Courseiva

CCNA Enterprise Firewall and VDOMs Questions

75 of 186 questions · Page 1/3 · Enterprise Firewall and VDOMs · Answers revealed

1
MCQhard

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a specific physical interface to a non-management VDOM and ensure that the interface is not visible or configurable from other VDOMs. The interface is currently assigned to the root VDOM. What is the correct procedure to reassign the interface to VDOM-1?

A.In the global configuration, directly change the interface's VDOM to VDOM-1; the FortiGate automatically deletes all references in the root VDOM.
B.In the root VDOM, remove all references to the interface (such as firewall policies and routing entries), then use the global configuration to set the interface's VDOM to VDOM-1.
C.From VDOM-1, use the command 'config system interface' and edit the interface, then set its VDOM to VDOM-1. The FortiGate automatically removes it from the root VDOM.
D.Create a new VDOM link between the root VDOM and VDOM-1, then bridge the physical interface to the VDOM link so that VDOM-1 can use it without reassigning the interface.
AnswerB

To move a physical interface from one VDOM to another, you must first remove any configuration that references the interface in its current VDOM, such as firewall policies, routes, and DHCP server settings. Then, in the global configuration, you can change the interface's VDOM assignment. This ensures that the interface is cleanly detached before being reassigned. After reassignment, the interface becomes visible only in the target VDOM.

Why this answer

Reassigning a physical interface to a different VDOM requires removing all references to that interface in its current VDOM, such as firewall policies, routes, and DHCP settings. Once the interface is free of references, you can change its VDOM assignment in the global configuration. This process ensures that the interface is cleanly moved and becomes exclusively available to the target VDOM, maintaining proper isolation between VDOMs.

Exam trap

The trap here is thinking that changing the VDOM assignment automatically cleans up references or that you can edit the interface from the target VDOM, when in fact you must manually remove references from the current VDOM first.

2
MCQeasy

An administrator needs to monitor traffic flows across multiple FortiGate devices in a Security Fabric. The administrator wants to see a unified view of all traffic, including inter-device traffic, from a single pane. Which Fortinet tool provides this capability?

A.FortiAP
B.FortiManager
C.FortiGate local logs
D.FortiAnalyzer
AnswerD

FortiAnalyzer aggregates logs and provides cross-device traffic visibility.

Why this answer

FortiAnalyzer is the correct tool because it aggregates logs and traffic data from multiple FortiGate devices within a Security Fabric, providing a unified view of all traffic, including inter-device flows. It uses the FortiTelemetry protocol to collect logs and supports the Security Fabric's topology mapping, allowing administrators to monitor cross-device traffic from a single pane of glass.

Exam trap

The trap here is that candidates often confuse FortiManager's centralized management capabilities with FortiAnalyzer's log aggregation and monitoring functions, leading them to select FortiManager for traffic visibility when it is actually designed for policy and configuration management, not real-time traffic analysis.

How to eliminate wrong answers

Option A is wrong because FortiAP is a wireless access point device that provides Wi-Fi connectivity, not a centralized log aggregation or traffic monitoring tool for multiple FortiGates. Option B is wrong because FortiManager is primarily a centralized management platform for configuration and policy deployment, not a log analysis or traffic monitoring tool; it does not provide the unified traffic view that FortiAnalyzer offers. Option C is wrong because FortiGate local logs are stored locally on each device and cannot provide a unified view across multiple FortiGates or show inter-device traffic flows.

3
MCQmedium

A FortiGate in HA active-passive mode has two VDOMs. VDOM-1 is configured for management (management VDOM). The administrator connects to the management VDOM IP to manage the device. What is a characteristic of the management VDOM?

A.It provides administrative access and is separate from data VDOMs
B.It automatically synchronizes configuration to other VDOMs
C.It must be the root VDOM
D.It can only be accessed via the console port
AnswerA

The management VDOM is a dedicated administrative VDOM that isolates management-plane traffic from the data VDOMs, so administrative access to the FortiGate is kept separate from user traffic. This satisfies the requirement to manage the HA pair without exposing data-plane interfaces.

Why this answer

In an HA active-passive setup with multiple VDOMs, a management VDOM is dedicated to administrative access (e.g., SSH, HTTPS, SNMP) and is logically separated from data VDOMs that handle production traffic. This separation ensures that management traffic does not interfere with data plane operations and that administrative access remains available even if data VDOMs experience issues. The management VDOM can be any VDOM, not necessarily the root, and its configuration is not automatically synchronized to other VDOMs.

Exam trap

The trap here is that candidates often assume the management VDOM must be the root VDOM or that it automatically syncs configurations to other VDOMs, but Fortinet explicitly separates these concepts to allow flexible administrative isolation without affecting global settings or HA synchronization.

How to eliminate wrong answers

Option B is wrong because the management VDOM does not automatically synchronize its configuration to other VDOMs; configuration synchronization in HA is handled at the system level (e.g., via FGCP), not by the management VDOM itself. Option C is wrong because the management VDOM does not have to be the root VDOM; any VDOM can be designated as the management VDOM, and the root VDOM is a separate concept used for global settings. Option D is wrong because the management VDOM can be accessed via any allowed administrative interface (e.g., network interfaces with HTTPS/SSH enabled), not only the console port; console access is just one of many possible methods.

4
MCQhard

An admin creates a VDOM named 'CustomerA' with inter-VDOM link to the management VDOM. The admin wants CustomerA administrators to manage only their own VDOM. Which configuration step is required?

A.Use the 'config system admin' command and set trusthost to the admin's IP
B.Place the management VDOM and CustomerA in different administrative domains (ADOMs) in FortiManager
C.Create a new administrator and set the 'VDOM' field to 'CustomerA' and assign a profile with appropriate permissions
D.Enable admin-role override in the VDOM settings
AnswerC

Assigning the administrator's VDOM field to CustomerA scopes their login session to that VDOM alone, so they cannot view or configure the management VDOM or any other. The accompanying profile then governs which actions are permitted within CustomerA, satisfying the requirement for isolated per-VDOM administration.

Why this answer

To restrict a VDOM administrator to manage only their own VDOM, you must create a new administrator account and explicitly set the 'VDOM' field to that VDOM (e.g., 'CustomerA') and assign a profile with the necessary permissions. This ensures the admin's scope is limited to that VDOM, preventing access to the management VDOM or other VDOMs.

Exam trap

The trap here is confusing IP-based access control (trusthost) with VDOM-based administrative scoping, leading candidates to select Option A instead of understanding that VDOM assignment is the correct method to isolate admin privileges to a single VDOM.

How to eliminate wrong answers

Option A is wrong because the 'trusthost' setting restricts the source IP address from which an admin can log in, not the VDOM scope; it does not limit the admin to managing only CustomerA. Option B is wrong because administrative domains (ADOMs) are a FortiManager concept for multi-device management, not a FortiGate VDOM isolation feature; the question is about local VDOM administration on a single FortiGate. Option D is wrong because 'admin-role override' is not a standard FortiGate VDOM setting; the correct mechanism is to assign the admin to a specific VDOM via the 'config system admin' command with the 'vdom' parameter.

5
MCQeasy

What is the primary function of FortiAnalyzer's FortiView feature?

A.Centralized device configuration management
B.Scheduling and generating compliance reports
C.Real-time traffic monitoring and visualization
D.Automated remediation of security incidents
AnswerC

FortiView aggregates logs from managed FortiGate devices into dashboards and drill-down views, delivering real-time traffic monitoring and visualisation. This directly satisfies the stem's requirement for the primary function, since FortiView's purpose is presenting live and historical traffic, threat and application data graphically rather than performing configuration or policy enforcement.

Why this answer

FortiView on FortiAnalyzer provides real-time traffic monitoring and visualization by aggregating logs from FortiGate devices and displaying them in graphical dashboards. It allows administrators to instantly view top talkers, applications, threats, and other network activity without needing to run manual queries, making it the primary function for live traffic analysis.

Exam trap

The trap here is that candidates confuse FortiView's real-time monitoring with FortiManager's centralized management or FortiAnalyzer's reporting capabilities, leading them to pick Option A or B instead of recognizing that FortiView is explicitly designed for live traffic visualization.

How to eliminate wrong answers

Option A is wrong because centralized device configuration management is handled by FortiManager, not FortiAnalyzer; FortiAnalyzer focuses on log management and reporting, not pushing configuration changes. Option B is wrong because while FortiAnalyzer can generate compliance reports, that is a secondary feature of the Reports module, not the primary function of FortiView, which is specifically for real-time monitoring and visualization. Option D is wrong because automated remediation of security incidents is a function of FortiSOAR or FortiGate's automation stitches, not FortiAnalyzer's FortiView, which is read-only and does not execute actions.

6
Multi-Selecthard

An organization uses FortiAnalyzer for centralized logging. The security team wants to use playbooks to automate responses to detected incidents. Which THREE components are essential for a playbook to function?

Select 3 answers
A.Trigger
B.A report schedule
C.Conditions
D.A dashboard visualization
E.Actions
AnswersA, C, E

A playbook needs a trigger to initiate execution when a matching event or incident is detected. Without this starting condition, no automated response tasks can run, making the trigger an essential component of playbook functionality.

Why this answer

In FortiAnalyzer playbooks, the essential building blocks are the trigger, conditions, and actions. Option A (Trigger) is correct because a playbook must have an event source that initiates execution, such as a new log, incident, or event detected by FortiAnalyzer. Option C (Conditions) is correct because conditions define the matching logic or filters that determine whether the playbook should run and which path it follows.

Option E (Actions) is correct because actions specify the automated response steps the playbook performs, such as sending notifications, running CLI scripts, or creating incidents. Option B (A report schedule) is not required, since reports are separate scheduled outputs and do not drive playbook execution. Option D (A dashboard visualization) is not required, because dashboards are for display and monitoring, not for the functional logic of a playbook.

Exam trap

The trap here is that candidates often confuse 'report schedule' or 'dashboard visualization' as necessary components because they are common FortiAnalyzer features, but they are not part of the core playbook execution triad of trigger, conditions, and actions.

7
MCQmedium

An administrator configures a new ADOM in FortiManager for a set of FortiGates. The administrator wants to assign meta fields to devices in this ADOM. Where should the meta fields be defined?

A.Policy & Objects -> Object configurations
B.Device Manager -> ADOM settings
C.System settings -> Admin
D.Global database objects
AnswerB

Meta fields are ADOM-scoped objects, defined under Device Manager's ADOM settings so every device in that ADOM can be tagged consistently. Defining them here satisfies the requirement to assign meta fields to devices within the new ADOM.

Why this answer

Meta fields in FortiManager are defined at the ADOM level under Device Manager -> ADOM settings. This ensures that the custom fields are available for all devices within that specific ADOM, allowing consistent metadata assignment across managed FortiGates. Defining them elsewhere, such as in global database objects, would apply them globally rather than per-ADOM, which is not the administrator's intent.

Exam trap

The trap here is that candidates may confuse ADOM-specific settings with global database objects, assuming meta fields must be defined globally for consistency, but FortiManager requires them to be defined at the ADOM level to maintain isolation between administrative domains.

How to eliminate wrong answers

Option A is wrong because 'Policy & Objects -> Object configurations' is used for managing firewall policies and shared objects, not for defining device-level meta fields. Option C is wrong because 'System settings -> Admin' deals with administrative access and user permissions, not device metadata configuration. Option D is wrong because 'Global database objects' are shared across all ADOMs and would apply meta fields globally, whereas the requirement is to assign meta fields specifically to devices in a single ADOM.

8
Multi-Selecthard

A FortiGate admin configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The admin wants traffic from VDOM-A to reach a server in VDOM-B. Which three configuration steps are required? (Choose three.)

Select 3 answers
A.Enable NAT on the VDOM link interface
B.Configure static routes pointing to the VDOM link interface on both VDOMs
C.Configure a firewall policy on VDOM-A allowing traffic to the VDOM link interface
D.Disable ARP on the VDOM link interfaces
E.Create a VDOM link and assign an interface to each VDOM
AnswersB, C, E

Each VDOM maintains its own routing table, so both VDOM-A and VDOM-B need static routes whose gateway is the VDOM link interface to reach the peer's subnets. Without these routes, traffic has no path across the link and forwarding fails.

Why this answer

Option E is correct because a VDOM link must first be created and its two ends (interfaces) assigned to VDOM-A and VDOM-B, which provides the physical/logical path for inter-VDOM traffic. Option B is correct because each VDOM needs a static route whose destination is the remote subnet and whose gateway/interface is the local VDOM link interface, so traffic is forwarded across the link. Option C is correct because FortiGate security policies are required to permit traffic between interfaces, so VDOM-A needs a policy allowing traffic from its source interface to the VDOM link interface.

Option A is not required because NAT is not needed for inter-VDOM routing when addressing is preserved; NAT could even break return-path routing. Option D is not required because ARP must remain enabled on the VDOM link interfaces for next-hop resolution.

Exam trap

The trap here is that candidates often assume VDOM links automatically route traffic between VDOMs, but they forget that each VDOM maintains its own independent routing table, so explicit static routes are mandatory for inter-VDOM communication.

9
MCQeasy

A network administrator wants to delegate management of a specific VDOM to a junior administrator. The junior should be able to modify firewall policies and objects within that VDOM but not change system settings or other VDOMs. Which administrative access configuration meets this requirement?

A.Place the VDOM in transparent mode to allow full access
B.Create a RADIUS user that is assigned to the VDOM group
C.Use the management VDOM feature to assign the junior admin to the VDOM
D.Create a local user with an admin profile that has permissions for that VDOM only
AnswerD

A local user bound to an admin profile scoped to a single VDOM grants read-write access to that VDOM's firewall policies and objects, while denying system settings and other VDOMs. This satisfies least-privilege delegation exactly as the stem requires.

Why this answer

FortiGate allows you to create a local user with an admin profile that has permissions scoped to a specific VDOM. By assigning the junior administrator to that VDOM-only profile, they can modify firewall policies and objects within that VDOM but cannot change system settings or access other VDOMs. This is the standard method for delegating VDOM-specific administrative access without granting global or multi-VDOM privileges.

Exam trap

The trap here is that candidates often confuse the management VDOM feature (which only handles management traffic routing) with VDOM-specific admin profiles, or assume that transparent mode or RADIUS group assignment inherently restricts permissions, when in fact only a properly scoped admin profile can enforce VDOM-level access control.

How to eliminate wrong answers

Option A is wrong because placing a VDOM in transparent mode changes its operational mode (layer 2 forwarding) and does not restrict administrative access; it still allows full access to the VDOM's configuration if the admin has appropriate permissions. Option B is wrong because a RADIUS user assigned to a VDOM group only controls authentication and group membership, not the specific permissions within a VDOM; the admin profile assigned to the user determines the actual access scope, and RADIUS alone does not restrict to a single VDOM. Option C is wrong because the management VDOM feature is used to centralize management traffic (e.g., SNMP, syslog) and does not delegate administrative permissions; it does not restrict a junior admin to a specific VDOM.

10
MCQeasy

What is the purpose of FortiAnalyzer in a Fortinet security fabric?

A.To provide sandboxing and advanced threat protection
B.To act as a network firewall and IPS
C.To collect and analyze logs, generate reports, and provide visibility into security events
D.To manage and deploy configurations to FortiGates
AnswerC

FortiAnalyzer aggregates logs from FortiGate and fabric devices, then correlates them into reports and dashboards, satisfying the requirement for centralised visibility into security events. Unlike FortiManager, which handles configuration and policy deployment, FortiAnalyzer's role is analytics and retention, delivering the log analysis and reporting the stem asks about.

Why this answer

FortiAnalyzer is the centralized logging and analytics platform within the Fortinet Security Fabric. It aggregates logs from FortiGate and other Fabric devices, correlates events, generates compliance reports, and provides a single-pane-of-glass view for security monitoring and forensic analysis. This directly supports visibility and reporting, not real-time threat prevention or configuration management.

Exam trap

The trap here is confusing FortiAnalyzer with FortiManager, as both are central management tools, but FortiAnalyzer focuses on log collection and reporting, while FortiManager handles configuration deployment and policy management.

How to eliminate wrong answers

Option A is wrong because sandboxing and advanced threat protection are functions of FortiSandbox, not FortiAnalyzer; FortiAnalyzer can integrate with FortiSandbox for log correlation but does not perform sandboxing itself. Option B is wrong because network firewall and IPS are core functions of FortiGate, not FortiAnalyzer; FortiAnalyzer is a log collector and analyzer, not an inline security device. Option D is wrong because managing and deploying configurations to FortiGates is the role of FortiManager, which uses the FortiGate API and policy packages; FortiAnalyzer has no configuration deployment capabilities.

11
MCQmedium

An administrator configures a FortiGate with VDOMs and notices that the 'config vdom' command lists multiple VDOMs, but only one VDOM is shown in the 'show full-configuration' output. What is the most likely reason?

A.The administrator is in the context of a specific VDOM
B.The VDOMs are not properly synchronized
C.The VDOMs are not assigned any interfaces
D.The FortiGate is in transparent mode
AnswerA

Entering a VDOM context scopes subsequent commands to that VDOM only, so 'show full-configuration' displays just the current VDOM's configuration. The 'config vdom' listing still enumerates all defined VDOMs, explaining why multiple appear there but only one appears in the full output.

Why this answer

The 'config vdom' command lists all VDOMs configured on the FortiGate because it operates in the global context. However, 'show full-configuration' only displays the configuration of the current VDOM context. If the administrator is inside a specific VDOM (e.g., after executing 'config vdom' and 'edit <vdom-name>'), the output is scoped to that VDOM, not the global configuration.

This is a fundamental behavior of VDOM-based CLI navigation in FortiOS.

Exam trap

The trap here is that candidates assume 'config vdom' lists all VDOMs because they are all active, but they forget that 'show full-configuration' output is context-dependent and only reflects the current VDOM or global scope, not the entire device configuration.

How to eliminate wrong answers

Option B is wrong because VDOM synchronization is not relevant to CLI output scoping; synchronization affects configuration replication between HA members, not the visibility of VDOMs in 'show full-configuration'. Option C is wrong because unassigned interfaces do not prevent a VDOM from appearing in 'show full-configuration'; a VDOM without interfaces still has its own configuration block. Option D is wrong because transparent mode is a separate operational mode that does not affect VDOM listing or configuration display; a FortiGate in transparent mode can still have multiple VDOMs and the same CLI scoping rules apply.

12
MCQmedium

An administrator wants to group firewall objects by department (e.g., Sales, Engineering) and easily filter them in FortiManager policy packages. Which feature should be used?

A.Tags in FortiGate
B.ADOM overrides
C.Meta fields
D.Policy package folders
AnswerC

Meta fields attach custom key-value pairs to firewall objects, letting administrators tag objects by department and filter them within FortiManager policy packages. This directly satisfies the requirement to group and filter objects by department such as Sales or Engineering.

Why this answer

Meta fields in FortiManager allow administrators to define custom attributes (e.g., Department) for firewall objects. These fields can then be used to group and filter objects within policy packages, enabling efficient management by department without requiring separate ADOMs or VDOMs.

Exam trap

The trap here is that candidates may confuse meta fields with FortiGate tags, but tags are device-local and not available for filtering in FortiManager policy packages, whereas meta fields are a FortiManager-specific feature designed for cross-device object grouping.

How to eliminate wrong answers

Option A is wrong because Tags in FortiGate are local to the FortiGate device and are not synchronized to FortiManager for filtering in policy packages; they are used for object categorization on the device itself. Option B is wrong because ADOM overrides are used to manage configuration differences across ADOMs, not to group or filter objects by custom attributes like department. Option D is wrong because Policy package folders organize policy packages themselves, not individual firewall objects within a package.

13
MCQeasy

Which FortiManager feature allows an administrator to view the exact CLI commands that will be pushed to a managed FortiGate before installation?

A.Policy Check
B.Revision History
C.Device Manager Dashboard
D.Install Preview
AnswerD

Install Preview renders the exact CLI configuration FortiManager will push to the managed FortiGate, letting the administrator inspect commands before committing. Policy Package revision history and install wizard show prior or summary states, but only Install Preview exposes the precise command set for pre-installation review.

Why this answer

Install Preview is the correct answer because it allows an administrator to review the exact CLI commands that FortiManager will push to a managed FortiGate during the next installation. This feature provides a pre-installation view of the configuration changes, enabling verification before committing changes to the device.

Exam trap

The trap here is that candidates may confuse Install Preview with Revision History, thinking that viewing past configurations is the same as previewing pending changes, but Revision History only shows saved snapshots, not the upcoming installation script.

How to eliminate wrong answers

Option A is wrong because Policy Check is used to validate policy consistency and conflicts across FortiGates, not to preview CLI commands. Option B is wrong because Revision History stores previous configuration backups and allows rollback, but does not show the pending CLI commands for the next installation. Option C is wrong because the Device Manager Dashboard provides a summary view of device status and configuration, but does not display the exact CLI commands that will be pushed.

14
MCQhard

In a FortiManager deployment with global ADOM enabled, an administrator creates a firewall policy in the global ADOM. What is the effect of this policy on the per-ADOM devices?

A.The policy is used only if no per-ADOM policy exists with the same name
B.The policy is applied only to devices in the same ADOM as the global ADOM
C.The policy is ignored unless explicitly assigned to each ADOM
D.The policy is installed as a header policy on all managed FortiGates
AnswerD

Global ADOM policies are pushed to every managed FortiGate as header policies, positioned above each device's local policies in the policy package. This satisfies the scenario's requirement that a single global-ADOM firewall policy affects all per-ADOM devices without duplicating configuration, since header policies are evaluated first during traffic matching.

Why this answer

In FortiManager, when global ADOM is enabled, policies created in the global ADOM are automatically installed as header policies on all managed FortiGates across all ADOMs. Header policies are evaluated before per-ADOM policies, allowing global enforcement of rules. This ensures consistent security posture across the entire managed estate.

Exam trap

NSE7 often tests the misconception that global ADOM policies are optional or require manual assignment, when they are actually automatically installed as header policies on all devices.

How to eliminate wrong answers

Option A is wrong because global policies are not fallbacks; they are always applied as header policies, regardless of per-ADOM policies. Option B is wrong because global ADOM policies apply to all ADOMs, not just the one they are created in. Option C is wrong because global policies do not require explicit assignment; they are automatically pushed to all devices.

15
Multi-Selectmedium

An administrator is troubleshooting why a new firewall policy on a managed FortiGate is not taking effect. The policy was created in FortiManager and installed successfully. Which TWO steps should the administrator verify to identify the issue? (Select TWO.)

Select 2 answers
A.Reboot the FortiGate
B.Review the FortiGate's routing table
C.Check if the policy is disabled
D.Check the policy order in the policy list
E.Verify the FortiGate's HA status
AnswersC, D

A policy installed successfully can still be inactive if its status is disabled. Verifying the enabled/disabled state on the managed FortiGate confirms whether the policy is actually evaluated, directly explaining why it produces no effect.

Why this answer

Option C is correct because a policy that exists in FortiManager and installs successfully can still be administratively disabled on the managed FortiGate, in which case it will never match traffic; the administrator should confirm the policy's status is enabled. Option D is correct because firewall policies are evaluated top-down and the first matching policy wins, so if a broader or conflicting policy appears above the new policy in the policy list, the new policy will never be hit; verifying its position in the order is essential. Option A is not appropriate because rebooting the FortiGate does not resolve a policy configuration or ordering problem and would only cause unnecessary downtime.

Option B is not the right focus because routing determines whether traffic reaches the FortiGate and which interface/next-hop is used, but the scenario states the policy itself is not taking effect, not that traffic is failing to route. Option E is not relevant because HA status affects failover and session synchronization, not whether a specific installed policy matches traffic.

Exam trap

The trap here is that candidates often assume a successful installation guarantees the policy is active, overlooking the disabled state or the impact of policy order on traffic matching.

16
MCQhard

An administrator has a FortiGate with multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 are connected via an inter-VDOM link. The administrator wants to apply security profiles to traffic passing between the VDOMs. However, when checking the policy list in VDOM-1, no policy is shown for traffic destined to VDOM-2. What is the most likely reason?

A.The inter-VDOM link interfaces have not been assigned to a zone, so policies cannot reference them.
B.Inter-VDOM link traffic is not subject to firewall policies by default.
C.The administrator must create a policy in each VDOM that allows traffic from the inter-VDOM link interface to the destination interface.
D.The administrator is looking at the wrong VDOM; policies for inter-VDOM traffic are only visible in the root VDOM.
AnswerC

To allow and inspect traffic between VDOMs, you must create firewall policies in both VDOMs. For traffic from VDOM-1 to VDOM-2, a policy is needed in VDOM-1 (from internal to inter-VDOM link) and another in VDOM-2 (from inter-VDOM link to internal). Without these policies, traffic is dropped and no policy is shown because none exists yet.

Why this answer

Inter-VDOM traffic requires explicit firewall policies in both the source and destination VDOMs. The administrator must create a policy in VDOM-1 allowing traffic from the internal interface to the inter-VDOM link, and a corresponding policy in VDOM-2 from the inter-VDOM link to the internal interface. Without these, traffic is not allowed and no policy exists.

Exam trap

The trap here is assuming that inter-VDOM traffic is automatically allowed or that policies are only needed in one VDOM, when in fact policies are required in both VDOMs for traffic to pass and be inspected.

17
MCQmedium

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM so that it can be used for that VDOM's traffic. Which configuration step is required?

A.In the global configuration, edit the physical interface and set the VDOM to the desired VDOM.
B.Create a VLAN subinterface on the physical interface and assign the VLAN to the VDOM.
C.Use the 'set vdom' command under the interface configuration in the root VDOM.
D.In the VDOM configuration, add the physical interface to the VDOM's interface list.
AnswerA

To assign a physical interface to a VDOM, you must edit the interface in the global configuration (or within the VDOM, depending on the model) and set its VDOM attribute. This moves the interface from the root VDOM to the specified VDOM, making it available for that VDOM's policies and routing. This is the standard procedure.

Why this answer

Assigning a physical interface to a VDOM requires editing the interface in the global configuration and setting its VDOM attribute. This moves the interface to the target VDOM, where it can be used for that VDOM's traffic. Other methods like VLANs or VDOM-specific interface lists do not achieve the same result.

Exam trap

The trap here is confusing VLAN subinterfaces, which allow sharing a physical interface, with assigning the entire physical interface to a single VDOM.

18
MCQeasy

An administrator is deploying a FortiGate in multi-VDOM mode for a managed services provider. Each customer must have an isolated logical firewall with its own interfaces, policies, and administrators, and the provider wants to limit each customer administrator to only their own VDOM. Which configuration accomplishes this?

A.Use global firewall policies and global address objects shared across all customers
B.Enable virtual clustering and assign each customer to a different HA group within the cluster
C.Configure transparent mode on the FortiGate so each customer subnet is bridged independently
D.Create one VDOM per customer, assign interfaces to each VDOM, and create an administrative profile that grants access only to that customer's VDOM
AnswerD

Multi-VDOM mode plus per-VDOM administrative profiles is the standard way to give each customer an isolated logical firewall. Interfaces assigned to a VDOM cannot be used by other VDOMs, policies are per-VDOM, and an administrative profile scoped to a single VDOM restricts visibility and changes. This combination delivers the isolation and delegated administration the provider requires.

Why this answer

Multi-VDOM mode lets a single FortiGate host multiple logical firewalls, each with dedicated interfaces, policies, and routing. Pairing each customer VDOM with an administrative profile scoped to that VDOM gives the provider both traffic isolation and delegated, restricted management, which is the core MSSP deployment pattern on FortiGate.

Exam trap

The trap here is assuming transparent mode or virtual clustering alone provides tenant isolation, when actual separation and delegated administration come from per-VDOM configuration plus scoped administrative profiles.

19
MCQmedium

An administrator has a FortiGate in multi-VDOM mode. VDOM-1 is assigned to the marketing team and VDOM-2 to the finance team. The administrator wants both VDOMs to be able to reach a shared DNS server at 10.10.10.53 that sits behind the root VDOM's wan1 interface, without giving either team access to the other's traffic. Which configuration accomplishes this?

A.Configure a static route in VDOM-1 and VDOM-2 with the destination 10.10.10.53/32 and the outgoing interface set to wan1, then add a firewall policy in each VDOM allowing DNS outbound.
B.Assign wan1 as a secondary IP on VDOM-1 and VDOM-2 so both VDOMs share the same physical interface, then add a policy route on root that forwards DNS traffic to 10.10.10.53.
C.Create a VDOM link between root and VDOM-1 and another between root and VDOM-2, then add static routes in VDOM-1 and VDOM-2 pointing to the root side of their respective VDOM links, and configure firewall policies on root to allow DNS to 10.10.10.53.
D.Enable inter-VDOM routing globally and create a single VDOM link shared by VDOM-1, VDOM-2, and root, then place all three VDOMs in the same OSPF area to exchange routes to 10.10.10.53.
AnswerC

A VDOM link is a virtual point-to-point interface pair that provides Layer 3 connectivity between two VDOMs. Each team VDOM routes toward the root side of its own link, and the root VDOM applies policies permitting only DNS to the shared server. Because each VDOM has a distinct link, traffic between VDOM-1 and VDOM-2 cannot traverse directly, satisfying isolation.

Why this answer

Inter-VDOM links create a private point-to-point Layer 3 path between exactly two VDOMs. By giving each team VDOM its own link to the root VDOM and controlling traffic with root-side policies, the administrator provides selective shared-service access while preventing any direct path between the two teams. Sharing one physical interface or one VDOM link across three VDOMs is not supported and would compromise isolation.

Exam trap

The trap here is assuming a single VDOM link or a shared physical interface can serve several VDOMs, when a VDOM link is only ever a two-VDOM point-to-point pair.

20
MCQeasy

In FortiAnalyzer, which tool provides real-time traffic monitoring and allows drilling down into details such as top talkers, applications, and threats?

A.Reports
B.Incidents
C.FortiView
D.Log Viewer
AnswerC

FortiView is FortiAnalyzer's real-time monitoring console, presenting drill-down dashboards for top talkers, applications, and threats. It queries live log data, letting analysts pivot from aggregate views into specific sessions and detections, which matches the requirement for real-time traffic monitoring with detailed drill-down.

Why this answer

FortiView in FortiAnalyzer provides real-time traffic monitoring with drill-down capabilities into top talkers, applications, and threats. It aggregates data from FortiGate logs and presents it in an interactive dashboard, allowing administrators to identify and investigate network anomalies instantly without generating reports.

Exam trap

The trap here is that candidates confuse the Log Viewer's ability to display logs in real time with FortiView's purpose-built aggregation and drill-down features, leading them to select Log Viewer instead of FortiView.

How to eliminate wrong answers

Option A is wrong because Reports in FortiAnalyzer are scheduled or on-demand summaries of historical data, not real-time monitoring tools. Option B is wrong because Incidents are correlated event groupings for security analysis, not a tool for live traffic inspection. Option D is wrong because Log Viewer displays raw log entries in a tabular format without real-time aggregation or drill-down into top talkers, applications, or threats.

21
MCQhard

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?

A.Create a firewall policy in VDOM-B that allows incoming traffic to the VDOM link interface and a policy in VDOM-A that allows traffic from the VDOM link to the server.
B.Create a central SNAT policy in VDOM-B to translate the public IP to the server's private IP, and apply it to the VDOM link.
C.Configure a VIP on VDOM-B that maps the public IP to the server's private IP, and ensure firewall policies allow the traffic in both VDOMs.
D.Enable NAT on the VDOM link interface in VDOM-B and create a static route in VDOM-A pointing to the server.
AnswerC

A VIP (Virtual IP) on VDOM-B performs destination NAT, translating the public IP to the server's private IP. Combined with firewall policies in VDOM-B (allowing incoming traffic to the VIP) and VDOM-A (allowing traffic from the VDOM link to the server), this enables access. The VDOM link carries the translated traffic between VDOMs.

Why this answer

To allow external access to a server behind a FortiGate with multiple VDOMs, a VIP must be configured on the VDOM with the public IP to perform destination NAT. Firewall policies in both VDOMs must permit the traffic, and the VDOM link carries the translated packets. Without the VIP, the server would not receive the traffic correctly.

Exam trap

The trap here is assuming that inter-VDOM routing and firewall policies alone are sufficient, overlooking the need for destination NAT via a VIP.

22
MCQeasy

An administrator needs to isolate customer traffic in a FortiGate deployed at a service provider. Each customer should have independent administrators and security policies. Which feature should be used?

A.VLAN interfaces
B.Policy packages
C.Administrative domains (ADOMs)
D.Virtual domains (VDOMs)
AnswerD

VDOMs partition a single FortiGate into independent virtual firewalls, each with its own administrators, policies, and routing. This satisfies the service provider requirement for isolated customer traffic with separate administrative access and security policies on one appliance.

Why this answer

Virtual domains (VDOMs) allow a single FortiGate to be partitioned into multiple independent virtual firewalls, each with its own administrators, security policies, routing tables, and interfaces. This is the correct feature for isolating customer traffic at a service provider because it provides complete administrative and policy separation per customer, which VLAN interfaces alone cannot achieve.

Exam trap

The trap here is confusing VLAN interfaces (Layer 2 segmentation) with VDOMs (full virtual firewall instances), leading candidates to choose VLANs when the question explicitly requires independent administrators and security policies.

How to eliminate wrong answers

Option A is wrong because VLAN interfaces only provide Layer 2 segmentation of traffic on a physical port; they do not create independent administrative domains or separate security policy contexts. Option B is wrong because policy packages are containers for firewall policies within a single VDOM or non-VDOM mode; they do not isolate administrators or provide independent routing and management. Option C is wrong because administrative domains (ADOMs) are a FortiManager concept for managing multiple FortiGate devices centrally, not a feature on the FortiGate itself for local isolation.

23
MCQhard

An administrator manages a FortiGate 500E with multiple VDOMs. The administrator needs to configure a new VDOM named 'Partner' and ensure that the Partner VDOM can use a dedicated physical interface for WAN connectivity. The FortiGate has an unused interface 'port5'. The administrator wants to assign port5 to the Partner VDOM and configure it with an IP address. Which sequence of steps is correct?

A.In the global configuration, edit port5 and set its VDOM to 'Partner'. Then, within the Partner VDOM, configure the IP address on port5.
B.Enable 'vdom-link' on port5 and assign it to the Partner VDOM, then configure the IP address.
C.In the global configuration, create a virtual interface and bind it to port5, then assign it to the Partner VDOM.
D.Within the Partner VDOM, create a new interface and map it to port5 using the 'set interface' command.
AnswerA

To assign a physical interface to a VDOM, you must first move the interface to that VDOM in the global configuration. After the interface is in the Partner VDOM, you can then configure its IP address and other settings within that VDOM's context. This two-step process is required because interface ownership is defined at the global level.

Why this answer

Physical interfaces are assigned to VDOMs from the global configuration by editing the interface and setting its VDOM attribute. Once the interface belongs to the Partner VDOM, you can enter that VDOM and configure the IP address and other settings. This is the correct and only method to dedicate a physical interface to a VDOM.

Exam trap

The trap here is attempting to configure the interface IP address before moving it to the VDOM, or trying to create a new interface within the VDOM; physical interfaces must be moved from global first.

24
Drag & Dropmedium

Drag and drop the steps to configure a FortiGate to send logs to a FortiAnalyzer into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure a FortiGate to send logs to FortiAnalyzer is: first add the FortiAnalyzer as a log device, then configure its IP address and shared key for authentication, then choose which log types (e.g., traffic, event, etc.) to forward, optionally apply filters to refine the logs, and finally test the connectivity to verify the configuration. This order ensures that each step builds upon the previous one, avoiding errors such as trying to configure a device that hasn't been added yet or testing before all settings are in place.

25
Matchingmedium

Match each Fortinet component to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Next-generation firewall

Centralized management platform

Logging and reporting server

Advanced threat detection and analysis

Web application firewall

Why these pairings

FortiGate is the NGFW, FortiManager manages devices, FortiAnalyzer handles logging/analytics, and FortiClient is an endpoint agent. Common confusions involve swapping these roles.

26
MCQhard

A company has deployed two FortiGate-600Es in an active-passive HA cluster. The cluster is configured with three VDOMs: VDOM-A (corporate LAN), VDOM-B (guest Wi-Fi), and VDOM-C (DMZ). Each VDOM has its own set of interfaces and policies. The cluster is also configured to use FGCP with session pickup enabled. Recently, the network team noticed that after a failover event, some user sessions in VDOM-B are not being picked up, causing disruption for guest users. The session pickup feature is enabled globally. The administrator checks the configuration and finds the following settings on the primary FortiGate: - config system ha set session-pickup enable set session-pickup-connectionless enable end - config vdom edit VDOM-A config system ha set session-pickup enable end next edit VDOM-B config system ha set session-pickup disable end next edit VDOM-C config system ha set session-pickup enable end next Based on this configuration, what is the most likely reason that sessions in VDOM-B are not being picked up?

A.The HA priority of the cluster is set too low, causing session pickup to fail for VDOM-B.
B.Session pickup for connectionless protocols is not enabled, so UDP sessions in VDOM-B are not picked up.
C.Session pickup is disabled specifically for VDOM-B in the per-VDOM HA configuration.
D.The interfaces assigned to VDOM-B do not have session pickup enabled.
AnswerC

Per-VDOM HA settings override the global session-pickup configuration, so VDOM-B's explicit `set session-pickup disable` prevents its sessions from being synchronised to the secondary FortiGate during failover. The global `set session-pickup enable` cannot re-enable it, which is why only guest Wi-Fi sessions are lost.

Why this answer

The per-VDOM HA configuration for VDOM-B explicitly disables session pickup with 'set session-pickup disable'. Even though the global HA settings enable session pickup, the per-VDOM setting overrides the global setting for that VDOM. As a result, after a failover, sessions in VDOM-B are not synchronized to the standby FortiGate and are not picked up, causing disruption for guest users.

Exam trap

The trap here is that candidates assume global session pickup settings apply uniformly to all VDOMs, overlooking that per-VDOM HA settings override the global configuration, which is a common misconfiguration in multi-VDOM HA deployments.

How to eliminate wrong answers

Option A is wrong because HA priority affects which unit becomes primary, not whether session pickup functions per VDOM; session pickup is controlled by explicit enable/disable settings, not priority. Option B is wrong because 'session-pickup-connectionless' is enabled globally, which would allow UDP and other connectionless sessions to be picked up, but this global setting is overridden by the per-VDOM disable for VDOM-B. Option D is wrong because session pickup is configured at the VDOM level, not per interface; interfaces inherit the VDOM's session pickup setting, so disabling it on the VDOM prevents pickup regardless of interface configuration.

27
MCQeasy

An administrator is reviewing the HA configuration shown in the exhibit. The primary unit has failed, and the secondary unit (with priority 100) has taken over. However, the administrator notices that the secondary unit has an IP address of 10.10.10.2 on port3, but cannot ping the management gateway 10.10.10.1. What is the most likely cause?

A.The HA management interface IP is not active on the secondary
B.The hbdev configuration is incorrect
C.The override setting is preventing the secondary from taking over management
D.session-pickup is not enabled
AnswerA

The management IP is active only on the primary unit; the secondary uses the same IP after failover, but the network may not have updated.

Why this answer

When the secondary unit takes over in an HA cluster, the HA management interface IP (configured under config system ha) is only active on the primary unit by default. Even after failover, the secondary unit does not automatically activate this IP unless the 'management-interface-ip' is explicitly configured to be active on the secondary. Since the secondary unit has IP 10.10.10.2 on port3 but cannot ping the management gateway 10.10.10.1, the most likely cause is that the HA management interface IP is not active on the secondary, meaning the secondary unit is using its own port3 IP (10.10.10.2) but the gateway expects the management IP to be reachable from that subnet, which it is not.

Exam trap

The trap here is that candidates often assume the secondary unit automatically inherits all IP addresses from the primary after failover, but FortiGate HA specifically requires explicit configuration for the management interface IP to be active on the secondary.

How to eliminate wrong answers

Option B is wrong because hbdev (heartbeat device) configuration affects HA heartbeat communication between units, not the activation of the management IP on the secondary after failover. Option C is wrong because the override setting controls whether a higher-priority unit can preempt the current primary after it recovers; it does not prevent the secondary from taking over management functions after the primary fails. Option D is wrong because session-pickup is a feature for synchronizing firewall sessions between HA members; it has no impact on whether the management interface IP is active on the secondary unit.

28
MCQeasy

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM and ensure that the interface is dedicated to that VDOM only. Which action should the administrator take?

A.Enable the 'dedicated' option in the interface settings and select the VDOM.
B.In the interface configuration, set the VDOM field to the desired VDOM.
C.Create a VLAN interface on the physical interface and assign the VLAN interface to the desired VDOM.
D.Use the 'set vdom' command in the global configuration to move the interface to the desired VDOM.
AnswerB

Each physical interface on a FortiGate can be assigned to a single VDOM. By setting the VDOM field in the interface configuration to the desired VDOM, the interface becomes dedicated to that VDOM. It will no longer be available to other VDOMs. This is the standard method to allocate physical interfaces to VDOMs, ensuring isolation and proper traffic handling.

Why this answer

To dedicate a physical interface to a VDOM, you assign the interface to that VDOM by setting its VDOM field in the interface configuration. This removes the interface from other VDOMs and makes it exclusively available to the assigned VDOM. Other methods like VLANs are used for sharing, and there is no 'dedicated' option.

Exam trap

The trap here is confusing interface dedication with VLAN sharing, or inventing a 'dedicated' setting that does not exist.

29
MCQhard

A FortiGate running FortiOS 7.2 has multiple VDOMs. The administrator notices that inter-VDOM routing between two VDOMs is not working. Configuration shows a firewall policy allowing the traffic, and the route table shows routes to the destination VDOM. What additional configuration is required?

A.Configure a static route with a gateway IP in the destination VDOM
B.Create a VDOM link interface pair and assign them to the respective VDOMs
C.Assign an IP address to the VLAN interface on the source VDOM
D.Enable 'inter-vdom' under config system global
AnswerB

Inter-VDOM traffic requires a VDOM link, a virtual interface pair whose ends sit in each VDOM, to carry packets between them. Routes and a permissive policy alone cannot forward traffic without this link, so the missing link explains the failure.

Why this answer

Inter-VDOM routing requires a VDOM link, which is a pair of logical interfaces (one in each VDOM) that are directly connected. Without this link, the VDOMs cannot exchange traffic even if firewall policies and routes exist, because they operate as separate virtual firewalls with isolated forwarding tables.

Exam trap

The trap here is that candidates assume a firewall policy and routes are sufficient for inter-VDOM traffic, overlooking the mandatory VDOM link interface pair that provides the actual Layer 3 adjacency between the VDOMs.

How to eliminate wrong answers

Option A is wrong because a static route with a gateway IP in the destination VDOM is not possible; the gateway must be reachable via an interface that belongs to the source VDOM, and inter-VDOM routing requires a direct link (VDOM link) rather than a next-hop in another VDOM. Option C is wrong because assigning an IP to a VLAN interface on the source VDOM does not create a path to the destination VDOM; VLAN interfaces are used for Layer 2 segmentation within a single VDOM, not for inter-VDOM connectivity. Option D is wrong because there is no 'inter-vdom' toggle under config system global; inter-VDOM routing is enabled by default when VDOMs are enabled, and the missing piece is the VDOM link interface pair, not a global setting.

30
MCQhard

A FortiGate administrator configures a VDOM with a limit on the number of firewall policies. The VDOM has 200 policies, and the limit is set to 250. The administrator attempts to add a new policy but receives an error indicating the limit has been reached. What is the MOST likely reason?

A.The administrator must reboot the FortiGate for the limit to take effect
B.The limit includes IPv4, IPv6, and other policy types
C.The VDOM has reached the maximum number of objects, not policies
D.The limit is per VDOM and cannot be changed
AnswerB

FortiGate's VDOM policy limit is a combined counter covering IPv4, IPv6, multicast and other policy types, not IPv4 alone. With 200 policies already configured across those categories, the effective total has reached 250, so the next addition is rejected despite the apparent headroom.

Why this answer

The FortiGate VDOM policy limit includes all policy types—IPv4, IPv6, and others (e.g., local-in policies, authentication policies). Even if the administrator has only 200 IPv4 policies, the total count of all policy types combined may already reach the 250 limit, preventing the addition of a new policy. This is why the error occurs despite the VDOM appearing to have room under the configured limit.

Exam trap

The trap here is that candidates assume the limit applies only to IPv4 firewall policies, ignoring that FortiGate counts all policy types (IPv4, IPv6, local-in, etc.) against the same limit, leading them to choose an incorrect answer like C or D.

How to eliminate wrong answers

Option A is wrong because policy limits take effect immediately without requiring a reboot; FortiGate enforces the limit dynamically upon policy creation. Option C is wrong because the error specifically references the policy limit, not the object limit; FortiGate has separate limits for objects (e.g., addresses, services) and policies, and the error message would differ if it were an object limit issue. Option D is wrong because the limit can be changed per VDOM via the config vdom command (e.g., set firewall-policy-limit), and it is not immutable.

31
MCQhard

A FortiGate HA cluster is configured with two units in active-passive mode. The administrator needs to perform a firmware upgrade on the cluster with minimal downtime. The current firmware version is 7.2.5 and the target is 7.2.7. The cluster uses FGCP with session synchronization enabled. Which procedure should the administrator follow?

A.Upgrade only the primary unit and let the secondary synchronize automatically
B.Disable HA, upgrade both units, then re-enable HA
C.Upgrade both units at the same time by connecting to each via console
D.Upgrade the passive unit first, perform a graceful failover, then upgrade the new passive unit
AnswerD

FGCP session synchronisation lets the passive unit take over with existing sessions intact. Upgrading the passive unit first keeps the active unit forwarding traffic, then a graceful failover makes the upgraded unit active, minimising downtime while both run 7.2.7.

Why this answer

It follows the recommended upgrade procedure for an active-passive FGCP cluster with session synchronization. By upgrading the passive unit first, then performing a graceful failover (which preserves existing sessions via FGCP session sync), and finally upgrading the new passive unit, the administrator ensures that the cluster remains operational throughout the process with minimal traffic disruption. This method avoids a full cluster outage and maintains session continuity.

Exam trap

The trap here is that candidates assume firmware synchronization works like configuration synchronization, leading them to choose Option A, but FGCP does not automatically replicate firmware images between cluster members.

How to eliminate wrong answers

Option A is wrong because upgrading only the primary unit does not cause the secondary to synchronize firmware; FGCP synchronizes configuration and session state, not firmware images, so the secondary would remain on the old version and the cluster would break. Option B is wrong because disabling HA removes redundancy and causes a full traffic outage during the upgrade, which contradicts the goal of minimal downtime. Option C is wrong because upgrading both units simultaneously via console without a failover sequence would likely cause a split-brain scenario or traffic loss, as both units would reboot at the same time, dropping all sessions.

32
MCQeasy

A network administrator wants to logically separate two departments on a single FortiGate. Each department must have its own firewall policies, routing table, and administrators. Which feature should be used?

A.Virtual Domains (VDOMs)
B.Policy Packages
C.Administrative Domains (ADOMs)
D.VLANs
AnswerA

VDOMs partition a single FortiGate into independent virtual firewalls, each with its own firewall policies, routing table and administrator accounts. This satisfies the requirement to separate the two departments logically while sharing the same physical appliance.

Why this answer

Virtual Domains (VDOMs) allow a single FortiGate to be partitioned into multiple independent virtual firewalls, each with its own firewall policies, routing table, and administrative access. This meets the requirement for logical separation of departments with isolated policy and routing domains.

Exam trap

The trap here is confusing VLANs with VDOMs: VLANs segment Layer 2 traffic but do not provide independent routing tables or administrative domains, so candidates often pick VLANs when the question explicitly requires separate routing and administrators.

How to eliminate wrong answers

Option B is wrong because Policy Packages are used to group firewall policies within a VDOM or a non-VDOM FortiGate, but they do not provide separate routing tables or independent administrators. Option C is wrong because Administrative Domains (ADOMs) are a FortiManager concept for managing multiple FortiGates or VDOMs, not a feature on a single FortiGate for local separation. Option D is wrong because VLANs operate at Layer 2 to segment broadcast domains and require a Layer 3 interface or VDOM to enforce separate routing tables and firewall policies; they do not inherently provide independent routing or administrative isolation.

33
MCQmedium

An administrator is deploying a FortiGate with multiple VDOMs in NAT mode. The administrator wants to ensure that traffic between VDOMs is inspected by security profiles and that inter-VDOM traffic does not bypass the firewall policy engine. Which configuration is required to achieve this?

A.Enable VDOM partitioning and assign interfaces to each VDOM.
B.Enable inter-VDOM routing and create a firewall policy between the VDOM links.
C.Enable ASIC offloading for inter-VDOM traffic to ensure inspection.
D.Configure a single firewall policy with all interfaces as source and destination.
AnswerB

Inter-VDOM links create virtual interfaces that allow traffic to be routed between VDOMs. To inspect traffic, you must create firewall policies on each VDOM that permit and inspect traffic entering and leaving the VDOM link. This ensures that security profiles are applied and traffic does not bypass the policy engine.

Why this answer

Inter-VDOM routing requires VDOM links, which are virtual interfaces that connect VDOMs. To inspect inter-VDOM traffic, firewall policies must be created on each VDOM to allow and apply security profiles to traffic traversing the VDOM link. This ensures that all inter-VDOM traffic is subject to the same security policies as external traffic, preventing bypass.

Exam trap

The trap here is assuming that enabling inter-VDOM links automatically inspects traffic; policies are still required on both VDOMs.

34
MCQhard

An administrator configures a multi-VDOM FortiGate in transparent mode. The admin notices that the management IP is reachable from both interfaces, but traffic passing through the device is not being inspected. What is the likely issue?

A.Inter-VDOM routing is misconfigured
B.The VDOM is in transparent mode, but no firewall policy is applied to the traffic
C.The FortiGate needs a default route
D.The management IP is assigned to the wrong VDOM
AnswerB

In transparent mode a VDOM still requires firewall policies to permit and inspect traffic; without one, frames are forwarded uninspected. The reachable management IP merely confirms the VDOM is up, so the missing policy is the actual cause of traffic bypassing inspection.

Why this answer

In transparent mode, a FortiGate acts as a Layer 2 bridge, and traffic passing through the device is controlled by firewall policies, not by routing. Even though the management IP is reachable (because it is a separate IP on the bridge interface), no traffic inspection occurs unless an explicit firewall policy is configured to allow and inspect the traffic between the bridge interfaces. Option B correctly identifies that the missing firewall policy is the root cause.

Exam trap

The trap here is that candidates assume transparent mode automatically inspects all traffic or that management IP reachability implies full functionality, but in reality, a firewall policy is mandatory for traffic inspection even in Layer 2 mode.

How to eliminate wrong answers

Option A is wrong because inter-VDOM routing is not relevant in a single-VDOM transparent mode setup; the issue is about intra-VDOM traffic passing through the bridge, not between VDOMs. Option C is wrong because a default route is used for management traffic originating from the FortiGate itself, not for transit traffic passing through the device in transparent mode; transit traffic is bridged and does not require a routing table. Option D is wrong because the management IP being reachable from both interfaces indicates it is correctly assigned to the VDOM; the problem is the lack of a firewall policy to inspect transit traffic, not a misassignment of the management IP.

35
MCQhard

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The default route in VDOM-A points to a next-hop router, and VDOM-B has a static route to a subnet behind VDOM-A. Users in VDOM-B cannot reach that subnet. The administrator runs 'diagnose ip route list' in both VDOMs and sees the routes are present. What is the most likely cause?

A.The VDOM link MTU is too small for the traffic
B.The VDOM link interfaces are administratively down
C.Firewall policies are missing on the VDOMs to permit traffic between the VDOM link and the destination interfaces
D.The VDOMs are in different administrative domains (ADOMs) on FortiManager
AnswerC

Routes exist in both VDOMs, so forwarding is resolved; the VDOM link interfaces and destination interfaces still require firewall policies to permit the traffic. Inter-VDOM routing is not implicitly allowed, so absent policies silently drop packets between VDOM-A and VDOM-B.

Why this answer

Even though the routes are present in both VDOMs, inter-VDOM routing via a VDOM link requires explicit firewall policies on each VDOM to permit traffic between the VDOM link interface and the destination interface. Without these policies, the FortiGate drops the traffic at the firewall layer, even though the routing table is correct. This is a common misconfiguration because VDOM links behave like physical interfaces and are subject to firewall policy enforcement.

Exam trap

The trap here is that candidates assume that because routes are present and the VDOM link is up, traffic should flow automatically, forgetting that FortiGate enforces firewall policies even for inter-VDOM traffic.

How to eliminate wrong answers

Option A is wrong because an MTU mismatch would cause fragmentation issues or packet drops, but the routes would still be present and the administrator would typically see ICMP fragmentation-needed messages or packet loss, not a complete inability to reach the subnet. Option B is wrong because if the VDOM link interfaces were administratively down, the routes would not appear in the routing table (the interface would be down, making the next-hop unreachable), and the administrator would see the interfaces in a 'down' state. Option D is wrong because ADOMs on FortiManager are a management-plane concept that controls visibility and administrative access, not data-plane forwarding; inter-VDOM routing is handled locally on the FortiGate and is unaffected by FortiManager ADOM configuration.

36
MCQhard

An administrator configures automation stitches on FortiManager to trigger a script when a specific event log is received. The script should block the source IP on the firewall. However, the script does not run when the event occurs. What is a likely cause?

A.The event handler filter does not match the log
B.The FortiGate is in transparent mode
C.The script is not compiled
D.The script is set to run on all managed devices
AnswerA

Automation stitches fire only when the event handler's filter matches the incoming log. If the filter criteria do not match the log's fields or values, the stitch never triggers, so the blocking script is never executed despite the event occurring.

Why this answer

Automation stitches on FortiManager rely on event handler filters to match specific log IDs or patterns. If the filter does not match the incoming event log (e.g., wrong log ID, incorrect field value, or mismatched severity), the trigger condition is never met, and the script will not execute. This is the most common misconfiguration when setting up event-driven automation.

Exam trap

The trap here is that candidates may assume the script itself has a syntax error or that transparent mode disables automation, but the real issue is almost always a filter mismatch in the event handler configuration.

How to eliminate wrong answers

Option B is wrong because FortiGate transparent mode does not prevent automation stitches from running; the script execution is independent of the firewall's operational mode. Option C is wrong because FortiManager scripts are interpreted, not compiled, so there is no compilation step required. Option D is wrong because setting the script to run on all managed devices would not prevent it from running; it would simply apply the script to every device, which could cause unintended behavior but does not block execution.

37
MCQeasy

What is the purpose of header and footer policies in a FortiManager policy package?

A.They are used for VDOM-specific policies that cannot be modified
B.They provide a way to group policies for reporting purposes
C.They define policies that are placed at the top (header) and bottom (footer) of the policy list when applied to a FortiGate
D.They allow policy packages to be installed in a specific sequence
AnswerC

Header and footer policies sit at the very top and bottom of the policy list once the package is installed on a FortiGate, giving administrators guaranteed precedence for global allow or deny rules regardless of where other policies are inserted.

Why this answer

Header and footer policies in FortiManager policy packages allow administrators to define policies that are automatically placed at the very top (header) and very bottom (footer) of the policy list when the package is installed on a FortiGate. This ensures that critical policies, such as default deny rules or inter-VDOM links, remain in a fixed position regardless of other policy changes. This mechanism is essential for maintaining a consistent security posture across managed FortiGates.

Exam trap

The trap here is that candidates often confuse header/footer policies with VDOM-specific policies or policy grouping, when in fact they are specifically designed to enforce a fixed policy order at the top and bottom of the policy list.

How to eliminate wrong answers

Option A is wrong because header and footer policies are not VDOM-specific; they are part of the policy package and can be modified like any other policy. Option B is wrong because header and footer policies are not used for grouping policies for reporting; reporting groups are handled via policy tags or separate grouping features. Option D is wrong because header and footer policies do not control the installation sequence of policy packages; installation sequence is managed by the 'Installation Order' setting in FortiManager, not by header/footer policies.

38
MCQeasy

What is the primary purpose of an administrative VDOM on a FortiGate?

A.To enable transparent mode operation
B.To increase the maximum number of firewall policies
C.To provide independent management and administrative access for different tenants or departments
D.To route traffic between different VDOMs
AnswerC

An administrative VDOM isolates management functions, giving each tenant or department its own administrators, routing and configuration scope without affecting others. This satisfies the stem's requirement for independent management and administrative access, since each VDOM maintains separate admin accounts, policies and objects within the single FortiGate device.

Why this answer

An administrative VDOM on a FortiGate provides independent management and administrative access for different tenants or departments. Each administrative VDOM has its own administrator accounts, authentication settings, and management interfaces (HTTPS, SSH, SNMP), allowing multi-tenant isolation without requiring separate physical firewalls. This is distinct from traffic-forwarding VDOMs, which handle data plane operations.

Exam trap

The trap here is confusing the management-plane isolation of an administrative VDOM with data-plane functions like inter-VDOM routing or transparent mode, leading candidates to select options that describe traffic forwarding or operational modes instead of administrative separation.

How to eliminate wrong answers

Option A is wrong because transparent mode operation is a per-VDOM setting (config system vdom edit <vdom> set mode transparent), not a purpose of an administrative VDOM; administrative VDOMs can operate in either transparent or NAT mode. Option B is wrong because the maximum number of firewall policies is limited by the FortiGate model and total VDOM resources, not by the presence of an administrative VDOM; an administrative VDOM does not increase policy limits. Option D is wrong because routing traffic between different VDOMs is accomplished via inter-VDOM links (config system vdom-link) or VDOM peering, not by an administrative VDOM, which is solely for management plane separation.

39
MCQeasy

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that a specific VDOM can use more system resources, such as sessions and CPU, than other VDOMs. Which FortiGate feature should the administrator use?

A.Configure per-VDOM resource limits in the VDOM settings.
B.Enable NPU offloading for the VDOM to increase its throughput.
C.Create a separate administrative profile for the VDOM with elevated privileges.
D.Assign a higher priority to the VDOM in the global VDOM configuration.
AnswerA

FortiGate allows administrators to set resource limits per VDOM, such as maximum sessions, CPU usage, and memory. This ensures that a VDOM can be allocated more resources or restricted to prevent it from consuming all system resources. The administrator can adjust these limits for the specific VDOM that requires more resources.

Why this answer

To allocate more system resources to a specific VDOM, the administrator should configure per-VDOM resource limits. FortiGate allows setting maximum sessions, CPU usage, memory, and other resources on a per-VDOM basis. This ensures that the VDOM has sufficient resources while preventing it from monopolizing system resources.

This is the correct feature for resource allocation in multi-VDOM deployments.

Exam trap

The trap here is confusing performance optimization features like NPU offloading with resource allocation controls such as per-VDOM limits.

40
MCQeasy

Which FortiAnalyzer feature allows administrators to create automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected?

A.FortiView
B.Reports
C.Incidents
D.Playbooks
AnswerD

Playbooks in FortiAnalyzer chain automated response actions to log-event triggers, so an intrusion detection event can invoke a block-IP action without manual intervention. This satisfies the requirement for automated, event-driven response rather than static alerting or scheduled reports.

Why this answer

Playbooks in FortiAnalyzer allow administrators to define automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected. This feature uses a visual workflow editor to chain conditions and actions (e.g., executing CLI commands via FortiGate API or sending alerts) based on real-time log analysis, enabling automated threat mitigation without manual intervention.

Exam trap

The trap here is that candidates confuse Playbooks with Incidents, assuming Incidents include automation, but Incidents are purely for manual or semi-manual investigation workflows, while Playbooks are the only feature for fully automated, event-triggered responses.

How to eliminate wrong answers

Option A is wrong because FortiView is a real-time monitoring and visualization tool that displays traffic logs, sessions, and security events, but it does not provide automation or trigger-based response actions. Option B is wrong because Reports are scheduled or on-demand document generation tools for summarizing historical data, not for executing automated responses to live events. Option C is wrong because Incidents are a grouping mechanism for related alerts and logs to aid investigation, but they do not include automated action execution like blocking IPs.

41
MCQmedium

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A.The session has expired and is being removed
B.A UDP session on port 443 is being blocked
C.The firewall policy is incorrectly configured
D.A TCP session on port 443 has been active for 1 hour and will expire in 3599 seconds
AnswerD

The output shows proto=6 (TCP), duration=3600 seconds (one hour active) and expire=3599 seconds remaining. This precisely matches a TCP session on destination port 443 that has run for an hour and will time out in 3599 seconds.

Why this answer

The output shows a TCP session (proto=6) on port 443 with a duration of 3600 seconds (1 hour) and an expire value of 3599 seconds, meaning the session has been active for 1 hour and will expire in 3599 seconds. The 'proto=6' indicates TCP, and 'proto_state=01' is the TCP established state, confirming an active TCP session.

Exam trap

The trap here is that candidates may misinterpret 'expire=3599' as the session expiring soon or already expired, when in fact it indicates the remaining time before timeout, and the session is still active with a duration of 3600 seconds.

How to eliminate wrong answers

Option A is wrong because the expire value of 3599 seconds indicates the session is still active and will expire in the future, not that it has expired and is being removed. Option B is wrong because proto=6 indicates TCP, not UDP, and the session is not being blocked; it is active. Option C is wrong because the output does not provide any information about firewall policy configuration; it only shows session state and timing details.

42
MCQmedium

A FortiGate 600E is running in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator assigns physical port3 to VDOM-1 as a dedicated interface, then creates a VLAN subinterface (VLAN 100) on port3 for VDOM-2. After configuration, VLAN 100 traffic is dropped even though the VLAN interface is up. Which action resolves the issue?

A.Configure a VDOM link between VDOM-1 and VDOM-2 and route VLAN 100 traffic through the link.
B.Enable the vlan-forwarding setting under config system interface on port3.
C.Assign the physical port3 interface to VDOM-2 as well, using the same interface in both VDOMs.
D.Create the VLAN 100 subinterface inside VDOM-1, where the parent interface resides, rather than in VDOM-2.
AnswerD

VLAN subinterfaces must be created on the parent interface within the same VDOM that owns the parent. Since port3 belongs to VDOM-1, VLAN 100 must be defined in VDOM-1. If VDOM-2 needs separate VLAN traffic, the parent interface should be shared or a different physical interface used in VDOM-2.

Why this answer

On FortiGate, VLAN subinterfaces inherit the VDOM membership of their parent physical interface. Because port3 is assigned to VDOM-1, VLAN 100 must also be created within VDOM-1. Creating it under VDOM-2 leaves the traffic unhandled in the VDOM that actually receives the frames, so frames are dropped.

Exam trap

The trap here is assuming that a subinterface can be placed in a different VDOM than its parent interface, which is not supported on FortiGate.

43
MCQmedium

An enterprise FortiGate has multiple VDOMs. The administrator wants to allow traffic from VDOM A to reach servers in VDOM B without traversing an external router. Which configuration is required?

A.Place both VDOMs in the same VDOM group
B.Configure a static route in each VDOM pointing to the other VDOM's management IP
C.Create an inter-VDOM link using the 'config system interface' command with type 'vdom-link'
D.Enable VDOM forwarding in global settings
AnswerC

A vdom-link interface creates a direct virtual connection between VDOMs, allowing traffic to pass internally without an external router. Configuring it via 'config system interface' with type 'vdom-link' satisfies the requirement for VDOM A to reach VDOM B servers without external routing.

Why this answer

Inter-VDOM links are the native FortiGate mechanism for routing traffic between VDOMs without external hardware. Created via 'config system interface' with type 'vdom-link', they act as a direct Layer 3 connection between VDOMs, allowing traffic to flow internally through the FortiGate's backplane. This avoids the need for an external router or physical cabling.

Exam trap

The trap here is that candidates often confuse enabling VDOM forwarding (a global toggle) with creating the actual inter-VDOM link, assuming the toggle alone allows traffic to flow between VDOMs without an explicit interface configuration.

How to eliminate wrong answers

Option A is wrong because VDOM groups are used for administrative grouping or shared resources (like VDOMs in a security fabric), not for enabling Layer 3 traffic forwarding between VDOMs. Option B is wrong because static routes pointing to a VDOM's management IP would only reach the management interface, not forward data traffic to the other VDOM's networks; management IPs are not used for data-plane forwarding. Option D is wrong because VDOM forwarding (enabled via 'config system global' with 'vdom-forward') controls whether the FortiGate can forward traffic between VDOMs at all, but it does not create the actual link or interface needed for inter-VDOM communication; an inter-VDOM link is still required.

44
MCQmedium

A FortiGate running FortiOS 7.4.1 has two VDOMs: CustomerA and CustomerB. The administrator wants CustomerA to access an HTTP server in CustomerB. Both VDOMs have appropriate policies. What additional configuration is required?

A.Configure a VDOM link between CustomerA and CustomerB
B.Create a policy allowing traffic from CustomerA to CustomerB
C.Enable inter-VDOM routing under system settings
D.Assign both VDOMs to the same administrative domain in FortiManager
AnswerA

Inter-VDOM routing requires a VDOM link, a virtual point-to-point interface pair connecting the two VDOMs. Without it, traffic from CustomerA cannot reach CustomerB even when both have correct policies, because VDOMs are isolated routing instances.

Why this answer

A VDOM link is required to enable Layer-2 or Layer-3 connectivity between two VDOMs on the same FortiGate. Without a VDOM link, the VDOMs are isolated from each other, even if policies exist. The VDOM link acts as a virtual interface pair that forwards traffic between CustomerA and CustomerB, allowing the HTTP server access.

Exam trap

The trap here is that candidates assume inter-VDOM policies alone suffice, forgetting that VDOMs are fully isolated routing domains requiring a dedicated link (VDOM link) to exchange traffic.

How to eliminate wrong answers

Option B is wrong because policies alone cannot forward traffic between VDOMs; inter-VDOM traffic requires a VDOM link to provide the physical or logical path. Option C is wrong because inter-VDOM routing is not a global setting that can be enabled; it is inherently provided by configuring VDOM links or inter-VDOM links under each VDOM. Option D is wrong because FortiManager administrative domains are management constructs for centralized device management, not for enabling data-plane traffic between VDOMs on a single FortiGate.

45
MCQhard

An organization has multiple ADOMs in FortiManager. The admin wants to share a set of firewall objects across all ADOMs. What is the best approach?

A.Create a meta field and assign objects
B.Use the Global ADOM to create global objects
C.Manually recreate the objects in each ADOM
D.Enable object sharing in the system settings
AnswerB

Global ADOM objects are inherited by every ADOM, satisfying the cross-ADOM sharing requirement without duplication. Objects created there propagate automatically to all ADOMs, including newly created ones, and remain centrally managed. Per-ADOM objects cannot be referenced elsewhere, so only the Global ADOM provides the required scope.

Why this answer

The Global ADOM in FortiManager is specifically designed to create and manage global objects (such as address objects, services, and schedules) that can be shared across all regular ADOMs. When an object is created in the Global ADOM, it is automatically available in all ADOMs that are linked to it, eliminating the need for duplication. This is the only native, supported method for sharing objects across multiple ADOMs in FortiManager.

Exam trap

The trap here is that candidates may confuse the Global ADOM with a regular ADOM or think that a simple system setting can enable object sharing, when in fact the Global ADOM is a distinct, purpose-built feature for cross-ADOM object sharing.

How to eliminate wrong answers

Option A is wrong because meta fields are used for custom metadata tagging and filtering of objects within an ADOM, not for sharing objects across ADOMs. Option C is wrong because manually recreating objects in each ADOM is inefficient, error-prone, and defeats the purpose of centralized management with FortiManager. Option D is wrong because FortiManager does not have a system-level 'object sharing' toggle; object sharing is achieved exclusively through the Global ADOM mechanism.

46
Multi-Selecteasy

A FortiGate administrator wants to use FortiAnalyzer to view traffic logs from multiple VDOMs. Which TWO steps must the administrator perform on FortiAnalyzer?

Select 2 answers
A.Install a security profile on FortiAnalyzer
B.Add the FortiGate as a device in FortiAnalyzer
C.Create a separate ADOM for each VDOM
D.Configure the FortiGate to send logs to FortiAnalyzer
E.Enable FortiAnalyzer's built-in firewall
AnswersB, D

Adding the FortiGate as a device in FortiAnalyzer establishes the log-receiving relationship and registers each VDOM as a separate ADOM or device entry, satisfying the requirement to view traffic logs from multiple VDOMs. Without this registration, FortiAnalyzer cannot receive or index the FortiGate's logs.

Why this answer

Option B is correct because FortiAnalyzer can only receive, index, and display logs from a FortiGate after that FortiGate has been added as a managed device (via the device registration/authorization process), which establishes the log-receiving relationship. Option D is correct because the FortiGate must be configured to send its logs to FortiAnalyzer, typically by enabling logging to FortiAnalyzer under config log fortianalyzer setting and pointing it at the FortiAnalyzer IP, so that traffic logs from all VDOMs are actually transmitted. Options A and E are incorrect because FortiAnalyzer is a log management and analytics appliance, not a traffic-inspecting firewall, so it does not require security profiles or a built-in firewall to view logs.

Option C is incorrect because a single ADOM can contain the FortiGate and its multiple VDOMs; separate ADOMs per VDOM are not required to view multi-VDOM traffic logs.

Exam trap

The trap here is that candidates often think a separate ADOM is mandatory for each VDOM, but FortiAnalyzer can consolidate logs from multiple VDOMs into a single ADOM, and the key requirement is simply adding the FortiGate as a device and configuring log forwarding.

47
Multi-Selectmedium

An enterprise FortiGate has multiple VDOMs. The security policy requires that all traffic between VDOMs must be inspected by a next-generation firewall profile. Which three steps are necessary to achieve this? (Choose three.)

Select 3 answers
A.Ensure routing is properly configured to forward traffic through the inter-VDOM link
B.Place both VDOMs in the same ADOM in FortiManager
C.Enable VDOM inspection mode in global settings
D.Configure a firewall policy on the inter-VDOM link with the required security profile
E.Create an inter-VDOM link between the VDOMs
AnswersA, D, E

Routes direct traffic to the link interface.

Why this answer

For traffic to traverse between VDOMs via an inter-VDOM link, proper routing must be configured in each VDOM to forward traffic through the inter-VDOM link interface. Without correct routing entries (static or dynamic), packets will not be directed to the inter-VDOM link, and the next-generation firewall profile cannot be applied.

Exam trap

The trap here is that candidates often assume VDOM inspection mode must be enabled globally to apply security profiles on inter-VDOM links, but in reality, the inspection mode only affects how VDOMs handle traffic at the kernel level and does not control policy-based inspection on inter-VDOM links.

48
MCQhard

An administrator has configured two VDOMs on a FortiGate. One VDOM is in NAT mode and the other in transparent mode. The administrator wants traffic from the transparent mode VDOM to be routed through the NAT mode VDOM. What must be configured to allow inter-VDOM routing?

A.Use a physical interface to connect the VDOMs
B.Create an inter-VDOM link
C.Enable NPU offloading
D.Configure firewall policies between the VDOMs
AnswerB

An inter-VDOM link creates a virtual point-to-point Ethernet interface pairing two VDOMs, enabling traffic to pass between them regardless of operating mode. This satisfies the requirement to route traffic from the transparent VDOM into the NAT-mode VDOM, since the link provides the Layer 3 path that transparent mode alone cannot supply.

Why this answer

Inter-VDOM routing between VDOMs in different modes (NAT and transparent) requires a dedicated inter-VDOM link (IVL), which is a virtual internal connection that allows traffic to pass between VDOMs without consuming physical ports. The IVL creates a pair of virtual interfaces, one in each VDOM, and firewall policies must be configured to permit traffic across them. This is the only method that supports routing between VDOMs of different modes on the same FortiGate.

Exam trap

The trap here is that candidates assume firewall policies alone can route traffic between VDOMs, but without an inter-VDOM link, the VDOMs are completely isolated and cannot exchange any traffic regardless of policy configuration.

How to eliminate wrong answers

Option A is wrong because using a physical interface to connect VDOMs is unnecessary and inefficient; inter-VDOM links are virtual and avoid wasting physical ports. Option C is wrong because NPU offloading is a hardware acceleration feature for packet processing, not a mechanism for enabling inter-VDOM routing. Option D is wrong because firewall policies alone cannot enable inter-VDOM routing; they are required after the inter-VDOM link is created to allow traffic, but the link itself is the fundamental connectivity component.

49
MCQhard

A FortiGate in transparent mode is deployed between a router and a switch. The administrator needs to apply a deep inspection profile to HTTP traffic. What is the correct configuration for the interfaces?

A.Configure a management IP on the VDOM and apply the inspection profile to the policy
B.Place both interfaces in the same VDOM and enable DHCP
C.Switch to NAT mode to enable deep inspection
D.Assign IPs to both interfaces and create a policy from LAN to WAN
AnswerA

The VDOM management IP provides connectivity; policies inspect traffic on the bridge.

Why this answer

In transparent mode, FortiGate acts as a Layer 2 bridge, so interfaces do not require IP addresses. Deep inspection of HTTP traffic is applied via a firewall policy that references a deep inspection profile, and a management IP must be configured on the VDOM to allow the FortiGate to participate in management traffic (e.g., DNS, NTP, or proxy operations). Option A correctly identifies that the management IP is set on the VDOM and the inspection profile is applied to the policy.

Exam trap

The trap here is that candidates assume transparent mode cannot perform deep inspection because it lacks routed interfaces, but FortiGate supports full UTM inspection in transparent mode via the management IP and policy-based profiles.

How to eliminate wrong answers

Option B is wrong because placing both interfaces in the same VDOM is correct for transparent mode, but enabling DHCP is unnecessary and irrelevant—transparent mode interfaces do not require IP addresses or DHCP services. Option C is wrong because deep inspection is fully supported in transparent mode; switching to NAT mode is not required and would change the FortiGate's Layer 2 behavior. Option D is wrong because assigning IPs to both interfaces is not valid in transparent mode—interfaces remain without IPs, and policies are created using the management IP, not LAN-to-WAN direction.

50
MCQmedium

A FortiGate has multiple VDOMs. The administrator notices that traffic from VDOM-1 to VDOM-2 is allowed by inter-VDOM policies but is not being inspected by the security profiles. What is the most likely cause?

A.The security profiles are applied only on the egress VDOM
B.The traffic is using a bypass path due to asymmetric routing
C.The VDOMs are in different virtual routers
D.The VDOM link is configured as a signal interface
AnswerA

Correct.

Why this answer

When inter-VDOM traffic flows through a VDOM link, security profiles are applied only on the egress VDOM by default. This is because the VDOM link acts as a logical wire, and inspection occurs at the point where traffic exits the link. If the administrator has applied security profiles only on the ingress VDOM (VDOM-1), they will not be enforced on traffic leaving VDOM-1 toward VDOM-2, resulting in no inspection.

Exam trap

The trap here is that candidates assume security profiles are applied symmetrically on both sides of an inter-VDOM link, but FortiGate only inspects traffic on the egress VDOM, so profiles must be configured on the destination VDOM's policy.

How to eliminate wrong answers

Option B is wrong because asymmetric routing would cause session setup failures or packet drops, not a bypass of security profiles; inter-VDOM policies still enforce inspection regardless of routing symmetry. Option C is wrong because different virtual routers do not prevent inter-VDOM traffic from being inspected; they only affect routing decisions, not security profile application. Option D is wrong because a signal interface is used for heartbeat or management traffic between VDOMs, not for data traffic, and would not cause security profiles to be skipped.

51
MCQeasy

An administrator wants to use FortiAnalyzer to generate weekly compliance reports for all managed FortiGates. Which FortiAnalyzer feature should be used?

A.Incidents
B.Reports
C.FortiView
D.Log Analytics
AnswerB

FortiAnalyzer Reports is the built-in feature for generating scheduled compliance and security reports from logged data across managed devices. Configuring a weekly schedule with all FortiGates as data sources produces the required recurring output, which other features such as Log Browse or Incidents do not provide.

Why this answer

FortiAnalyzer's Reports feature is specifically designed to generate scheduled, customizable compliance reports that aggregate data from multiple managed FortiGates. This allows administrators to produce weekly reports aligned with regulatory standards (e.g., PCI DSS, HIPAA) without manual effort, leveraging pre-defined or custom report templates.

Exam trap

The trap here is that candidates often confuse FortiView's real-time dashboards with the scheduled, template-driven reporting capability of the Reports module, assuming that visualization tools can substitute for formal compliance report generation.

How to eliminate wrong answers

Option A is wrong because Incidents in FortiAnalyzer are used for tracking and managing security events and alerts, not for generating scheduled compliance reports. Option C is wrong because FortiView provides real-time and historical data visualization for monitoring and troubleshooting, but it lacks the scheduling and template-based reporting required for weekly compliance reports. Option D is wrong because Log Analytics focuses on searching, correlating, and analyzing log data, not on producing formatted, scheduled compliance reports.

52
MCQmedium

An admin needs to configure a FortiGate to send logs to FortiAnalyzer for a specific VDOM only. How can this be achieved?

A.Set the FortiAnalyzer IP in the specific VDOM's log settings
B.Create a separate ADOM in FortiAnalyzer for that VDOM
C.Configure log forwarding globally; it applies to all VDOMs
D.Use a firewall policy to filter logs to FortiAnalyzer
AnswerA

Configuring FortiAnalyzer under the target VDOM's log settings scopes log forwarding to that VDOM alone, since each VDOM maintains independent log configuration on the FortiGate. This satisfies the stem's requirement to send logs for a specific VDOM only, leaving other VDOMs unaffected.

Why this answer

FortiGate allows per-VDOM log configuration, including the FortiAnalyzer IP address, under the VDOM's log settings. This ensures that only logs from that specific VDOM are sent to the designated FortiAnalyzer, while other VDOMs remain unaffected.

Exam trap

The trap here is that candidates often confuse global log forwarding with per-VDOM log settings, assuming that a global configuration can be selectively applied to a single VDOM, which is not supported in FortiGate's VDOM architecture.

How to eliminate wrong answers

Option B is wrong because creating a separate ADOM in FortiAnalyzer is a management and administrative grouping on the FortiAnalyzer side, not a configuration on the FortiGate to control which VDOM's logs are sent. Option C is wrong because configuring log forwarding globally applies to all VDOMs, which does not meet the requirement of sending logs for a specific VDOM only. Option D is wrong because firewall policies are used for traffic filtering and not for selecting which logs are forwarded to FortiAnalyzer; log forwarding is controlled by log settings, not firewall policies.

53
MCQeasy

A company is implementing a Security Fabric with multiple FortiGate devices. They want to use FortiAnalyzer for centralized logging and FortiManager for centralized management. Which of the following is a prerequisite for adding a FortiGate to the Security Fabric?

A.The FortiGate must have FortiAnalyzer configured as a log device
B.The FortiGate's management IP must be configured via DHCP
C.The FortiGate must have network connectivity to the FortiManager
D.The FortiGate must be operating in transparent mode
AnswerC

Connectivity is required for management.

Why this answer

For a FortiGate to join a Security Fabric, it must have network connectivity to the FortiManager that manages the fabric. FortiManager acts as the fabric root or controller, and the FortiGate registers with it using the FortiManager IP or FQDN. Without this connectivity, the FortiGate cannot be added to the Security Fabric topology.

Exam trap

The trap here is that candidates often confuse the prerequisite for logging (FortiAnalyzer) with the prerequisite for fabric management (FortiManager), assuming both must be configured before adding a FortiGate, but only FortiManager connectivity is required for fabric membership.

How to eliminate wrong answers

Option A is wrong because configuring FortiAnalyzer as a log device is not a prerequisite for adding a FortiGate to the Security Fabric; logging can be configured after the FortiGate joins the fabric. Option B is wrong because the FortiGate's management IP can be static or DHCP, but DHCP is not a requirement; the prerequisite is simply that the FortiGate has a reachable management IP. Option D is wrong because the FortiGate can operate in NAT/route mode or transparent mode when joining the Security Fabric; transparent mode is not a requirement.

54
MCQmedium

A FortiGate administrator runs the following command and sees the output: diagnose sys session filter dport 443 diagnose sys session list Output shows sessions with proto=6 and expire time decreasing. What does this indicate?

A.The sessions are using UDP protocol
B.The FortiGate is performing deep packet inspection on these sessions
C.The sessions are being blocked by a firewall policy
D.The sessions are TCP sessions and are active
AnswerD

Proto=6 identifies TCP, and a decreasing expire timer proves the session remains live in the FortiGate session table rather than timing out. This satisfies the stem's constraint: port 443 traffic is being tracked as established, active TCP sessions, confirming normal stateful inspection behaviour.

Why this answer

The command 'diagnose sys session filter dport 443' filters sessions with destination port 443, and 'diagnose sys session list' displays them. The output shows 'proto=6', which is the protocol number for TCP (per IANA protocol numbers). The 'expire time decreasing' indicates that the session timer is counting down, which is normal behavior for an active TCP session that is being refreshed by ongoing traffic.

Therefore, the sessions are TCP and active.

Exam trap

The trap here is that candidates may confuse 'expire time decreasing' with a session being blocked or expiring, when in fact it is a normal indicator of an active TCP session that is being refreshed by traffic.

How to eliminate wrong answers

Option A is wrong because proto=6 specifically indicates TCP, not UDP (UDP is protocol 17). Option B is wrong because the command output does not show any deep packet inspection (DPI) status; DPI would require additional configuration and is not indicated by session list output. Option C is wrong because blocked sessions would not appear in the session list with a decreasing expire time; blocked traffic is denied by the firewall policy and does not create a session entry.

55
Multi-Selectmedium

A FortiGate administrator wants to use FortiManager automation stitches to automatically block IP addresses that trigger multiple intrusion prevention events. Which two components are required to configure an automation stitch? (Choose two.)

Select 2 answers
A.Trigger
B.Playbook
C.Destination
D.Schedule
E.Action
AnswersA, E

A trigger defines the event that initiates the automation stitch, such as an IPS log or event handler. Without a trigger, FortiManager has no condition to evaluate, so it is a required component for automatically blocking offending IP addresses.

Why this answer

An automation stitch in FortiManager requires a Trigger to define the event that initiates the stitch (e.g., an intrusion prevention event) and an Action to specify the response (e.g., blocking an IP address via a firewall address object). The Trigger monitors for specific log messages or system events, while the Action executes the configured remediation step. Without both, the stitch cannot be created or function.

Exam trap

The trap here is that candidates often confuse 'Playbook' (an optional grouping of actions) with a required component, or mistakenly think 'Destination' or 'Schedule' are needed for event-driven automation, when in fact only Trigger and Action are mandatory.

56
MCQmedium

A FortiGate has two VDOMs: 'root' and 'customer'. The admin wants to route traffic from 'customer' to the internet via 'root', which has a BGP connection to an ISP. What is the required configuration?

A.Enable VDOM forwarding on the WAN interface in 'root'
B.Configure a static route in 'customer' pointing to the 'root' VDOM's management IP
C.Place both VDOMs in the same VDOM group and enable route leak
D.Create an inter-VDOM link between 'customer' and 'root', and configure policies to allow traffic
AnswerD

An inter-VDOM link provides the Layer 3 path between 'customer' and 'root', since VDOMs have separate routing tables. Firewall policies on both VDOMs must then permit the traffic, allowing 'customer' to reach the internet via root's BGP-learned default route.

Why this answer

Inter-VDOM links are the only supported method for routing traffic between VDOMs on the same FortiGate. An inter-VDOM link creates a virtual point-to-point connection between two VDOMs, allowing traffic to flow through firewall policies. Without this link, VDOMs are isolated and cannot exchange traffic, even if static routes or BGP are configured.

Exam trap

The trap here is that candidates often assume VDOMs can route traffic to each other simply by configuring static routes or using a shared interface, but FortiGate requires a dedicated inter-VDOM link with firewall policies to enable inter-VDOM traffic.

How to eliminate wrong answers

Option A is wrong because VDOM forwarding on a WAN interface is not a feature; interfaces belong to a single VDOM and cannot forward traffic to another VDOM without an inter-VDOM link. Option B is wrong because a static route in 'customer' pointing to the 'root' VDOM's management IP would only route control traffic to the management interface, not data-plane traffic between VDOMs. Option C is wrong because VDOM groups are used for administrative grouping and configuration sharing, not for routing traffic between VDOMs; route leaking is not a supported feature between VDOMs on the same FortiGate.

57
MCQmedium

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator wants VDOM-A and VDOM-B to exchange routing information dynamically without using static routes. The administrator has already created a VDOM link named 'vlink' between the two VDOMs and assigned IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. Which additional configuration is required on each VDOM to enable OSPF adjacency over the VDOM link?

A.Create a firewall policy allowing OSPF (protocol 89) between the VDOM link interfaces.
B.Set the VDOM link interfaces to 'wan' role and enable OSPF on the physical interfaces.
C.Enable OSPF on the VDOM link interface and assign both interfaces to the same OSPF area.
D.Configure a static route on each VDOM pointing to the other VDOM's interface IP address.
AnswerC

OSPF requires that interfaces be enabled for OSPF and placed in the same area to form an adjacency. The VDOM link acts as a point-to-point connection, so configuring both ends with matching area ID and network type will allow OSPF neighbors to form. This is the standard method for dynamic routing between VDOMs.

Why this answer

To enable OSPF over a VDOM link, you must configure OSPF on the link interfaces and ensure they are in the same area. This allows the two VDOMs to form an adjacency and exchange routes dynamically. The VDOM link provides the Layer 3 connectivity, but the routing protocol configuration is what enables dynamic route exchange.

Exam trap

The trap here is assuming that creating a VDOM link automatically enables routing protocols or that a firewall policy is needed for OSPF, when in fact OSPF must be explicitly configured on the link interfaces.

58
Multi-Selecthard

Which THREE actions can an administrator perform using FortiManager in a Security Fabric environment? (Choose three.)

Select 3 answers
A.Upgrade the firmware of multiple FortiGates at once
B.View logs from all managed FortiGates in a single dashboard
C.Terminate IPsec VPN tunnels on the FortiManager
D.Configure FortiGate to manage the FortiManager
E.Push firewall policies to multiple FortiGates simultaneously
AnswersA, B, E

Firmware upgrade can be done centrally.

Why this answer

FortiManager supports centralized firmware management, allowing administrators to upgrade the firmware of multiple FortiGates simultaneously via the 'Firmware Upgrade' wizard in the Device Manager. This leverages the FortiManager's role as a central management point, which can stage and push firmware images to managed devices in a Security Fabric, reducing downtime and ensuring consistency across the fabric.

Exam trap

The trap here is that candidates confuse FortiManager's ability to configure VPN settings with the ability to terminate active tunnels, or they mistakenly think the FortiGate can manage the FortiManager (reversing the management relationship), which is a common misconception in centralized management architectures.

59
Multi-Selectmedium

A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?

Select 2 answers
A.ADOM configuration
B.Log analytics
C.Reports
D.Automation stitches
E.Policy packages
AnswersB, C

Log analytics aggregates and correlates log data from multiple FortiGates, letting the engineer build compliance reports from consolidated views. It satisfies the multi-device collection and reporting requirement directly, rather than relying on per-device raw logs.

Why this answer

Log analytics (option B) is correct because it provides the ability to search, filter, and visualize logs from multiple FortiGates, enabling the identification of trends and anomalies necessary for compliance reporting. Reports (option C) is correct because FortiAnalyzer includes a dedicated reporting engine that can generate scheduled or on-demand compliance reports based on collected logs, with pre-defined templates for standards like PCI DSS, HIPAA, and SOX.

Exam trap

The trap here is that candidates confuse FortiAnalyzer's ADOM feature (which is for administrative separation) with log collection or reporting, or they mistakenly associate automation stitches or policy packages with compliance reporting, which are actually features of FortiGate or FortiManager, not FortiAnalyzer.

60
MCQeasy

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own separate routing table. Which statement is correct?

A.All VDOMs share a single global routing table, but policies can filter routes.
B.Only the management VDOM has a routing table; other VDOMs use the management VDOM's routing table.
C.Each VDOM maintains its own independent routing table, and routes are not shared between VDOMs by default.
D.Routes are automatically synchronized between VDOMs to ensure consistent routing.
AnswerC

In multi-VDOM mode, each VDOM operates as a separate virtual firewall with its own routing table, interfaces, and policies. By default, routes are not shared between VDOMs. This isolation allows each VDOM to have independent routing decisions, which is essential for multi-tenant or segmented environments. Inter-VDOM routing must be explicitly configured if needed.

Why this answer

In a multi-VDOM FortiGate, each VDOM has its own independent routing table. Routes are not shared between VDOMs by default, ensuring isolation. This allows each VDOM to have separate routing policies and next-hop gateways.

Inter-VDOM routing must be explicitly configured using VDOM links if communication between VDOMs is required.

Exam trap

The trap here is assuming that VDOMs share a common routing table or that routes are synchronized, when in fact each VDOM maintains its own separate routing table.

61
Drag & Dropmedium

Drag and drop the steps to configure a site-to-site IPsec VPN on a FortiGate firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Phase 1 establishes the IKE SA, Phase 2 creates the IPsec SA, then routing and policies are applied to allow traffic through the tunnel.

62
Multi-Selectmedium

An administrator is deploying a FortiGate with multiple VDOMs in NAT/route mode. The administrator needs to configure inter-VDOM routing between VDOM-A and VDOM-B. Which two actions are required to enable traffic to flow between the two VDOMs? (Choose two.)

Select 2 answers
A.Configure a static route in the global routing table pointing to both VDOMs.
B.Configure firewall policies in each VDOM to allow traffic from the source to the destination through the VDOM link.
C.Enable inter-VDOM routing globally using the command 'config system global' and set 'inter-vdom-routing enable'.
D.Assign the same VDOM ID to both VDOMs to allow routing between them.
E.Create a VDOM link and assign it to both VDOM-A and VDOM-B.
AnswersB, E

Even with a VDOM link, the implicit deny policy in each VDOM blocks traffic. You must create policies in VDOM-A and VDOM-B that permit the desired traffic, specifying the VDOM link as the incoming and outgoing interface. Both directions require policies to allow bidirectional communication.

Why this answer

Inter-VDOM routing requires a VDOM link to provide the Layer 3 connection, and firewall policies in both VDOMs to permit the traffic. The VDOM link acts as a virtual cable between the two VDOMs, and each VDOM must have a policy allowing traffic from the source to the destination via that link. Without both, traffic is blocked by the implicit deny.

Exam trap

The trap here is thinking that a global setting can enable inter-VDOM routing, when in fact it requires per-VDOM VDOM links and policies.

63
Matchingmedium

Match each FortiGate routing concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manually configured route

Link-state dynamic routing protocol

Path-vector dynamic routing protocol

Routes traffic based on policy criteria

Load balancing across multiple paths

Why these pairings

Correct matches: PBR, Route redistribution, Administrative distance, and Static route are correctly paired. ECMP and Metric are swapped; ECMP distributes traffic across equal-cost paths, while Metric compares routes within a protocol.

64
MCQhard

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to multiple VDOMs to save physical ports. Which feature should they use?

A.VDOM links
B.Transparent mode
C.VLAN subinterfaces
D.Interface zones
AnswerC

VLAN subinterfaces allow a single physical interface to be logically divided into multiple VLAN interfaces, each of which can be assigned to a different VDOM. This enables sharing of a physical port across VDOMs while maintaining traffic separation. It is the standard method for this requirement.

Why this answer

VLAN subinterfaces allow a physical interface to be partitioned into multiple logical interfaces, each with its own VLAN ID. These subinterfaces can be assigned to different VDOMs, enabling the sharing of a single physical port while keeping traffic isolated. This is the correct feature for the scenario.

Exam trap

The trap here is confusing VDOM links with VLAN subinterfaces; VDOM links connect VDOMs internally, while VLAN subinterfaces connect VDOMs to external networks over a shared physical link.

65
MCQmedium

A FortiGate administrator needs to configure a policy that allows traffic from VDOM A to VDOM B using inter-VDOM routing. Which configuration is required?

A.A single policy in VDOM A with destination VDOM B
B.A static route in VDOM A pointing to VDOM B
C.Policies in both VDOMs allowing traffic to and from the inter-VDOM link
D.Disable VDOM security features
AnswerC

Inter-VDOM links terminate in both VDOMs, so each side needs a firewall policy permitting traffic across the link. Without policies in both VDOM A and VDOM B, the implicit deny drops packets, so this satisfies the bidirectional inter-VDOM routing requirement.

Why this answer

Inter-VDOM routing requires explicit policy enforcement on both sides of the inter-VDOM link. A single policy in VDOM A cannot control return traffic from VDOM B, and FortiGate does not implicitly allow traffic between VDOMs. Therefore, policies must be configured in both VDOMs to permit traffic in both directions, ensuring stateful inspection and security controls are applied consistently.

Exam trap

The trap here is that candidates assume a single policy in the source VDOM is sufficient, forgetting that FortiGate treats each VDOM as a separate virtual firewall requiring its own policy for return traffic.

How to eliminate wrong answers

Option A is wrong because a single policy in VDOM A only controls outbound traffic from VDOM A; return traffic from VDOM B would be dropped without a corresponding policy in VDOM B. Option B is wrong because static routes direct traffic but do not provide firewall policy enforcement; inter-VDOM traffic still requires explicit allow policies in both VDOMs. Option D is wrong because disabling VDOM security features would bypass all security controls, which is not a valid or secure configuration for inter-VDOM routing.

66
MCQmedium

A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?

A.They are used for NAT policies only
B.They provide default logging for all traffic
C.They apply only to the root VDOM
D.They are evaluated before other policies in the same policy package
AnswerD

Header policies sit at the top of a policy package and are evaluated before the package's other policies, letting administrators enforce global rules such as logging or blocking across all managed FortiGates without editing each individual policy.

Why this answer

Header policies in FortiManager are evaluated before any other policies in the same policy package. This allows administrators to enforce mandatory rules—such as blocking specific traffic or applying global inspection—that must be processed first, ensuring they are not bypassed by more specific policies later in the sequence.

Exam trap

The trap here is that candidates often confuse header policies with global policies or default settings, assuming they apply only to NAT or root VDOMs, when in fact they are simply policies that are evaluated first within a specific policy package.

How to eliminate wrong answers

Option A is wrong because header policies are not limited to NAT policies; they can include any firewall policy type, including security, authentication, or traffic shaping. Option B is wrong because header policies do not automatically provide default logging; logging must be explicitly configured within each policy. Option C is wrong because header policies apply to the entire policy package, not just the root VDOM; they affect all VDOMs that use that package.

67
MCQeasy

What is the purpose of a management VDOM in a multi-VDOM FortiGate?

A.To apply security profiles for all VDOMs
B.To route all inter-VDOM traffic
C.To provide a dedicated VDOM for system administration and management traffic
D.To host customer-facing services
AnswerC

A management VDOM isolates administrative traffic—HTTPS, SSH and SNMP—from production VDOMs, satisfying the requirement to separate system administration from user data forwarding. It centralises management access, letting administrators reach the FortiGate without exposing management interfaces on customer-facing VDOMs.

Why this answer

A management VDOM is a dedicated administrative VDOM that isolates system management traffic (e.g., SSH, HTTPS, SNMP, syslog) from data-plane VDOMs. This ensures that administrative access and logging remain available even if a data VDOM fails or is misconfigured, and it prevents management traffic from competing with production traffic for resources.

Exam trap

The trap here is that candidates often confuse the management VDOM with a 'super-VDOM' that controls all others, but in reality it only handles administrative traffic and has no data-plane forwarding role.

How to eliminate wrong answers

Option A is wrong because security profiles (e.g., antivirus, web filtering) are applied per VDOM or per policy, not centrally by a management VDOM; each VDOM has its own independent security policy engine. Option B is wrong because inter-VDOM traffic is routed by the VDOM link or inter-VDOM link feature, not by the management VDOM; the management VDOM does not participate in data-plane forwarding. Option D is wrong because customer-facing services (e.g., web servers, application hosting) are typically placed in a separate data VDOM, not the management VDOM, which is reserved strictly for administrative access and monitoring.

68
MCQhard

An administrator has a FortiGate with multiple VDOMs and a management VDOM enabled. The management VDOM is used for out-of-band management and logging. The administrator wants to ensure that the management VDOM can reach a syslog server on the Internet while all other VDOMs use a separate data VDOM for their Internet traffic. Which configuration is required to allow the management VDOM to use a different default route than the other VDOMs?

A.Configure a default route in the management VDOM pointing to the management gateway, and ensure that the management VDOM has its own interface with Internet connectivity.
B.Use the global routing table to define a default route that applies only to the management VDOM.
C.Enable 'allow-subnet-overlap' in the management VDOM to permit a separate default route.
D.Create a policy route in the management VDOM that forwards all traffic to the data VDOM's default gateway.
AnswerA

Each VDOM maintains its own routing table. To give the management VDOM a distinct default route, you must configure it within that VDOM. The management VDOM must also have an interface connected to the Internet or a next-hop that can reach the syslog server. This isolates management traffic from data traffic.

Why this answer

To allow the management VDOM to use a different default route, you must configure that route within the management VDOM itself. Each VDOM has its own routing table, so a default route in one VDOM does not affect others. The management VDOM also needs its own interface with Internet reachability.

This ensures management traffic uses the intended path while data VDOMs use theirs.

Exam trap

The trap here is confusing the global routing table with per-VDOM routing tables; the global table does not provide default routes for VDOM traffic.

69
MCQmedium

An administrator has a FortiGate 600E running FortiOS 7.2 with multiple VDOMs enabled. The administrator wants to create a new VDOM named 'DMZ' and assign it a specific physical interface (port3) that is currently unused. After creating the VDOM, the administrator navigates to Network > Interfaces in the DMZ VDOM but cannot see port3 in the list of available interfaces to assign. What is the most likely reason for this?

A.The interface port3 is currently used by another VDOM, so it is hidden until it is removed from that VDOM.
B.The administrator needs to reboot the FortiGate after creating the VDOM for the interface to become visible.
C.The physical interface port3 must be assigned to a VDOM from the global configuration before it appears in the VDOM's interface list.
D.The administrator must enable 'VDOM mode' on the interface before it can be seen in the VDOM.
AnswerC

In FortiOS, physical interfaces are initially in the global configuration. To make an interface available within a VDOM, the administrator must first assign it to that VDOM from the global VDOM settings (System > VDOM > select VDOM > assign interfaces). Only after assignment does the interface appear in the VDOM's Network > Interfaces list for configuration.

Why this answer

In a multi-VDOM FortiGate, physical interfaces belong to the global configuration by default. To use an interface within a VDOM, the administrator must explicitly assign it to that VDOM from the global VDOM settings. Until that assignment is made, the interface will not be listed in the VDOM's Network > Interfaces section, preventing configuration.

Exam trap

The trap here is assuming that any unused physical interface is automatically available in all VDOMs, when in fact it must be explicitly assigned from the global configuration.

70
MCQmedium

In FortiManager, an administrator wants to apply a set of firewall policies to multiple FortiGates in different ADOMs. The policies must be centrally managed. What is the best approach?

A.Use the Global ADOM to define global policies that apply to all ADOMs
B.Create a policy package in each ADOM and use the same policies
C.Configure the policies directly on each FortiGate
D.Use automation stitches to copy policies between ADOMs
AnswerA

Global ADOM policies are inherited by all ADOMs, providing central management.

Why this answer

The Global ADOM in FortiManager allows administrators to define firewall policies that are automatically inherited by all ADOMs, ensuring consistent, centrally managed policy enforcement across multiple FortiGates without manual duplication. This approach leverages FortiManager's hierarchical policy model, where global policies are pushed to each ADOM's policy packages and take precedence over local policies unless overridden.

Exam trap

The trap here is that candidates often confuse the Global ADOM with a simple 'global policy' feature, not realizing it is a dedicated administrative domain with its own policy database and inheritance rules, leading them to choose option B (manual duplication) or D (automation stitches) as workarounds.

How to eliminate wrong answers

Option B is wrong because creating a policy package in each ADOM with the same policies duplicates configuration effort and defeats centralized management, as each ADOM's policies must be individually maintained and pushed. Option C is wrong because configuring policies directly on each FortiGate bypasses FortiManager's centralized control, leading to configuration drift and no single source of truth. Option D is wrong because automation stitches are designed for event-triggered actions (e.g., dynamic responses), not for replicating static policy sets between ADOMs, and they lack the inheritance and revision control of Global ADOM policies.

71
Multi-Selecthard

An administrator wants to ensure that traffic between two VDOMs on the same FortiGate is properly inspected. Which THREE configurations must be in place?

Select 3 answers
A.Inspection profiles applied to the policies
B.Enable SSL inspection on the inter-VDOM link interface
C.A firewall policy in each VDOM permitting traffic across the link
D.An inter-VDOM link between the VDOMs
E.Static routes on both VDOMs pointing to the inter-VDOM link
AnswersA, C, D

Security profiles must be attached to the inter-VDOM firewall policies, since inspection only occurs where a policy references the relevant profile. Without this binding, traffic crossing the link is permitted but not scanned, so the inspection requirement in the stem is unmet.

Why this answer

Option D is correct because an inter-VDOM link is the virtual interface pair that provides the actual data path between two VDOMs on the same FortiGate; without it, no traffic can pass between the VDOMs. Option C is correct because each VDOM requires its own firewall policy that permits traffic to traverse the inter-VDOM link, since policies are evaluated per-VDOM and a policy in one VDOM does not automatically apply to the other. Option A is correct because inspection profiles (such as antivirus, IPS, web filter, or application control) must be attached to those inter-VDOM policies for the traffic to actually be inspected rather than merely permitted.

Option B is not required because SSL inspection is a profile-level setting applied through a firewall policy, not a property enabled on the inter-VDOM link interface itself. Option E is not required because the inter-VDOM link is directly connected and its subnets are known to each VDOM, so static routes pointing to the link are unnecessary for basic inter-VDOM traffic.

Exam trap

The trap here is that candidates often assume SSL inspection must be enabled on the inter-VDOM link interface itself, but FortiGate requires SSL inspection to be configured as part of the inspection profile applied to the firewall policy, not on the interface.

72
MCQhard

An administrator configures FortiAnalyzer to receive logs from multiple FortiGates. They want to create a report that shows only incidents involving 'critical' severity and specific attack types. Which FortiAnalyzer feature allows the administrator to define such a custom report?

A.Incident management
B.Playbooks
C.FortiView dashboards
D.Report datasets and charts
AnswerD

Report datasets and charts let you write SQL queries against the log database, filtering on severity level and attack type before the chart renders. This satisfies the stem's constraint of restricting output to critical-severity incidents of specific attack types, which predefined report templates cannot isolate.

Why this answer

FortiAnalyzer's reporting engine uses datasets and charts to define custom reports. Datasets are SQL-like queries that extract specific log data, and charts visualize that data. By creating a dataset that filters for 'critical' severity and specific attack types, and then adding it to a report, the administrator can generate the desired custom report.

Other features like incident management, playbooks, and FortiView dashboards are for real-time monitoring and automated response, not custom report generation.

Exam trap

NSE7 often tests the distinction between reporting and monitoring features, so candidates might choose FortiView dashboards because they show similar data, but they are not for custom report creation.

How to eliminate wrong answers

Option A is wrong because incident management is used for tracking and managing security incidents, not for creating custom reports with specific filters. Option B is wrong because playbooks are automated workflows that respond to events, not reporting tools. Option C is wrong because FortiView dashboards provide real-time visualization of log data, but they are not used to create scheduled or custom reports with specific severity and attack type filters.

73
MCQmedium

An administrator is troubleshooting a scenario where FortiAnalyzer is not receiving logs from a FortiGate. The FortiGate shows 'log-fortianalyzer setting status: disconnected'. Which step should be taken first to resolve this?

A.Check the FortiGate's DNS resolution for the FortiAnalyzer hostname
B.Verify that the FortiGate can reach the FortiAnalyzer IP address and that the FortiAnalyzer service is running
C.Restart the FortiGate's logging service
D.Disable and re-enable logging to FortiAnalyzer
AnswerB

Connectivity is the most basic check; ping and service status should be verified first.

Why this answer

The 'disconnected' status indicates that the FortiGate cannot establish a TCP connection to the FortiAnalyzer. The first step is to verify basic Layer 3 reachability (ping) and that the FortiAnalyzer service is listening on the default port (TCP 514 or 3000 for encrypted). Without confirming these, further troubleshooting is premature.

Exam trap

The trap here is that candidates often jump to reconfiguring logging or restarting services (options C or D) without first verifying the most fundamental Layer 3 connectivity and service availability, which is the logical starting point for any 'disconnected' status.

How to eliminate wrong answers

Option A is wrong because DNS resolution is only relevant if the FortiGate is configured to use a hostname instead of an IP address; the status 'disconnected' points to a connectivity or service issue, not name resolution. Option C is wrong because restarting the FortiGate's logging service does not address underlying network or server-side problems; it only restarts the local logging daemon. Option D is wrong because disabling and re-enabling logging to FortiAnalyzer merely toggles the configuration without fixing the root cause of the disconnection; it is a reactive step that should be taken only after connectivity and service status are confirmed.

74
Multi-Selectmedium

An administrator is configuring a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that traffic between VDOMs is inspected by firewall policies. Which TWO statements about inter-VDOM routing are correct? (Choose two.)

Select 2 answers
A.Inter-VDOM links require the use of 802.1Q VLAN tagging to differentiate traffic.
B.Inter-VDOM links are virtual interfaces that must be created in pairs, with each end assigned to a different VDOM.
C.Traffic traversing an inter-VDOM link is subject to firewall policies and UTM inspection.
D.Inter-VDOM links can be configured in transparent mode VDOMs without IP addresses.
E.A single inter-VDOM link can connect more than two VDOMs simultaneously.
AnswersB, C

Inter-VDOM links are indeed virtual interfaces created in pairs. One end is assigned to one VDOM and the other end to another VDOM, providing a point-to-point connection. This design allows each VDOM to maintain its own routing table while enabling traffic to pass between them under policy control.

Why this answer

Inter-VDOM links are virtual point-to-point interfaces that connect two VDOMs, allowing each VDOM to have its own routing table. Traffic across these links is inspected by firewall policies and can have UTM profiles applied. They do not use VLAN tagging and are not used in transparent mode VDOMs.

These characteristics make them suitable for secure inter-VDOM communication.

Exam trap

The trap here is assuming that inter-VDOM links are like VLANs or can connect multiple VDOMs at once; they are strictly point-to-point and do not use tagging.

75
Multi-Selecthard

A company has a FortiGate with multiple VDOMs. The security team wants to use FortiManager to manage policies centrally. Which three steps are necessary to set up VDOM management via FortiManager? (Choose three.)

Select 3 answers
A.Enable VDOMs on the FortiGate and configure them for FortiManager management
B.Configure a static route on FortiManager to reach the FortiGate's management IP
C.Disable VDOM configuration locking on FortiManager
D.Add the FortiGate to FortiManager and assign it an appropriate ADOM
E.Ensure the FortiGate can reach the FortiManager server (network connectivity)
AnswersA, D, E

VDOMs must be enabled and each VDOM's management must be set to FortiManager.

Why this answer

VDOMs must be enabled on the FortiGate and each VDOM must be configured to allow FortiManager management. This is done by setting the 'set vdom mgmt' parameter within each VDOM or globally, which permits FortiManager to push policy and object changes to the specific VDOM context. Without this step, FortiManager cannot authenticate or communicate with the VDOMs, even if the device is added to the ADOM.

Exam trap

The trap here is that candidates often assume FortiManager needs a static route to the FortiGate, but in reality the FortiGate must initiate the FGFM tunnel, so network connectivity must be from the FortiGate to FortiManager, not the other way around.

Page 1 of 3 · 186 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Enterprise Firewall and VDOMs questions.