network connections, file system changes, and registry modifications—and securely transmits it to the FortiEDR management console (Controller) for analysis and threat detection. Without the sensor, the management console has no visibility into endpoint activity.

Exam trap

The trap here is that candidates often confuse FortiClient EMS (which manages endpoint policies) with the FortiEDR Sensor, assuming that EMS handles telemetry collection, when in fact the sensor is a separate, dedicated agent for endpoint detection and response.

How to eliminate wrong answers

Option A is wrong because FortiGate is a next-generation firewall that provides network security and can integrate with FortiEDR via API or syslog, but it does not collect or send endpoint telemetry data to the FortiEDR management console. Option C is wrong because FortiAnalyzer is a centralized logging and reporting appliance that aggregates logs from Fortinet devices (e.g., FortiGate, FortiMail) but does not act as the telemetry collection agent for FortiEDR endpoints. Option D is wrong because FortiClient EMS manages endpoint compliance, VPN, and web filtering policies, and while it can integrate with FortiEDR, it is not the component that collects and sends endpoint telemetry to the FortiEDR console.

50
MCQmedium

A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?

A.Configure the policy to use full SSL inspection and import the pinned applications' certificates as trusted CAs on the FortiGate.
B.Disable SSL inspection entirely on the policy and rely on the application control profile to identify the pinned applications.
C.Create an exemption in the SSL inspection profile for the pinned applications and apply deep inspection to the remaining traffic.
D.Set the SSL inspection profile to certificate-inspection for the policy and leave the rest of the traffic uninspected.
AnswerC

An SSL exemption lets the FortiGate bypass decryption for specified destinations or applications that use certificate pinning, while deep inspection continues for all other HTTPS traffic. This satisfies the goal of inspecting as much traffic as possible without breaking the pinned applications, and it is the supported way to handle pinned or sensitive traffic in a deep-inspection policy.

Why this answer

Deep inspection is required to examine encrypted traffic for threats, but certificate-pinned applications will reject the FortiGate's re-signed certificate. The supported approach is to add those applications or destinations to an SSL exemption so they are not decrypted, while deep inspection continues for everything else. This balances security visibility with application availability and is the recommended operational practice for mixed traffic.

Exam trap

The trap here is assuming that disabling SSL inspection or importing certificates is an acceptable substitute for a targeted SSL exemption when certificate-pinned applications must keep working.

51
MCQhard

An administrator configures email authentication (SPF, DKIM, DMARC) on FortiMail. They find that legitimate emails are being marked as spam by FortiMail. The SPF check passes but DKIM fails. What could be the issue?

A.The SPF record is too strict
B.The email was forwarded by an intermediary that strips the DKIM signature
C.FortiMail has a bug in the DKIM verification module
D.The DMARC policy is set to reject
AnswerB

DKIM validates a signature over specific headers and body. An intermediary forwarding the message can modify or strip those elements, invalidating the signature, so DKIM fails even though SPF still passes on the sending path.

Why this answer

When an email is forwarded by an intermediary (e.g., a mailing list or forwarding service), the intermediary often modifies the message headers or body, which invalidates the DKIM signature. Since DKIM relies on a cryptographic hash of the original message content and selected headers, any alteration—even by a legitimate forwarder—causes the signature verification to fail. The SPF check passes because the forwarding server may be authorized in the SPF record, but DKIM failure triggers spam classification if the DMARC policy is not aligned.

Exam trap

The trap here is that candidates assume DKIM failure is always due to a misconfiguration on the sending side, rather than recognizing that forwarding or intermediary modification is a common and legitimate cause of DKIM breakage.

How to eliminate wrong answers

Option A is wrong because a strict SPF record (e.g., -all) would cause SPF to fail, not pass; the question states SPF passes, so this is irrelevant. Option C is wrong because FortiMail's DKIM verification module is RFC 6376 compliant and does not have a known bug that would cause legitimate DKIM signatures to fail; this is a red herring. Option D is wrong because DMARC policy (p=reject) only dictates how receivers handle messages that fail both SPF and DKIM alignment; it does not cause DKIM to fail—it is an action based on the result, not the cause of the failure.

52
Multi-Selecthard

An organization is deploying FortiEDR to enhance endpoint protection. Which THREE capabilities does FortiEDR provide? (Choose three.)

Select 3 answers
A.Forensic investigation and root cause analysis
B.Decoy deployment to lure attackers
C.Real-time threat detection using behavioral analysis
D.Automated response to isolate compromised endpoints
E.Email security filtering
AnswersA, C, D

FortiEDR provides detailed forensic data for investigation.

Why this answer

FortiEDR provides forensic investigation and root cause analysis by recording detailed endpoint telemetry, including process creation, network connections, and file system changes. This allows security teams to reconstruct the full attack chain after an incident, identifying the initial infection vector and all subsequent malicious activities. The platform correlates these events across multiple endpoints to provide a comprehensive timeline for investigation.

Exam trap

The trap here is that candidates may confuse FortiEDR's capabilities with those of other Fortinet products, such as assuming decoy deployment (FortiDeceptor) or email filtering (FortiMail) are part of FortiEDR's endpoint protection suite.

53
MCQmedium

A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?

A.Web filter with FortiGuard category-based blocking
B.Application control with botnet signatures
C.DNS filter with botnet C&C domain blocking enabled
D.Antivirus profile with botnet C&C IP blocking
AnswerC

FortiGate's DNS filter, when configured with botnet C&C domain blocking, intercepts DNS responses for known malicious domains and redirects them to a sinkhole IP, preventing resolution. This directly addresses the scenario where malicious domains are not being blocked despite FortiGuard category blocking being active, because category blocking alone may not cover all C&C domains unless DNS filtering is enforced.

Why this answer

The DNS filter with botnet C&C domain blocking is designed to intercept DNS responses for known malicious domains and redirect them to a sinkhole, effectively preventing communication. This is the correct mechanism when the goal is to block DNS resolution of malicious domains. Other features operate at different layers and do not provide DNS-level sinkholing, so they would not address the specific problem.

Exam trap

The trap here is assuming that FortiGuard category-based web filtering alone will block all malicious domains, but it does not intercept DNS queries unless DNS filtering with botnet C&C blocking is enabled.

54
MCQhard

A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?

A.Static URL filter with the action set to 'Block' and the type set to 'Simple'.
B.FortiGuard web filter category override using a local category definition.
C.DNS filter with a custom blocklist entry for the domain.
D.Application control signature that matches the domain's HTTP header.
AnswerA

A static URL filter entry of type 'Simple' can match a specific URL or domain and apply the 'Block' action regardless of the FortiGuard category. This override takes precedence over category-based filtering, which is why the domain is blocked even though it is categorized as 'Unrated'. The custom blocklist is implemented through static URL filter entries that are evaluated before category actions.

Why this answer

A static URL filter entry with the action set to Block and type Simple allows an administrator to block specific URLs or domains regardless of their FortiGuard category. This is why a domain categorized as Unrated can still be blocked and present a block page. The static URL filter is evaluated as part of the web filter profile and overrides category-based actions.

Exam trap

The trap here is assuming that a block page always reflects the FortiGuard category action, when a static URL filter entry can enforce blocking independently of the category.

55
MCQeasy

A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?

A.Data Leak Prevention profile
B.Antivirus profile with SSL inspection
C.Web Filtering profile
D.Intrusion Prevention profile
AnswerB

The antivirus profile, when combined with SSL inspection, decrypts TLS sessions so the malware signatures and CDR engines can examine payloads hidden inside encrypted channels. This satisfies the requirement to block advanced malware using encrypted command-and-control traffic.

Why this answer

An Antivirus profile with SSL inspection enabled is required to decrypt encrypted C2 (command-and-control) traffic so that FortiGate can inspect the payload for malware signatures, heuristics, and behavioral patterns. Without SSL inspection, the ATP engine cannot see inside the encrypted tunnel, rendering the antivirus and other security profiles ineffective against encrypted C2 communications.

Exam trap

The trap here is that candidates often assume IPS or Web Filtering alone can block encrypted C2 traffic, but without SSL inspection, these profiles cannot see inside the encrypted tunnel, making the Antivirus profile with SSL inspection the only correct choice for detecting malware in encrypted communications.

How to eliminate wrong answers

Option A is wrong because a Data Leak Prevention (DLP) profile focuses on detecting and preventing unauthorized transmission of sensitive data (e.g., credit card numbers, PII) and does not perform SSL inspection or detect advanced malware C2 traffic. Option C is wrong because a Web Filtering profile controls access to URLs and categories (e.g., blocking malicious sites) but does not decrypt or inspect the content of encrypted sessions for malware payloads. Option D is wrong because an Intrusion Prevention profile (IPS) detects and blocks network-level exploits and vulnerabilities, but without SSL inspection, it cannot analyze encrypted C2 traffic; IPS relies on decrypted traffic to match signatures.

56
MCQhard

An admin configures Content Disarm and Reconstruction (CDR) on FortiGate to protect against malicious macros in Office documents. After applying the CDR profile to a firewall policy, users complain that documents are not being delivered. What is the most likely cause?

A.The CDR profile has 'File Filter' enabled that blocks the file type
B.The FortiGate is running in transparent mode
C.The firewall policy is configured for flow-based inspection
D.The antivirus profile is not applied to the same policy
AnswerC

CDR requires proxy-based inspection because it must buffer and reconstruct the entire file before delivery; flow-based inspection cannot perform this. The stem's constraint is documents not being delivered, which occurs because the CDR profile is silently bypassed under flow mode, so files are dropped or left unscanned rather than disarmed and forwarded.

Why this answer

CDR requires proxy-based inspection to intercept, disarm, and reconstruct documents. Flow-based inspection bypasses the deep inspection engine, so CDR cannot process the files, causing delivery failures. FortiGate must use proxy-based inspection mode for CDR to function correctly.

Exam trap

The trap here is that candidates assume CDR is a simple file-filtering feature that works regardless of inspection mode, but Fortinet explicitly restricts CDR to proxy-based inspection, making flow-based mode a common misconfiguration that causes silent delivery failures.

How to eliminate wrong answers

Option A is wrong because File Filter in a CDR profile controls which files are submitted for disarming, not whether they are blocked; if enabled, it would filter files before CDR, not prevent delivery after processing. Option B is wrong because transparent mode does not affect CDR functionality; CDR works in both transparent and NAT modes as long as proxy-based inspection is used. Option D is wrong because CDR operates independently of antivirus; while AV profiles can complement CDR, they are not required for CDR to deliver documents, and their absence would not cause delivery failure.

57
Multi-Selectmedium

A security administrator is configuring a FortiGate to use an external threat intelligence feed via a Threat Feed connector. The administrator wants to ensure that the firewall automatically blocks traffic to malicious IP addresses and domains from the feed. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Configure a DNS filter profile to block the domains from the feed.
B.Set the feed connector to 'malware' category in the security fabric settings.
C.Create a firewall address object that references the external threat feed connector.
D.Enable 'Block traffic from malicious sources' in the antivirus profile.
E.Create an external threat feed connector and specify the feed URL and refresh interval.
AnswersC, E

After creating the connector, you must create a firewall address object that references it. This object represents the dynamic list of IPs or domains from the feed. It is then used in firewall policies or other security profiles to enforce blocking. Without this address object, the feed data cannot be used in policies.

Why this answer

To use an external threat feed on FortiGate, you first create the external threat feed connector with the feed URL and refresh interval, then create a firewall address object that references that connector. The address object can then be used in firewall policies to block or allow traffic. Other options like antivirus profiles or DNS filters do not integrate directly with external threat feeds for IP/domain blocking.

Exam trap

The trap here is confusing external threat feed integration with antivirus or DNS filter profiles, which do not automatically consume the feed connector.

58
MCQmedium

A network admin wants to use FortiClient's advanced threat protection features to detect ransomware behavior on endpoints. Which FortiClient feature should be enabled?

A.Advanced Threat Protection
B.Web Filtering
C.Application Firewall
D.Vulnerability Scan
AnswerA

FortiClient's Advanced Threat Protection feature performs behavioural monitoring and signature-based detection on endpoints, identifying ransomware encryption patterns and blocking malicious processes. Enabling it satisfies the stem's requirement to detect ransomware behaviour, since the other FortiClient modules cover web filtering, antivirus scanning or VPN connectivity rather than behavioural threat detection.

Why this answer

FortiClient's Advanced Threat Protection (ATP) feature is specifically designed to detect and block ransomware behavior by using real-time behavioral analysis, machine learning, and exploit prevention. Unlike other features, ATP monitors process behavior for indicators of compromise (IoCs) such as mass file encryption or unauthorized file access patterns, making it the correct choice for ransomware detection.

Exam trap

The trap here is that candidates confuse 'Advanced Threat Protection' with general security features like web filtering or application control, not realizing that ATP is the only feature that performs behavioral analysis on endpoint processes to detect ransomware.

How to eliminate wrong answers

Option B (Web Filtering) is wrong because it controls access to URLs and categories but does not analyze endpoint process behavior for ransomware. Option C (Application Firewall) is wrong because it controls network traffic based on application signatures and policies, not local process behavior or file system anomalies. Option D (Vulnerability Scan) is wrong because it identifies missing patches and configuration weaknesses but does not provide real-time behavioral detection of ransomware execution.

59
MCQmedium

Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?

A.FortiSIEM
B.FortiSandbox
C.FortiDeceptor
D.FortiEDR
AnswerA

FortiSIEM aggregates logs and events from disparate network devices, then correlates them to surface unified threat views. This collection-and-correlation mechanism directly satisfies the stem's requirement for a single consolidated picture of threats across the network.

Why this answer

FortiSIEM is the correct answer because it is specifically designed as a Security Information and Event Management (SIEM) solution that aggregates, normalizes, and correlates logs and events from diverse sources—including firewalls, endpoints, servers, and cloud platforms—into a single pane of glass. It uses a patented event correlation engine and a unified event database to detect multi-stage attack patterns and provide actionable threat intelligence, fulfilling the requirement for a unified view of threats across the network.

Exam trap

The trap here is that candidates often confuse FortiSandbox or FortiEDR as the central correlation tool because they are prominent in the Fortinet Advanced Threat Protection (ATP) framework, but they lack the multi-source event aggregation and correlation that is the defining function of a SIEM like FortiSIEM.

How to eliminate wrong answers

Option B (FortiSandbox) is wrong because it is a threat detection and analysis appliance that focuses on executing suspicious files in a virtualized environment to identify zero-day malware, not on collecting and correlating security events from multiple sources. Option C (FortiDeceptor) is wrong because it is a deception-based threat detection platform that deploys decoys and lures to trap attackers, but it does not aggregate or correlate events from external sources; it only generates alerts from its own decoys. Option D (FortiEDR) is wrong because it is an endpoint detection and response solution that monitors and responds to threats on individual endpoints, but it lacks the centralized event correlation and multi-source aggregation capabilities of a SIEM.

60
MCQeasy

A network security administrator wants to use FortiGate to automatically quarantine an endpoint when FortiEDR detects malicious behavior on that endpoint. Which FortiGate feature should be used to integrate with FortiEDR for this purpose?

A.FortiGate IPsec VPN with dynamic routing to isolate the endpoint.
B.FortiGate antivirus profile with 'Block' action for all detected threats.
C.FortiGate DNS filter with a blocklist of the endpoint's IP address.
D.FortiGate Fabric Connector for FortiEDR with automated response actions.
AnswerD

The FortiGate Fabric Connector for FortiEDR allows the FortiGate to receive threat information and trigger automated responses, including quarantining the endpoint or blocking its traffic. This integration is part of the Security Fabric and is the intended way to coordinate endpoint detection with network enforcement. It directly enables the automatic quarantine action described in the scenario.

Why this answer

The FortiGate Fabric Connector for FortiEDR enables integration between the endpoint detection and response platform and the FortiGate. When FortiEDR identifies malicious behavior, the connector can trigger automated actions such as quarantining the endpoint or blocking its network access. This is the correct feature for coordinating endpoint detection with network enforcement in the Security Fabric.

Exam trap

The trap here is confusing general network security profiles, such as antivirus or DNS filtering, with the specific Fabric Connector integration that enables automated endpoint quarantine based on FortiEDR detections.

61
Multi-Selectmedium

A network admin is troubleshooting why FortiGate's antivirus is not detecting a known malware sample. The sample is detected by other scanners. Which two checks should the admin perform? (Choose two.)

Select 2 answers
A.Verify that the FortiGuard Antivirus subscription is active
B.Check that the file is not excluded by a file filter
C.Ensure the firewall policy is configured for proxy-based inspection
D.Check the antivirus database version against the latest available
E.Confirm that the antivirus profile has 'Scan on Delivery' enabled
AnswersA, D

Without a valid subscription, signatures are not updated.

Why this answer

FortiGate's antivirus engine relies on a valid FortiGuard Antivirus subscription to download and update the virus signature database. If the subscription has expired, the engine cannot receive new signatures, causing it to miss recently discovered malware samples that other scanners with active subscriptions detect.

Exam trap

The trap here is that candidates often confuse 'file filter' exclusions with antivirus signature exclusions, or assume proxy-based inspection is mandatory for antivirus, when in fact flow-based inspection also supports antivirus scanning.

62
MCQhard

A security analyst is investigating a recent security incident and wants to use FortiGate's Security Fabric to gather threat intelligence. The analyst needs to view detailed information about a detected threat, including the source, destination, and the specific IPS signature that triggered. Which FortiGate feature provides a centralized view of threat events and allows drill-down into individual incidents?

A.FortiView
B.FortiAnalyzer
C.FortiSandbox
D.FortiGuard Outbreak Prevention
AnswerA

FortiView provides a centralized dashboard that aggregates logs and events from various FortiGate features, including IPS, antivirus, and web filtering. It allows drill-down into specific threats, showing source, destination, and signature details. This makes it ideal for incident investigation and threat intelligence gathering within the Security Fabric.

Why this answer

FortiView is a built-in FortiGate feature that aggregates and visualizes threat events from multiple security functions, including IPS, antivirus, and web filtering. It allows administrators to drill down into specific incidents to see source, destination, and signature details, making it a powerful tool for threat investigation within the Security Fabric.

Exam trap

The trap here is confusing proactive blocking features like Outbreak Prevention with analytical tools like FortiView, or assuming that external appliances like FortiAnalyzer are required for centralized views.

63
Multi-Selectmedium

A security administrator is configuring FortiSandbox integration to automatically block malicious files detected in email attachments. Which TWO actions are required to achieve this integration?

Select 2 answers
A.Configure FortiGate to submit files to FortiSandbox for analysis
B.Deploy FortiClient endpoints with full disk encryption
C.Configure FortiSandbox to send SNMP traps when a file is malicious
D.Enable FortiGate's machine learning engine on the antivirus profile
E.Enable 'Block malicious files detected by FortiSandbox' in the antivirus profile
AnswersA, E

File submission is required so FortiSandbox can analyze files.

Why this answer

FortiGate must be configured to submit files to FortiSandbox for analysis, which is the foundational step to enable detection of malicious content in email attachments. This submission is typically done via the FortiGate antivirus profile, where the 'FortiSandbox' inline scanning option is enabled, allowing files to be sent to FortiSandbox for verdict-based blocking.

Exam trap

The trap here is that candidates often confuse the requirement for FortiSandbox to send SNMP traps (which is only for alerting) with the actual blocking action, or they mistakenly think that enabling the machine learning engine alone provides sandbox integration, when in fact it is a separate local detection feature.

64
MCQhard

A security team uses FortiSandbox in a FortiGate security fabric. They want files that receive a 'Malicious' verdict to be automatically quarantined and their source endpoints isolated without manual intervention. Which combination of Fortinet components and features must be configured to achieve this automated response?

A.FortiGate 'Security Fabric' connectors with FortiAnalyzer playbooks to push blocklists to FortiMail.
B.FortiSandbox 'Automation stitches' with FortiGate and FortiClient EMS to trigger quarantine and endpoint isolation.
C.FortiGate 'Threat Feed' with FortiGuard IOC service and manual firewall policy updates.
D.FortiSandbox 'Scan Profile' with 'Block Malicious Files' enabled and FortiGate AV quarantine.
AnswerB

FortiSandbox automation stitches can call FortiGate and FortiClient EMS actions when a malicious verdict is generated. FortiGate can block the file hash and quarantine the infected host, while FortiClient EMS can isolate the endpoint. This is the intended fabric-level automated response path for sandbox verdicts, so it correctly delivers quarantine and isolation without manual steps.

Why this answer

Automated response to a FortiSandbox malicious verdict requires an automation stitch that links the sandbox to enforcement points. FortiSandbox can trigger actions on FortiGate to block the file and quarantine the host, and on FortiClient EMS to isolate the endpoint. Other components such as FortiAnalyzer, FortiMail, or FortiGuard feeds do not provide the direct endpoint isolation needed here.

Exam trap

The trap here is assuming that any Fortinet security fabric component can automatically isolate an endpoint, when only FortiClient EMS provides that endpoint containment action.

65
Multi-Selectmedium

An administrator wants to create an automation stitch that responds to a high-severity IPS event by blocking the attacker IP. Which THREE components are required to build this automation stitch?

Select 3 answers
A.Trigger (e.g., IPS Event)
B.Schedule (e.g., run every hour)
C.Action (e.g., Block IP)
D.Target (e.g., FortiGate or FortiManager)
E.Condition (e.g., severity threshold)
AnswersA, C, D

Defines what event starts the stitch.

Why this answer

An automation stitch in FortiOS requires a trigger to initiate the workflow. In this scenario, the IPS event trigger is specifically designed to fire when a high-severity IPS signature match occurs, providing the necessary event data (e.g., attacker IP) to pass to subsequent actions. Without a trigger, the stitch would have no starting point.

Exam trap

The trap here is that candidates often confuse 'Condition' as a separate component because they think of it like a firewall policy's 'if-then' logic, but in FortiOS automation stitches, filtering logic is embedded within the trigger definition, not a standalone object.

66
MCQmedium

An administrator wants to automatically block a file that FortiSandbox has determined to be malicious. The FortiGate is configured with an antivirus profile that includes FortiSandbox submission. Which verdict action should be set to 'block' in the antivirus profile to achieve this?

A.Exempted
B.Unknown
C.Malicious
D.Clean
AnswerC

Setting the Malicious verdict to block lets the FortiGate drop files that FortiSandbox has already confirmed as malicious, satisfying the requirement for automatic blocking. Other verdicts, such as High Risk, cover suspicious but unconfirmed files, so they would not reliably block only sandbox-confirmed malware.

Why this answer

The 'Malicious' verdict action in the antivirus profile is specifically designed to block files that FortiSandbox has determined to be malicious. When FortiSandbox submits a file and returns a 'malicious' verdict, the FortiGate uses this action to enforce blocking, ensuring the file is not delivered to the end user.

Exam trap

The trap here is that candidates often confuse 'Unknown' with 'Malicious' and think blocking unknown files is safer, but FortiSandbox's 'Unknown' verdict means the file could not be analyzed (e.g., due to size or timeout), and blocking it would disrupt legitimate traffic; the correct approach is to block only confirmed malicious files.

How to eliminate wrong answers

Option A is wrong because 'Exempted' is used to bypass scanning for specific files or patterns, not to block malicious files. Option B is wrong because 'Unknown' verdict action is used for files that FortiSandbox could not conclusively classify; blocking unknown files would cause excessive false positives and is not the intended behavior for confirmed malicious files. Option D is wrong because 'Clean' verdict action allows files that are determined to be safe, which is the opposite of blocking malicious content.

67
MCQeasy

What is the primary difference between using a Web Application Firewall (WAF) on FortiGate versus using FortiWeb?

A.There is no difference; they are the same.
B.FortiGate WAF is cloud-based, while FortiWeb is on-premises.
C.FortiWeb provides dedicated, advanced WAF features and higher performance for web traffic, while FortiGate WAF is a basic protection feature.
D.FortiGate WAF can protect multiple web servers simultaneously, while FortiWeb protects only one.
AnswerC

FortiWeb is a purpose-built appliance offering full WAF capabilities, including advanced ML-based detection and higher throughput for web workloads. FortiGate's WAF is a lightweight UTM feature with limited inspection depth. This architectural split satisfies the stem's request for the primary difference between the two platforms.

Why this answer

FortiWeb is a dedicated web application firewall appliance that provides advanced, specialized WAF features such as machine learning-based bot detection, API discovery, and granular signature tuning, along with higher throughput for web traffic. In contrast, the WAF feature on FortiGate is a basic, integrated protection module that offers essential HTTP/HTTPS inspection and signature-based filtering, but lacks the depth and performance optimization of FortiWeb.

Exam trap

The trap here is that candidates assume all WAF implementations are functionally identical, overlooking the architectural and performance differences between an integrated feature and a dedicated appliance.

How to eliminate wrong answers

Option A is wrong because FortiGate WAF and FortiWeb are fundamentally different products; FortiGate integrates a basic WAF as a feature within its NGFW, while FortiWeb is a dedicated appliance with advanced web security capabilities. Option B is wrong because FortiGate WAF is not cloud-based; it runs on-premises as part of the FortiGate hardware or VM, and FortiWeb can be deployed both on-premises and as a cloud service (e.g., FortiWeb Cloud). Option D is wrong because both FortiGate WAF and FortiWeb can protect multiple web servers simultaneously; FortiWeb supports multi-server load balancing and virtual server configurations, while FortiGate WAF can apply policies to multiple web servers behind the firewall.

68
MCQmedium

A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?

A.Intrusion Prevention System (IPS) with botnet signatures
B.Application Control with botnet category
C.DNS Filter with botnet domain database
D.FortiGuard Category Based Filter
AnswerA

The IPS engine on FortiGate includes a comprehensive signature database that detects known botnet command-and-control patterns. When enabled, IPS inspects traffic flows and matches them against signatures specifically designed to identify C2 communication, such as those used by Mirai or Necurs. This provides the required signature-based detection and can block or log the traffic, directly addressing the administrator's goal.

Why this answer

The Intrusion Prevention System (IPS) on FortiGate uses a signature database that includes patterns for known botnet command-and-control traffic. Enabling IPS with botnet signatures allows the firewall to inspect packets and block or log C2 communications. Other features like web filtering, application control, or DNS filtering do not provide the same level of signature-based detection for C2 traffic.

Exam trap

The trap here is assuming that application control or DNS filtering can substitute for IPS when detecting botnet command-and-control traffic, but only IPS provides the deep packet inspection with botnet-specific signatures.

69
MCQmedium

An organization wants to prevent zero-day attacks by using Content Disarm and Reconstruction (CDR) on email attachments. Which Fortinet product provides this capability?

A.FortiWeb
B.FortiGate
C.FortiMail
D.FortiSandbox
AnswerC

FortiMail performs Content Disarm and Reconstruction on email attachments, stripping active content and rebuilding files into safe, inert versions before delivery. This directly satisfies the stem's requirement to block zero-day attacks, since CDR neutralises unknown exploits rather than relying on signature detection, which cannot identify previously unseen malware.

Why this answer

FortiMail is the correct answer because it natively integrates Content Disarm and Reconstruction (CDR) to sanitize email attachments by removing active content (e.g., macros, scripts, embedded objects) and rebuilding the file in a safe format. This prevents zero-day exploits that bypass signature-based detection, as CDR does not rely on threat intelligence but instead strips potentially malicious elements before delivery.

Exam trap

The trap here is that candidates often confuse FortiSandbox's dynamic analysis with CDR, assuming both provide proactive protection against zero-days, but FortiSandbox requires execution and detection, whereas CDR prevents exploitation by removing the attack surface entirely without relying on signatures or behavioral analysis.

How to eliminate wrong answers

Option A is wrong because FortiWeb is a web application firewall (WAF) that protects web servers from HTTP/HTTPS attacks (e.g., SQL injection, XSS) and does not process email attachments or provide CDR functionality. Option B is wrong because FortiGate is a next-generation firewall (NGFW) that can perform antivirus and sandboxing for traffic passing through it, but it does not include native CDR for email attachments; CDR is a feature specific to FortiMail's email security pipeline. Option D is wrong because FortiSandbox is a separate advanced threat detection appliance that uses dynamic analysis (e.g., detonating files in a sandbox) to identify unknown malware, but it does not perform CDR; CDR proactively disarms attachments without execution, whereas FortiSandbox relies on behavioral analysis after execution.

70
MCQhard

A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?

A.Change the IPS action from block to monitor
B.Add the VoIP servers to an IP exemption list in the IPS sensor
C.Disable protocol anomaly detection entirely
D.Tune the protocol anomaly thresholds to be more lenient for SIP
AnswerD

Protocol anomaly detection flags SIP deviations from strict RFC behaviour, and legitimate VoIP implementations often violate these expectations. Raising the anomaly thresholds for SIP reduces sensitivity to benign variation, cutting false positives while retaining signature-based IPS coverage for actual attacks.

Why this answer

Protocol anomaly detection in IPS sensors uses predefined thresholds to identify abnormal traffic patterns. When legitimate SIP traffic is being blocked, tuning the protocol anomaly thresholds to be more lenient for SIP allows the sensor to accommodate normal variations in SIP behavior without triggering false positives, while still maintaining protection against actual anomalies.

Exam trap

The trap here is that candidates may think disabling or bypassing detection (options A, B, or C) is the simplest fix, but the exam tests the understanding that protocol anomaly detection should be tuned rather than disabled to preserve security while reducing false positives.

How to eliminate wrong answers

Option A is wrong because changing the IPS action from block to monitor would stop blocking but also disable protection, which is not a targeted fix for false positives and leaves the network vulnerable to real threats. Option B is wrong because adding VoIP servers to an IP exemption list would bypass all IPS inspection for those IPs, which is overly broad and could allow actual attacks to go undetected. Option C is wrong because disabling protocol anomaly detection entirely removes a valuable security layer and is an extreme measure that does not address the root cause of false positives.

71
Multi-Selectmedium

A security analyst wants to use automation stitches on FortiGate to automatically block an IP address when a critical severity event is logged. Which TWO components are essential to create this automation stitch? (Choose two.)

Select 2 answers
A.A FortiGuard subscription
B.A FortiAnalyzer to store logs
C.An action that adds the source IP to a firewall address group
D.A static route to the internet
E.A trigger that matches critical severity logs
AnswersC, E

The action defines the response, such as blocking the IP.

Why this answer

An automation stitch in FortiGate requires an action to execute a specific task, such as adding a source IP to a firewall address group, which effectively blocks the IP. This action is essential for enforcing the security response triggered by the stitch.

Exam trap

The trap here is that candidates often confuse optional components (like FortiGuard or FortiAnalyzer) with essential ones, mistakenly thinking external services or connectivity are required for the stitch's core trigger and action logic.

72
MCQmedium

An administrator needs to deploy a honeypot solution to detect and deceive attackers inside the network. Which Fortinet product is BEST suited for this purpose?

A.FortiDeceptor
B.FortiSandbox
C.FortiEDR
D.FortiNAC
AnswerA

FortiDeceptor deploys decoys, lures and honeypots that mimic real assets, detecting and deceiving attackers who interact with them while generating high-fidelity alerts. This directly satisfies the stem's requirement for an in-network honeypot, unlike FortiGate, FortiAnalyzer or FortiSIEM, which provide enforcement, logging or correlation rather than deception.

Why this answer

FortiDeceptor is a dedicated deception-based security solution that deploys decoys (honeypots) and lures across the network to detect and misdirect attackers. It integrates with FortiGate and FortiSIEM to provide automated threat isolation and forensic data collection, making it the best choice for a honeypot deployment.

Exam trap

The trap here is that candidates may confuse FortiSandbox's file analysis with deception technology, but FortiSandbox does not deploy decoys or lures within the network for attacker interaction.

How to eliminate wrong answers

Option B (FortiSandbox) is wrong because it focuses on analyzing suspicious files and URLs in a sandboxed environment, not on deploying honeypots or decoys for attacker deception. Option C (FortiEDR) is wrong because it provides endpoint detection and response capabilities, including behavioral analysis and threat hunting, but does not include honeypot or deception technology. Option D (FortiNAC) is wrong because it is a network access control solution that manages device authentication and compliance, not a deception-based detection tool.

73
MCQmedium

A network security administrator is deploying a FortiSandbox appliance in a FortiGate environment. The administrator wants to ensure that when a zero-day malware sample is detonated, the FortiGate immediately blocks the file hash and the C2 callback. Which FortiSandbox integration method should the administrator configure on the FortiGate to achieve this?

A.Configure an external threat feed on the FortiGate using the FortiSandbox API to pull malicious IPs every 5 minutes.
B.Configure a syslog server on the FortiSandbox to send logs to the FortiGate, and create a firewall policy that denies traffic from the sandbox subnet.
C.Configure the FortiGate to send files to FortiSandbox via the 'fortisandbox' fabric connector and enable 'block malicious files' in the antivirus profile.
D.Enable 'Use FortiSandbox for unknown files' in the antivirus profile and set the action to 'monitor' for all protocols.
AnswerC

The FortiSandbox fabric connector allows the FortiGate to submit files and receive verdicts. Enabling 'block malicious files' in the antivirus profile ensures that once a verdict is returned, the FortiGate blocks the file hash and subsequent C2 traffic based on the sandbox's dynamic blocklist. This is the standard integration for automated threat blocking.

Why this answer

The FortiSandbox fabric connector on FortiGate enables seamless submission of files and retrieval of verdicts. When a file is deemed malicious, the FortiGate can block the file hash and C2 traffic via the antivirus profile's block action. This integrated approach automates threat protection without manual intervention, ensuring immediate response to zero-day threats.

Exam trap

The trap here is assuming that any connection to FortiSandbox automatically blocks threats, when in fact the antivirus profile must be configured to block malicious files and the fabric connector must be properly established.

74
MCQhard

A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?

A.Enable 'Treat Windows executable files as viruses' in the antivirus profile to block all executable downloads.
B.Configure FortiSandbox to send a verdict to FortiGate and set the action to 'Block' in the sandbox profile.
C.Enable the 'Block malicious URLs' option in the web filter profile so the download URL is blocked.
D.Add the file hash to a custom antivirus signature list or threat feed and enable it in the antivirus profile.
AnswerD

FortiGate antivirus can block files based on custom signatures or external threat feeds that include file hashes. Adding the hash to a custom list and referencing it in the antivirus profile ensures the file is detected and blocked on subsequent downloads, even if the URL changes. This directly addresses the known malicious hash and is the correct operational response.

Why this answer

When a specific malicious file hash is known, the most direct and reliable way to block it on FortiGate is to add that hash to a custom antivirus signature or external threat feed and enable it in the antivirus profile. This ensures detection regardless of the delivery URL or protocol, and it integrates with existing antivirus scanning. It also avoids overblocking legitimate executables and does not depend solely on sandbox verdict propagation.

Exam trap

The trap here is assuming that a FortiSandbox verdict automatically creates a hash-based block on FortiGate, when the administrator may need to explicitly add the hash to a custom list or threat feed.

75
MCQhard

An administrator configured FortiGate to forward suspected malicious files to FortiSandbox. They set the action to 'block' for malicious verdicts. Some files are being blocked, but others with a 'clean' verdict are allowed. However, they notice that some files that should have been sent to FortiSandbox are not being forwarded. Which reason is MOST likely?

A.The FortiGate antivirus engine is set to proxy-based mode
B.The FortiGate has insufficient disk space for temporary files
C.The file size exceeds the maximum size configured for FortiSandbox scanning
D.The FortiSandbox device is overloaded and rejecting submissions
AnswerC

FortiGate only submits files to FortiSandbox when they fall within the configured scan size limit; oversized files bypass sandbox inspection entirely. This satisfies the scenario's symptom of files not being forwarded, since verdicts for those files are never produced and blocking cannot occur.

Why this answer

The most likely reason is that the file size exceeds the maximum size configured for FortiSandbox scanning. FortiGate has a configurable limit (default 10 MB) for files sent to FortiSandbox; files larger than this threshold are not forwarded, even if the antivirus engine would otherwise trigger a submission. This explains why some files are blocked or allowed based on verdicts, while others are never submitted.

Exam trap

The trap here is that candidates often assume network or resource issues (overloaded FortiSandbox or disk space) are the cause, but the question specifically describes files that 'should have been sent' but are not, pointing to a configuration-based filter like file size limits rather than transient failures.

How to eliminate wrong answers

Option A is wrong because proxy-based mode is a valid inspection mode for FortiGate antivirus and does not prevent file forwarding to FortiSandbox; it actually supports file submission. Option B is wrong because insufficient disk space for temporary files would cause local scanning or caching issues, but FortiSandbox submissions are streamed or queued, not dependent on local temporary storage for forwarding. Option D is wrong because an overloaded FortiSandbox may delay or queue submissions, but it does not cause files to be completely not forwarded; FortiGate will still attempt submission and handle timeouts gracefully.

Page 1 of 3 · 157 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Advanced Threat Protection questions.