NSE7 · domain
scenario questions
Practise Fortinet NSE 7 Advanced Security NSE7 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (718)
Click any question to see the full explanation, or start a practice session above.
A FortiGate is configured with multiple VDOMs. The administrator wants to assign a specific physical interface to a non-management VDOM and ensure that the interface is not visible or configurable from other VDOMs. The interface is currently assigned to the root VDOM. What is the correct procedure to reassign the interface to VDOM-1?
Hard2An administrator is troubleshooting why a FortiGate is not applying the expected application control profile to traffic from a specific subnet. The administrator wants to verify which application signature is matching a live session in real time. Which CLI command should be used to display the application name and category for active sessions?
Medium3What is the purpose of BFD (Bidirectional Forwarding Detection) in a FortiGate routing configuration?
Easy4An administrator wants to use a FortiGate to manage FortiSwitch units via the LAN. Which interface configuration is required on the FortiGate to allow this management?
Easy5Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?
Easy6An administrator needs to monitor traffic flows across multiple FortiGate devices in a Security Fabric. The administrator wants to see a unified view of all traffic, including inter-device traffic, from a single pane. Which Fortinet tool provides this capability?
Easy7A FortiGate administrator is deploying ZTNA to provide access to internal applications for remote users. The administrator wants to ensure that users can only access the specific applications they are authorized for, and that the ZTNA access proxy performs authentication and authorization before forwarding traffic. Which FortiGate component must be configured to define the protected applications and the authentication rules for ZTNA access?
Medium8A FortiGate in HA active-passive mode has two VDOMs. VDOM-1 is configured for management (management VDOM). The administrator connects to the management VDOM IP to manage the device. What is a characteristic of the management VDOM?
Medium9A FortiGate is configured to send logs to FortiAnalyzer. The administrator notices that logs are not appearing on FortiAnalyzer. Running 'diagnose log device show' shows 'connected=no'. What is the most likely cause?
Medium10Which TWO of the following are required components for a Fortinet ZTNA solution? (Select two.)
Medium11An admin creates a VDOM named 'CustomerA' with inter-VDOM link to the management VDOM. The admin wants CustomerA administrators to manage only their own VDOM. Which configuration step is required?
Hard12What is the primary function of FortiAnalyzer's FortiView feature?
Easy13An organization uses FortiAnalyzer for centralized logging. The security team wants to use playbooks to automate responses to detected incidents. Which THREE components are essential for a playbook to function?
Hard14A FortiGate administrator needs to integrate with FortiNAC to enforce network access control for wired and wireless devices. The administrator wants FortiNAC to dynamically assign VLANs based on the device's security posture. Which FortiNAC feature enables this?
Medium15An administrator is troubleshooting an SD-WAN scenario where traffic from a branch office to a critical SaaS application is experiencing high latency. The SD-WAN rule uses the best quality SLA strategy. The administrator runs 'diagnose sys sdwan neighbor' and sees that both WAN links have SLA compliance above 90%. However, traffic still uses the slower link. The administrator then runs 'diagnose sys sdwan health-check list' and notices that the health-check server IP is different from the SaaS application's server IP. What is the MOST likely reason the traffic is not using the best-performing link?
Hard16Which FortiClient ATP feature provides protection against zero-day malware by monitoring process behavior and blocking suspicious activities at the endpoint?
Easy17An administrator configures a new ADOM in FortiManager for a set of FortiGates. The administrator wants to assign meta fields to devices in this ADOM. Where should the meta fields be defined?
Medium18A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)
Medium19A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?
Hard20A FortiGate admin configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The admin wants traffic from VDOM-A to reach a server in VDOM-B. Which three configuration steps are required? (Choose three.)
Hard21An administrator wants to use FortiExtender to provide LTE WAN connectivity. After connecting the FortiExtender to the FortiGate, the LTE interface is not showing up. What is the first troubleshooting step?
Medium22A network administrator runs 'get system ha status' on a FortiGate HA cluster and sees that only one unit shows as primary. The secondary unit shows as 'standalone' with no HA peer detected. What is the MOST likely cause of this issue?
Easy23An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is accessed via HTTPS. Which component must be configured on the FortiGate to act as a reverse proxy for the application?
Easy24An administrator configures BGP route advertisement but the routes are not being sent to the neighbor. The BGP session is established. What is the MOST likely cause?
Medium25An administrator is troubleshooting high CPU usage on a FortiGate. The administrator suspects that a specific process is causing the issue. Which TWO commands should the administrator use to identify the top CPU-consuming processes? (Choose two.)
Medium26A network administrator wants to delegate management of a specific VDOM to a junior administrator. The junior should be able to modify firewall policies and objects within that VDOM but not change system settings or other VDOMs. Which administrative access configuration meets this requirement?
Easy27A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)
Hard28What is the purpose of FortiAnalyzer in a Fortinet security fabric?
Easy29An administrator configures a FortiGate with VDOMs and notices that the 'config vdom' command lists multiple VDOMs, but only one VDOM is shown in the 'show full-configuration' output. What is the most likely reason?
Medium30An administrator is troubleshooting an SD-WAN setup where a specific application's traffic is not being steered according to the configured SD-WAN rule. The rule uses a performance SLA and the 'lowest-cost' strategy. The administrator runs 'diagnose sys sdwan health-check' and sees that both members are alive and meeting the SLA. However, traffic still goes over the higher-cost member. What is the most likely cause?
Hard31A network admin configures OSPF on a FortiGate with multiple areas, including one area that is not directly connected to the backbone (Area 0). To ensure that routes from that area are advertised into other areas, which OSPF feature must be properly configured?
Medium32An administrator needs to monitor the FortiGate's CPU usage in real-time from the CLI. Which command should be used?
Easy33Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?
Easy34Which SD-WAN load balancing algorithm is best for ensuring that all traffic from a specific source-destination pair uses the same WAN link?
Easy35An administrator wants to group firewall objects by department (e.g., Sales, Engineering) and easily filter them in FortiManager policy packages. Which feature should be used?
Medium36An administrator wants to enforce that only devices with antivirus software installed and up-to-date can access the corporate network. Which FortiGate feature should be used?
Easy37An administrator needs to verify if a FortiGate is receiving BGP routes from a peer. Which command should the admin run to see the BGP routing table?
Easy38An administrator wants to integrate FortiGate with an external threat intelligence feed to block known malicious IP addresses automatically. Which object should be used to consume the feed?
Medium39A FortiGate is configured with multiple virtual routers (VRFs). The administrator wants to allow communication between two VRFs using a firewall policy. Which type of interface is required for the policy?
Easy40Which FortiManager feature allows an administrator to view the exact CLI commands that will be pushed to a managed FortiGate before installation?
Easy41A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGate devices. The tunnel is established, but traffic is not passing. Which configuration should the administrator check first?
Medium42In a FortiManager deployment with global ADOM enabled, an administrator creates a firewall policy in the global ADOM. What is the effect of this policy on the per-ADOM devices?
Hard43An administrator is troubleshooting why a new firewall policy on a managed FortiGate is not taking effect. The policy was created in FortiManager and installed successfully. Which TWO steps should the administrator verify to identify the issue? (Select TWO.)
Medium44An admin wants to create a custom IPS signature to detect a specific exploit that sends a string 'EXPLOIT' in the HTTP Host header. Which signature syntax is correct?
Medium45A security team is configuring FortiMail for email security. They want to ensure that incoming emails are authenticated using SPF, DKIM, and DMARC, and that emails failing authentication are quarantined. Which THREE settings must be configured in FortiMail? (Choose three.)
Hard46An administrator is troubleshooting a ZTNA issue where users are able to authenticate but the application access is still blocked. The ZTNA status on FortiClient shows 'Connected' but the application does not load. What is the MOST likely cause?
Hard47A multi-area OSPF network includes a FortiGate as an ABR. The administrator needs to redistribute a static route into OSPF. Which command is required on the FortiGate to achieve this?
Medium48An administrator sees the following log entry: 'id=13593 msg="CDR: File attachment sanitized"' Which feature generated this log?
Medium49An administrator wants to integrate a FortiExtender with a FortiGate to provide cellular WAN connectivity. Which configuration step is required on the FortiGate to use the FortiExtender as an SD-WAN member?
Medium50An administrator has a FortiGate with multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 are connected via an inter-VDOM link. The administrator wants to apply security profiles to traffic passing between the VDOMs. However, when checking the policy list in VDOM-1, no policy is shown for traffic destined to VDOM-2. What is the most likely reason?
Hard51A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM so that it can be used for that VDOM's traffic. Which configuration step is required?
Medium52An administrator is deploying a FortiGate in multi-VDOM mode for a managed services provider. Each customer must have an isolated logical firewall with its own interfaces, policies, and administrators, and the provider wants to limit each customer administrator to only their own VDOM. Which configuration accomplishes this?
Easy53An administrator has a FortiGate in multi-VDOM mode. VDOM-1 is assigned to the marketing team and VDOM-2 to the finance team. The administrator wants both VDOMs to be able to reach a shared DNS server at 10.10.10.53 that sits behind the root VDOM's wan1 interface, without giving either team access to the other's traffic. Which configuration accomplishes this?
Medium54Which load balancing algorithm in SD-WAN distributes new sessions based on the source and destination IP addresses, ensuring that all sessions from a given source-destination pair go to the same member?
Easy55In FortiAnalyzer, which tool provides real-time traffic monitoring and allows drilling down into details such as top talkers, applications, and threats?
Easy56A FortiGate administrator is deploying ZTNA to protect an internal application. Users connect with FortiClient, which establishes a tunnel to the FortiGate. The administrator wants the FortiGate to verify the user's identity and device posture before allowing access to the application. Which FortiGate feature performs this verification as part of the ZTNA access proxy?
Easy57An administrator is deploying ZTNA with FortiClient EMS to secure access to a corporate web application. Which THREE components are required for a successful ZTNA deployment? (Choose three.)
Medium58A FortiGate has an IPsec VPN with a remote peer that uses IKEv2. The administrator wants to ensure that child SA rekeying uses PFS (Perfect Forward Secrecy) with Diffie-Hellman group 14. Which CLI command should the administrator configure on the FortiGate's phase 2 proposal?
Hard59A FortiGate is configured with an IPsec VPN that uses certificate-based authentication. The VPN fails to establish. The administrator checks the phase1 debug and sees the message: 'no suitable certificate found'. What is the most likely cause?
Hard60A FortiGate administrator is investigating a slow network performance issue. The administrator suspects that session table limits are being reached. Which TWO metrics should be monitored to confirm this? (Choose two.)
Hard61A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?
Easy62A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?
Hard63A network administrator wants to block known malicious IP addresses using threat intelligence feeds on FortiGate. Which feature should they use?
Easy64An administrator is troubleshooting an IPsec VPN tunnel that establishes phase 1 but fails to establish phase 2. The phase 2 configuration shows 'set proposal aes128-sha256' on both sides. Which TWO configuration items should the administrator verify?
Medium65A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?
Hard66A FortiGate administrator wants to monitor performance thresholds to be alerted when the firewall is under heavy load. Which THREE metrics can be monitored using the built-in performance monitoring features (e.g., 'diagnose sys top' or SNMP)?
Easy67An administrator is troubleshooting an IPsec VPN Phase 2 negotiation failure. The debug shows 'no matching phase 2 proposal' from the remote peer. Which TWO of the following are likely causes? (Choose two.)
Hard68What is the purpose of BFD on a FortiGate?
Easy69An administrator needs to isolate customer traffic in a FortiGate deployed at a service provider. Each customer should have independent administrators and security policies. Which feature should be used?
Easy70A FortiGate admin configures an automation stitch to send an email alert when a high-severity IPS event occurs. The trigger is 'IPS Event' and the action is 'Email'. After testing, no email is sent despite events being logged. What is the most likely cause?
Medium71A network administrator is troubleshooting a split-brain scenario in an HA cluster. Which TWO conditions can cause split-brain? (Choose two.)
Medium72An administrator manages a FortiGate 500E with multiple VDOMs. The administrator needs to configure a new VDOM named 'Partner' and ensure that the Partner VDOM can use a dedicated physical interface for WAN connectivity. The FortiGate has an unused interface 'port5'. The administrator wants to assign port5 to the Partner VDOM and configure it with an IP address. Which sequence of steps is correct?
Hard73Drag and drop the steps to configure a FortiGate to send logs to a FortiAnalyzer into the correct order.
Medium74A FortiGate administrator is troubleshooting a ZTNA problem where users are unable to connect to an internal application via FortiClient. FortiClient reports 'Connection refused'. The FortiGate ZTNA gateway is configured correctly. Which THREE steps should the administrator take to diagnose the issue?
Hard75An administrator wants to load balance traffic across two WAN links by session count. Which SD-WAN load balancing algorithm should they use?
Easy76An admin is troubleshooting an IPsec VPN tunnel that is failing phase 2. The IKE debug shows 'no matching proposal'. Which TWO settings should the admin verify on both sides? (Choose two.)
Medium77An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?
Medium78Match each Fortinet component to its description.
Medium79A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?
Hard80A company has deployed two FortiGate-600Es in an active-passive HA cluster. The cluster is configured with three VDOMs: VDOM-A (corporate LAN), VDOM-B (guest Wi-Fi), and VDOM-C (DMZ). Each VDOM has its own set of interfaces and policies. The cluster is also configured to use FGCP with session pickup enabled. Recently, the network team noticed that after a failover event, some user sessions in VDOM-B are not being picked up, causing disruption for guest users. The session pickup feature is enabled globally. The administrator checks the configuration and finds the following settings on the primary FortiGate: - config system ha set session-pickup enable set session-pickup-connectionless enable end - config vdom edit VDOM-A config system ha set session-pickup enable end next edit VDOM-B config system ha set session-pickup disable end next edit VDOM-C config system ha set session-pickup enable end next Based on this configuration, what is the most likely reason that sessions in VDOM-B are not being picked up?
Hard81An administrator is reviewing the HA configuration shown in the exhibit. The primary unit has failed, and the secondary unit (with priority 100) has taken over. However, the administrator notices that the secondary unit has an IP address of 10.10.10.2 on port3, but cannot ping the management gateway 10.10.10.1. What is the most likely cause?
Easy82A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)
Hard83An administrator is configuring an SD-WAN rule on a FortiGate. They want to load balance traffic across three WAN links based on the volume of traffic sent. Which load balancing algorithm should they use?
Easy84A FortiGate administrator is troubleshooting a VPN tunnel that connects to a remote site. The tunnel is up, but traffic is not passing. The administrator checks the Phase 2 settings and sees that the local and remote subnets are correctly defined. What is the next step to diagnose the issue?
Medium85An organization wants to implement multiple layers of defense against advanced persistent threats. Which three Fortinet solutions would be most effective in an ATP strategy? (Choose three.)
Medium86An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM and ensure that the interface is dedicated to that VDOM only. Which action should the administrator take?
Easy87A network administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The remote gateway logs show a proposal mismatch. On FortiGate, the administrator runs 'diagnose vpn ike config' and sees 'proposal: aes128-sha1, aes256-sha256'. The remote side expects 'aes256-sha1'. What is the most likely cause?
Medium88A FortiGate running FortiOS 7.2 has multiple VDOMs. The administrator notices that inter-VDOM routing between two VDOMs is not working. Configuration shows a firewall policy allowing the traffic, and the route table shows routes to the destination VDOM. What additional configuration is required?
Hard89An administrator wants to monitor the session count on a FortiGate in real time. Which CLI command provides this information?
Easy90A security analyst is reviewing alerts from FortiEDR and wants to automatically isolate an infected endpoint from the network when a malicious process is detected. Which FortiEDR feature should the analyst configure to achieve this?
Easy91A FortiGate administrator configures a VDOM with a limit on the number of firewall policies. The VDOM has 200 policies, and the limit is set to 250. The administrator attempts to add a new policy but receives an error indicating the limit has been reached. What is the MOST likely reason?
Hard92A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?
Hard93A FortiGate has multiple VRFs configured. An administrator wants to allow traffic from VRF 1 to reach a server in VRF 2. What configuration is required?
Medium94A FortiGate HA cluster is configured with two units in active-passive mode. The administrator needs to perform a firmware upgrade on the cluster with minimal downtime. The current firmware version is 7.2.5 and the target is 7.2.7. The cluster uses FGCP with session synchronization enabled. Which procedure should the administrator follow?
Hard95A FortiGate is the hub of an IPsec VPN and also terminates SSL VPN for remote users. The administrator wants remote users to access internal resources only after the FortiGate validates the endpoint's compliance through FortiClient EMS, and wants the validation to happen before the user is placed in a VPN address pool. Which SSL VPN configuration element enforces endpoint compliance during the connection handshake?
Hard96A FortiGate administrator has enabled FortiGuard Outbreak Prevention and selects the 'Use Outbreak Prevention Database' option. After a new outbreak is detected, the administrator verifies that the IPS signature is applied to all applicable policies. However, the administrator wants to ensure that the FortiGate dynamically updates its protection without requiring a full IPS engine update. Which FortiGuard service must be reachable for the FortiGate to receive outbreak prevention updates?
Medium97An administrator applies the above policy but users from 10.0.1.0/24 cannot access web servers at 10.0.2.0/24. However, they can ping the servers. What is the most likely cause?
Easy98A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?
Hard99A FortiGate administrator is deploying ZTNA to provide secure access to internal web applications. The administrator wants to ensure that only devices with up-to-date antivirus signatures are granted access. Which FortiGate component should be used to enforce this requirement?
Hard100A network administrator wants to logically separate two departments on a single FortiGate. Each department must have its own firewall policies, routing table, and administrators. Which feature should be used?
Easy101An administrator is investigating a security incident and needs to view raw logs from a FortiAnalyzer for a specific time range. The administrator wants to ensure the logs are not aggregated or summarized. Which type of log view should be used?
Hard102An administrator is deploying a FortiGate with multiple VDOMs in NAT mode. The administrator wants to ensure that traffic between VDOMs is inspected by security profiles and that inter-VDOM traffic does not bypass the firewall policy engine. Which configuration is required to achieve this?
Medium103An administrator runs 'diagnose sys session filter dport 443' and sees: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
Medium104An administrator configures a multi-VDOM FortiGate in transparent mode. The admin notices that the management IP is reachable from both interfaces, but traffic passing through the device is not being inspected. What is the likely issue?
Hard105An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The default route in VDOM-A points to a next-hop router, and VDOM-B has a static route to a subnet behind VDOM-A. Users in VDOM-B cannot reach that subnet. The administrator runs 'diagnose ip route list' in both VDOMs and sees the routes are present. What is the most likely cause?
Hard106A FortiGate has multiple equal-cost routes to the same destination via two different interfaces. ECMP load balancing is enabled. What determines how traffic is distributed among the routes?
Medium107A network administrator configures an SD-WAN zone with two members (port1 and port2) and sets the load balancing algorithm to 'spillover'. The spillover threshold is set to 100 Mbps on port1. If traffic reaches 120 Mbps on port1, what happens to new sessions?
Medium108A FortiGate is configured with an antivirus profile that has the machine learning engine enabled. An administrator notices that some files are being detected by the ML engine but the verdict is 'probably clean'. What does this verdict indicate?
Hard109Which FortiGate feature allows an administrator to define a granular policy based on the security posture of the endpoint device, such as OS version, antivirus status, and disk encryption, before granting access to a protected application?
Easy110An administrator configures automation stitches on FortiManager to trigger a script when a specific event log is received. The script should block the source IP on the firewall. However, the script does not run when the event occurs. What is a likely cause?
Hard111A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?
Easy112A FortiGate administrator notices that traffic classified as 'unknown' by the antivirus is being allowed. The administrator wants to ensure that such files are submitted to FortiSandbox for analysis and blocked until a verdict is received. Which configuration is required?
Medium113What does FortiGuard Outbreak Prevention use to protect against newly discovered malware outbreaks before traditional signatures are available?
Easy114An administrator is troubleshooting an HA cluster (active-passive) where both units show 'primary' in 'get system ha status'. The cluster is not synchronizing configurations. What is the MOST likely cause?
Hard115A FortiGate is configured as a hub in an ADVPN with multiple spokes. The administrator notices that some spokes are not learning routes from other spokes, even though the ADVPN tunnel is up. The hub is using BGP for routing. Which configuration on the hub is required to enable spoke-to-spoke route propagation?
Hard116What is the purpose of header and footer policies in a FortiManager policy package?
Easy117What is the primary purpose of an administrative VDOM on a FortiGate?
Easy118An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that a specific VDOM can use more system resources, such as sessions and CPU, than other VDOMs. Which FortiGate feature should the administrator use?
Easy119Which FortiAnalyzer feature allows administrators to create automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected?
Easy120What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?
Easy121An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?
Medium122An administrator wants to ensure that voice traffic (UDP 16384-32768) always uses the MPLS link, while internet-bound traffic uses broadband. Which SD-WAN feature should be configured to achieve this?
Easy123A FortiGate 600E is running in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator assigns physical port3 to VDOM-1 as a dedicated interface, then creates a VLAN subinterface (VLAN 100) on port3 for VDOM-2. After configuration, VLAN 100 traffic is dropped even though the VLAN interface is up. Which action resolves the issue?
Medium124A FortiGate VPN tunnel shows 'phase1 negotiation failed' in the logs. The remote gateway is a third-party device. The debug command 'diagnose vpn ike config' shows mismatched proposals. Which setting is MOST likely incorrect on the FortiGate?
Medium125An administrator is configuring a FortiGate for SD-WAN and wants to ensure that outgoing traffic from the internal network is distributed across two WAN links based on the number of active sessions. Which SD-WAN load balancing algorithm should be used?
Easy126A FortiGate administrator wants to use BFD to quickly detect link failures in an SD-WAN deployment. Which statement about BFD configuration on FortiGate is correct?
Easy127A FortiGate administrator needs to verify that the firewall is correctly identifying and logging a specific application, 'Facebook', that is being used by internal users. The administrator has already configured an application control profile with logging enabled for Facebook. Which CLI command should the administrator use to view the application control logs in real-time?
Easy128An enterprise FortiGate has multiple VDOMs. The administrator wants to allow traffic from VDOM A to reach servers in VDOM B without traversing an external router. Which configuration is required?
Medium129A FortiGate administrator is troubleshooting high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which action should the administrator take to reduce the CPU usage while maintaining security?
Medium130A company has two internet connections: a primary fiber link (port1, 100 Mbps) and a backup DSL link (port2, 20 Mbps). They are using SD-WAN to load balance traffic based on volume, with a rule that sends 70% of traffic to port1 and 30% to port2. Recently, users report that video conferencing applications are experiencing high latency and jitter. The network team finds that the SD-WAN performance SLA for the fiber link shows 80% packet loss and high latency. The SD-WAN rule action is set to 'best quality' with a latency threshold of 150 ms. The current latency on port1 is 200 ms, and on port2 is 40 ms. What should the administrator do to ensure that video conferencing traffic uses the DSL link while the fiber link is degraded?
Easy131Which FortiGate command is used to view the current CPU usage of individual processes in real time?
Easy132Drag and drop the steps to configure a FortiGate VDOM in multi-VDOM mode into the correct order.
Medium133A FortiGate is configured with a WAF profile to protect a web server. The administrator notices that SQL injection attacks are still reaching the server despite the WAF being enabled. What is the MOST likely reason?
Medium134A FortiGate running FortiOS 7.4.1 has two VDOMs: CustomerA and CustomerB. The administrator wants CustomerA to access an HTTP server in CustomerB. Both VDOMs have appropriate policies. What additional configuration is required?
Medium135A FortiGate administrator is troubleshooting a ZTNA access proxy rule that is not matching traffic from a specific user group. The rule is configured with a source of 'ZTNA_Users' and a destination of the internal web server. The administrator confirms that the user is authenticated and has the correct EMS tag. Which FortiGate CLI command should the administrator use to verify that the ZTNA rule is being evaluated correctly?
Hard136A FortiGate administrator needs to identify which process is consuming the most memory. Which command should be used?
Easy137An administrator is troubleshooting a BGP session that is not establishing between two FortiGates. The administrator has verified that the neighbor IP is reachable. Which TWO commands should be used to further diagnose the issue? (Choose two.)
Medium138A FortiGate administrator wants to prevent users from accessing a list of known malicious domains. The list is updated daily by a third-party provider and available as a plain text file over HTTPS. Which FortiGate feature should be used to ingest and block these domains?
Easy139A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?
Hard140An organization has multiple ADOMs in FortiManager. The admin wants to share a set of firewall objects across all ADOMs. What is the best approach?
Hard141A FortiGate administrator wants to use FortiAnalyzer to view traffic logs from multiple VDOMs. Which TWO steps must the administrator perform on FortiAnalyzer?
Easy142A security administrator wants to block email spoofing attacks against their organization's domain. They configure SPF, DKIM, and DMARC records. Which protocol authenticates the domain of the email sender by verifying the email's signature against a public key published in DNS?
Medium143An enterprise FortiGate has multiple VDOMs. The security policy requires that all traffic between VDOMs must be inspected by a next-generation firewall profile. Which three steps are necessary to achieve this? (Choose three.)
Medium144Which feature on FortiGate uses machine learning to detect never-before-seen malware based on file characteristics?
Easy145A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?
Medium146A FortiGate administrator is troubleshooting an issue where users are unable to access a web server behind the FortiGate. The web server is on the DMZ network, and users are on the internal network. The firewall policy from internal to DMZ is configured to allow HTTP and HTTPS. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which two actions should the administrator take to resolve this issue? (Choose two.)
Medium147An administrator configures FortiSandbox inline scanning for HTTP traffic. They notice that files uploaded via HTTP are being scanned but no verdict is being returned, causing delays. What is the MOST likely cause?
Medium148An administrator has configured two VDOMs on a FortiGate. One VDOM is in NAT mode and the other in transparent mode. The administrator wants traffic from the transparent mode VDOM to be routed through the NAT mode VDOM. What must be configured to allow inter-VDOM routing?
Hard149An administrator is configuring an SD-WAN rule to route traffic to a specific destination through a preferred member, but wants to ensure that if that member fails, traffic automatically switches to another member. Which SD-WAN rule configuration setting should they use to define the order of member preference?
Easy150A FortiGate in transparent mode is deployed between a router and a switch. The administrator needs to apply a deep inspection profile to HTTP traffic. What is the correct configuration for the interfaces?
Hard151A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees the tunnel state as 'connecting' but no phase2 selectors are listed. Which step should the administrator take next to identify the issue?
Medium152A FortiGate is configured with an SD-WAN rule using 'spillover' algorithm. The primary member has a spillover threshold of 100 Mbps. Traffic of 80 Mbps is currently flowing through the primary member. A new session requiring 30 Mbps arrives. What will happen?
Hard153A FortiGate administrator is configuring a security profile group and wants to enable inline blocking of malicious files based on FortiGuard cloud threat intelligence, without sending files to FortiSandbox. The administrator has already enabled the antivirus profile and selected the 'Block' action for infected files. Which additional setting should be configured to ensure that files identified as malicious by the FortiGuard service are blocked in real time?
Medium154A FortiGate administrator has configured a ZTNA access proxy for an internal web application and wants to enforce device compliance before allowing access. The administrator has integrated FortiClient EMS and created ZTNA tags for compliant devices. Users with compliant devices are still being denied access. The firewall policy references the ZTNA server and the tag. What should the administrator verify first?
Medium155A FortiGate administrator is configuring ZTNA to provide access to an internal web application. The administrator wants to ensure that only devices with a specific security posture tag are allowed access. The ZTNA rule is configured with a policy that references a device group synced from FortiClient EMS. However, when a user attempts to access the application, the connection is denied even though the device has the correct tag. What is the most likely cause?
Hard156A FortiGate has multiple VDOMs. The administrator notices that traffic from VDOM-1 to VDOM-2 is allowed by inter-VDOM policies but is not being inspected by the security profiles. What is the most likely cause?
Medium157An administrator wants to use FortiAnalyzer to generate weekly compliance reports for all managed FortiGates. Which FortiAnalyzer feature should be used?
Easy158A FortiGate administrator wants to enable load balancing for equal-cost paths to the same destination. The FortiGate has two equal-cost routes via two different next-hop routers. Which feature should the admin enable to load balance traffic across both paths?
Easy159A network administrator is setting up an IPsec VPN between two FortiGates. The administrator wants to ensure that if the VPN tunnel goes down, the FortiGate can automatically re-establish it without manual intervention. Which IPsec feature should the administrator enable to detect peer failures and trigger tunnel renegotiation?
Easy160An administrator needs to configure advanced email security on FortiMail to protect against phishing and spoofing. Which THREE features should be enabled to achieve comprehensive email authentication?
Medium161A multinational corporation is implementing ZTNA for remote access to a critical internal application hosted on a server with IP 10.0.1.200:8443. The FortiGate is deployed at the edge with WAN IP 203.0.113.50. The administrator configures a ZTNA rule with proxy destination 10.0.1.200:8443, a firewall policy allowing traffic from the ZTNA gateway to the internal server, and a VIP for port forwarding for testing. However, remote users report that they can establish a ZTNA connection to the gateway but the application page fails to load, showing a blank page after a long delay. The FortiGate logs show no errors, and the debug output indicates that the proxy successfully forwarded the request to 10.0.1.200:8443 and received a response. The internal server team confirms the application is working correctly for on-site users. What is the most likely cause?
Hard162An admin needs to configure a FortiGate to send logs to FortiAnalyzer for a specific VDOM only. How can this be achieved?
Medium163A company is implementing a Security Fabric with multiple FortiGate devices. They want to use FortiAnalyzer for centralized logging and FortiManager for centralized management. Which of the following is a prerequisite for adding a FortiGate to the Security Fabric?
Easy164An administrator wants to use FortiGate to automatically block traffic if FortiEDR detects a threat on an endpoint. Which feature should the administrator configure?
Medium165A FortiGate administrator wants to use PKI certificates for IPsec VPN authentication instead of pre-shared keys. Which phase1 parameter must be set to 'signature' to enable certificate-based authentication?
Easy166A FortiGate with SD-WAN configured has a Performance SLA monitoring Google DNS (8.8.8.8). The SLA is configured with latency threshold 100 ms and jitter threshold 20 ms. The link is currently meeting both thresholds. The administrator wants to ensure that if the SLA fails, traffic moves to another link. Which SD-WAN rule strategy should be used?
Medium167An administrator wants to block a zero-day malware outbreak detected by FortiGuard. Which feature should be configured to automatically block the threat across all enabled FortiGate devices?
Easy168An administrator configures an ALG for SIP traffic but notices that some SIP calls are failing. The admin suspects the ALG is modifying SIP headers incorrectly. Which debug command can help verify the ALG's actions on SIP packets?
Hard169A FortiGate administrator runs the following command and sees the output: diagnose sys session filter dport 443 diagnose sys session list Output shows sessions with proto=6 and expire time decreasing. What does this indicate?
Medium170A FortiGate administrator wants to integrate ZTNA with FortiClient EMS to control access to an internal application based on device posture. The admin has configured a ZTNA tag in EMS for 'AntiVirus enabled' and created a ZTNA rule in FortiGate. What additional configuration is required on the FortiGate to enforce access based on the ZTNA tag?
Easy171An administrator is configuring FortiGate automation stitches to respond to a detected ransomware outbreak. The trigger is a high severity event from FortiSandbox. Which TWO actions can be used in an automation stitch to contain the threat?
Medium172A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?
Medium173A FortiGate administrator wants to use FortiManager automation stitches to automatically block IP addresses that trigger multiple intrusion prevention events. Which two components are required to configure an automation stitch? (Choose two.)
Medium174A network administrator is troubleshooting why a FortiGate does not appear to be enforcing a newly configured application control profile. The policy is applied to traffic from the internal network to the internet. The administrator runs 'diagnose sys session list' and sees that sessions are being created, but the application control profile is not listed in the session details. Which action should the administrator take to verify that the application control profile is being applied?
Medium175Which of the following is a valid command to check the status of all BGP neighbors on a FortiGate?
Easy176A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?
Medium177A FortiGate has two VDOMs: 'root' and 'customer'. The admin wants to route traffic from 'customer' to the internet via 'root', which has a BGP connection to an ISP. What is the required configuration?
Medium178A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator wants VDOM-A and VDOM-B to exchange routing information dynamically without using static routes. The administrator has already created a VDOM link named 'vlink' between the two VDOMs and assigned IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. Which additional configuration is required on each VDOM to enable OSPF adjacency over the VDOM link?
Medium179Which THREE actions can an administrator perform using FortiManager in a Security Fabric environment? (Choose three.)
Hard180A FortiGate administrator wants to ensure that files in email attachments are disarmed before delivery. Which security feature should be configured in the antivirus profile?
Easy181An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?
Medium182A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?
Medium183An organization wants to implement email authentication to prevent spoofing and phishing attacks. They use FortiMail as their email security gateway. Which THREE mechanisms should they configure to achieve comprehensive email authentication?
Medium184A FortiGate administrator has deployed ZTNA with FortiClient EMS tagging. A remote user's endpoint is tagged as 'Compliant' in EMS, but the FortiGate ZTNA policy still denies the user's connection to the internal web application. The administrator confirmed the EMS connector status on the FortiGate shows 'Connected' and the tag is visible in the FortiGate's device inventory. What is the most likely cause of the access denial?
Medium185A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?
Medium186An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own separate routing table. Which statement is correct?
Easy187An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?
Medium188What is the purpose of a route map when used with route redistribution on a FortiGate?
Easy189A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that only specific subnets are allowed over the tunnel and that the tunnel uses strong encryption. After configuring phase1 and phase2, the administrator notices that the tunnel is up, but traffic from a subnet that should be allowed is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. What is the most likely reason for the traffic not passing?
Hard190A healthcare provider is deploying ZTNA to secure access to an internal electronic health records (EHR) system. The EHR system is composed of multiple web services running on different ports behind a load balancer with IP 10.0.10.100. The load balancer listens on ports 443, 8443, and 9090. The administrator configures a single ZTNA rule with proxy destination 10.0.10.100:443, expecting that the other ports will be accessed via the same rule. However, users report that they can only access the service on port 443; connections to ports 8443 and 9090 fail. The FortiGate logs show that requests to other ports are being dropped. What should the administrator do to resolve this?
Medium191In a Fortinet ZTNA deployment, which component is responsible for forwarding decrypted traffic to the internal application server after the FortiGate proxy has performed SSL inspection?
Easy192Drag and drop the steps to configure a site-to-site IPsec VPN on a FortiGate firewall into the correct order.
Medium193A network administrator is configuring SD-WAN on a FortiGate. They have multiple WAN links and want to ensure that traffic for a critical application uses the link with the lowest latency. Which SD-WAN configuration component should be used to achieve this?
Medium194A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?
Easy195An administrator wants to block outbound traffic from internal hosts to known malicious domains without relying on full URL inspection or certificate inspection. The requirement is to use a lightweight DNS-based security service on FortiGate that can block botnet C2 and phishing domains. Which FortiGuard feature should the administrator enable and configure in a DNS filter profile?
Medium196You are troubleshooting a VPN phase 2 negotiation failure. The logs show 'no proposal chosen'. What is the MOST likely cause?
Hard197A FortiGate is configured with ECMP load balancing. What is the default behavior when multiple routes have equal cost?
Easy198During a failover test in an active-passive HA cluster, the administrator notices that the secondary unit does not take over the primary role after a link failure on the primary. The 'get system ha status' shows both units in 'standalone' mode. What is the MOST likely cause?
Medium199An organization wants to deploy a web application firewall (WAF) to protect a public-facing web application. They are evaluating FortiGate versus FortiWeb. Which of the following is a key advantage of using FortiWeb over FortiGate for WAF functionality?
Medium200A company is deploying ZTNA to protect an internal application. They want to ensure that only users with devices that have disk encryption enabled and the latest OS patches can access the application. Which THREE components must be configured to achieve this?
Hard201An administrator is deploying a FortiGate with multiple VDOMs in NAT/route mode. The administrator needs to configure inter-VDOM routing between VDOM-A and VDOM-B. Which two actions are required to enable traffic to flow between the two VDOMs? (Choose two.)
Medium202An administrator wants to use FortiGate to block outbound traffic to known malicious IP addresses based on a threat intelligence feed. They configure a threat feed connector and a firewall policy with a destination address group. However, the policy is not blocking traffic to the malicious IPs. What is the most likely cause?
Medium203A company wants to receive threat intelligence feeds from external sources to enhance their FortiGate's protection. Which method should be used to integrate external threat feeds into FortiGate?
Medium204A FortiGate administrator is configuring a ZTNA rule to protect an internal application. The administrator wants to ensure that only devices with a specific compliance tag are allowed, while all other devices are denied. The administrator has already created the ZTNA server and the FortiClient EMS tags. What is the correct way to enforce this requirement in the firewall policy?
Easy205An organization deploys FortiEDR to protect endpoints. Which component is responsible for collecting and sending telemetry data to the FortiEDR management console?
Medium206Match each FortiGate routing concept to its description.
Medium207A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to multiple VDOMs to save physical ports. Which feature should they use?
Hard208A FortiGate is configured with a firewall policy that has a URL filter profile. Users report that access to a specific website is blocked, but the administrator wants to verify which URL filter category matched the request. The administrator runs 'diagnose debug application urlfilter -1' in the CLI. However, no output appears. What is the MOST likely reason for the lack of output?
Medium209A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?
Medium210A FortiGate administrator needs to configure a policy that allows traffic from VDOM A to VDOM B using inter-VDOM routing. Which configuration is required?
Medium211An administrator configures email authentication (SPF, DKIM, DMARC) on FortiMail. They find that legitimate emails are being marked as spam by FortiMail. The SPF check passes but DKIM fails. What could be the issue?
Hard212An organization is deploying FortiEDR to enhance endpoint protection. Which THREE capabilities does FortiEDR provide? (Choose three.)
Hard213A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?
Medium214Refer to the exhibit. A tunnel interface is configured with IP 10.0.1.1/30 and remote-ip 10.0.1.2/30. The phase2 defines src-subnet as 10.0.1.0/30 and dst-subnet as 10.0.2.0/30. What is the most likely problem with this configuration?
Hard215A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?
Medium216What is the purpose of a management VDOM in a multi-VDOM FortiGate?
Easy217A FortiGate is configured as a ZTNA access proxy for an internal application. The administrator wants to enforce device compliance using FortiClient EMS tags before allowing access. Which configuration step is required to ensure that only endpoints with a specific EMS tag can access the application?
Medium218A FortiGate administrator wants to see the current number of active sessions. Which command provides this information?
Easy219A company is deploying ZTNA to replace their legacy VPN. They want to ensure that only users with a valid certificate and compliant antivirus can access the internal application. Which TWO components are required on the FortiGate for this deployment?
Easy220An administrator is deploying an ADVPN with a hub and two spokes. The hub is behind a NAT device and has a static public IP, while both spokes are behind NAT with dynamic public IPs. The administrator wants the spokes to establish shortcuts directly between each other. Which configuration is required for the shortcut to form?
Hard221An administrator has a FortiGate with multiple VDOMs and a management VDOM enabled. The management VDOM is used for out-of-band management and logging. The administrator wants to ensure that the management VDOM can reach a syslog server on the Internet while all other VDOMs use a separate data VDOM for their Internet traffic. Which configuration is required to allow the management VDOM to use a different default route than the other VDOMs?
Hard222A network administrator is troubleshooting a FortiGate HA cluster in active-passive mode. The administrator notices that the secondary unit is not receiving heartbeat packets from the primary unit, and the cluster has split. The administrator runs 'diagnose sys ha status' on both units and sees that the primary unit shows the secondary as 'not connected', while the secondary unit shows the primary as 'not connected'. The administrator verifies that the heartbeat interfaces are correctly configured and physically connected. What is the MOST likely cause of the split?
Hard223An administrator has a FortiGate 600E running FortiOS 7.2 with multiple VDOMs enabled. The administrator wants to create a new VDOM named 'DMZ' and assign it a specific physical interface (port3) that is currently unused. After creating the VDOM, the administrator navigates to Network > Interfaces in the DMZ VDOM but cannot see port3 in the list of available interfaces to assign. What is the most likely reason for this?
Medium224A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?
Hard225In FortiManager, an administrator wants to apply a set of firewall policies to multiple FortiGates in different ADOMs. The policies must be centrally managed. What is the best approach?
Medium226An administrator wants to ensure that traffic between two VDOMs on the same FortiGate is properly inspected. Which THREE configurations must be in place?
Hard227A site-to-site IPsec VPN tunnel is failing. The administrator runs 'diagnose vpn ike config' and sees that phase 1 parameters are correct. However, phase 2 negotiation fails with 'no proposal chosen'. What is the MOST likely cause?
Medium228An administrator configures an SD-WAN rule to steer traffic from a specific subnet to an SD-WAN member with the lowest cost. Which load balancing algorithm should be selected in the SD-WAN rule to achieve this behavior?
Medium229An administrator configures FortiAnalyzer to receive logs from multiple FortiGates. They want to create a report that shows only incidents involving 'critical' severity and specific attack types. Which FortiAnalyzer feature allows the administrator to define such a custom report?
Hard230An administrator wants to troubleshoot why specific traffic is not matching a configured firewall policy. Which debug command should be used?
Medium231A FortiGate administrator wants to use Fortinac for network access control. Which of the following is the PRIMARY function of Fortinac in a network?
Easy232A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?
Easy233A FortiGate administrator is using FortiNAC to enforce network access control for wired endpoints. The administrator wants to quarantine any endpoint that fails antivirus compliance. Which action should be configured in the FortiNAC policy to achieve this?
Medium234An administrator is troubleshooting a scenario where FortiAnalyzer is not receiving logs from a FortiGate. The FortiGate shows 'log-fortianalyzer setting status: disconnected'. Which step should be taken first to resolve this?
Medium235Which routing technique allows a FortiGate to forward packets based on source IP address, destination IP address, or other criteria, in addition to the destination IP alone?
Easy236A FortiGate administrator configures SAML SSO with FortiGate as the Service Provider (SP) and an external IdP. Users report that they are prompted for credentials repeatedly without successful authentication. What is the most likely cause?
Medium237A FortiGate is configured with OSPF and BGP. The administrator wants to redistribute OSPF routes into BGP. Which TWO steps are required?
Medium238An administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that both phase 1 and phase 2 are up. The policy allows traffic from both sides. What should the administrator check next?
Medium239An admin configures Content Disarm and Reconstruction (CDR) on FortiGate to protect against malicious macros in Office documents. After applying the CDR profile to a firewall policy, users complain that documents are not being delivered. What is the most likely cause?
Hard240A FortiGate is configured with two SD-WAN members (wan1, wan2) and a performance SLA for each. The SD-WAN rule uses 'Maximize Bandwidth' strategy with volume-based load balancing. The administrator notices that traffic is only using wan1, even though both links have capacity. The SLA status for wan2 shows 'alive'. What could be the problem?
Hard241An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. The performance SLA monitors latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest jitter that also meets the SLA thresholds. Which SD-WAN strategy should be used?
Easy242A security administrator is configuring a FortiGate to use an external threat intelligence feed via a Threat Feed connector. The administrator wants to ensure that the firewall automatically blocks traffic to malicious IP addresses and domains from the feed. Which two actions are required to achieve this? (Choose two.)
Medium243An administrator runs 'diagnose debug application fnbam -1' and sees messages like 'LB_SELECT: selected server 10.0.0.2:80' but the client connection fails. The FortiGate is configured with server load balancing. What could be the issue?
Hard244An administrator is configuring a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that traffic between VDOMs is inspected by firewall policies. Which TWO statements about inter-VDOM routing are correct? (Choose two.)
Medium245An administrator wants to enforce that only devices with up-to-date antivirus software can access corporate resources via ZTNA. Which FortiClient feature should be used to enforce this requirement?
Easy246A company has a FortiGate with multiple VDOMs. The security team wants to use FortiManager to manage policies centrally. Which three steps are necessary to set up VDOM management via FortiManager? (Choose three.)
Hard247An administrator wants to enforce that only devices with corporate-owned certificates can establish an IPsec VPN tunnel. Which IPsec authentication method should be configured?
Easy248A network admin is deploying a FortiGate in transparent mode to inspect traffic between two Layer 2 switches. Which of the following statements about transparent mode is correct?
Medium249A network admin wants to use FortiClient's advanced threat protection features to detect ransomware behavior on endpoints. Which FortiClient feature should be enabled?
Medium250A FortiGate is configured with multiple BGP peers. One of the peers is not receiving the expected routes. The administrator runs 'get router info bgp neighbors <IP>' and sees that the 'State/PfxRcd' field is 'Active'. What does this indicate?
Medium251An administrator notices high CPU usage on a FortiGate. To identify which process is consuming the most CPU, which command should be used?
Medium252Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?
Medium253A FortiGate administrator is troubleshooting a scenario where users in VDOM-1 cannot reach a server in VDOM-2. Inter-VDOM routing is configured using a VDOM link. The administrator checks the session table and sees that packets are arriving on the VDOM link interface but are not being forwarded. What is the MOST likely cause?
Hard254An administrator is configuring an IPsec VPN on a FortiGate that will interoperate with a third-party peer. The peer requires the use of a specific encryption domain and does not support IKEv2. The administrator wants to ensure that only specific subnets are permitted through the tunnel, while all other traffic is excluded from the SA. Which configuration element on the FortiGate directly controls which traffic is selected for the IPsec tunnel?
Hard255A FortiGate administrator notices that after installing a new policy package from FortiManager, the firewall policies on the managed FortiGate do not match what was configured in FortiManager. What feature should the administrator use to review the exact changes before committing?
Easy256A network security administrator wants to use FortiGate to automatically quarantine an endpoint when FortiEDR detects malicious behavior on that endpoint. Which FortiGate feature should be used to integrate with FortiEDR for this purpose?
Easy257A network admin is troubleshooting why FortiGate's antivirus is not detecting a known malware sample. The sample is detected by other scanners. Which two checks should the admin perform? (Choose two.)
Medium258An administrator wants to ensure that only devices with up-to-date antivirus software can access a sensitive application via ZTNA. Which FortiGate feature should be used to enforce this requirement?
Easy259A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to enable communication between VDOM-A and VDOM-B using an inter-VDOM link. The administrator creates the link and assigns IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. The administrator then adds a static route in VDOM-A to VDOM-B's network (192.168.2.0/24) via 10.0.0.2, and a static route in VDOM-B to VDOM-A's network (192.168.1.0/24) via 10.0.0.1. However, traffic still fails. What is the most likely missing configuration?
Hard260A FortiGate is configured with a firewall policy that applies an application control profile blocking social media. Users report that they can still access Facebook. The administrator verifies that the policy is correctly matching the traffic and that the application control profile is applied. Which CLI command should the administrator use to verify whether the application control is correctly identifying the traffic?
Medium261A security analyst is investigating a recent security incident and wants to use FortiGate's Security Fabric to gather threat intelligence. The analyst needs to view detailed information about a detected threat, including the source, destination, and the specific IPS signature that triggered. Which FortiGate feature provides a centralized view of threat events and allows drill-down into individual incidents?
Hard262A security administrator is configuring FortiSandbox integration to automatically block malicious files detected in email attachments. Which TWO actions are required to achieve this integration?
Medium263A FortiGate administrator needs to use FortiManager to deploy a new security policy to all firewalls in a specific ADOM. Which two steps are part of the installation process? (Choose two.)
Easy264A FortiGate is configured with a VIP for an internal web server. Users report that the web server is unreachable from the internet, but it is accessible from the internal network. The administrator runs 'diagnose debug flow' with filters for the public IP and sees that the traffic reaches the FortiGate but is dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?
Hard265What is the purpose of a prefix list in FortiGate routing?
Easy266You run 'diagnose vpn ike gateway list' and see the following: gateway name: HUB_GW version: IKEv2 state: UP mode: main local: 10.0.0.1:500 remote: 203.0.113.5:500 auth: psk dpd: on rekey: 86400 num_peers: 2 total_tunnels: 2 auto-discovery: enabled What does the 'auto-discovery: enabled' indicate about this VPN gateway?
Hard267A network administrator is troubleshooting an IPsec VPN tunnel between Site A (FortiGate) and Site B (third-party VPN peer). The tunnel fails to establish. On FortiGate, phase1 status shows 'up' but phase2 status remains 'down'. What is the MOST likely cause?
Medium268A ZTNA rule is configured to allow access to an internal application only if the client device has the ZTNA tag 'Compliant' and the user is authenticated via SAML. The FortiGate is acting as ZTNA proxy. A user successfully authenticates but the device is not tagged. What happens when the user tries to access the application?
Medium269An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. They have two WAN members: port1 (MPLS) and port2 (Internet). They create a performance SLA that monitors latency and jitter, and set the SLA target to 150 ms latency and 30 ms jitter. They apply the SLA to both members. The SD-WAN rule is set to 'Best Quality' strategy. After applying the configuration, they notice that VoIP traffic is sometimes routed over port2 even though port1 has lower latency and jitter. What is the most likely reason?
Medium270You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
Hard271Which TWO features are required to implement an always-on SSL VPN tunnel with FortiGate that automatically reconnects when the user's network changes?
Hard272A FortiGate is configured with two VRF instances: VRF10 (for a customer) and VRF20 (for another customer). Each VRF has its own interfaces and routing table. The administrator wants to allow a specific server in VRF10 (10.10.10.5) to be reachable from a host in VRF20 (20.20.20.5) without leaking all routes between VRFs. Which FortiGate feature should be used to achieve this?
Hard273A security team uses FortiSandbox in a FortiGate security fabric. They want files that receive a 'Malicious' verdict to be automatically quarantined and their source endpoints isolated without manual intervention. Which combination of Fortinet components and features must be configured to achieve this automated response?
Hard274An organization uses FortiNAC for network access control. They want to enforce that only corporate-managed devices with up-to-date patches can access the production VLAN. Which THREE components must be integrated or configured?
Hard275An administrator configures BFD on a FortiGate to improve convergence time for OSPF. What is the primary purpose of BFD in this context?
Medium276A network administrator is deploying a FortiGate in multi-VDOM mode. The administrator wants to restrict a specific VDOM so that it can only use a maximum of 2 GB of system memory and 10% of the total CPU resources. Which FortiGate feature should the administrator use?
Easy277An administrator is troubleshooting a FortiGate HA cluster that is experiencing frequent failovers. The administrator wants to verify the HA status and identify potential issues. Which TWO commands should the administrator use to gather relevant information? (Choose two.)
Medium278An administrator has a FortiGate with two VDOMs: 'root' and 'VDOM-A'. The administrator wants to assign a physical interface to VDOM-A, but the interface is currently assigned to the root VDOM and is in use by a firewall policy. What must the administrator do before changing the interface's VDOM assignment?
Hard279An administrator wants to see the current number of active sessions on a FortiGate. Which command should the admin use?
Easy280A FortiGate administrator is planning a multi-VDOM deployment for a service provider. Which TWO statements are true about VDOM limitations and best practices?
Medium281A FortiGate is configured with two SD-WAN members: port1 and port2. The administrator wants to ensure that voice traffic uses port1, but if port1's latency exceeds 150 ms, voice traffic should fail over to port2. Which configuration is required to achieve this?
Hard282A FortiGate is configured with an explicit web proxy on port 8080. Users report that some websites load slowly while others fail to load at all. The administrator runs 'diagnose debug application wad 8' and sees messages about 'proxy worker' and 'connection failed'. Which command should the administrator use to view the current proxy sessions in real time?
Medium283A FortiGate is configured as a SAML service provider (SP) for ZTNA. Users authenticate via an external IdP. After authentication, users are not able to access applications even though the ZTNA proxy rule lists them. What should the administrator check FIRST?
Medium284An enterprise deploys a FortiGate in transparent mode to bridge two broadcast domains. The administrator needs to apply a web filter to HTTP traffic between these domains. Which configuration is required?
Medium285Drag and drop the steps to perform a firmware upgrade on a FortiGate device into the correct order.
Medium286A FortiManager administrator wants to deploy a policy package that contains shared header and footer policies across multiple devices. How should these policies be configured in FortiManager?
Medium287In FortiManager, what is the difference between a Global ADOM and a regular ADOM?
Easy288An administrator is configuring an SD-WAN rule to distribute traffic across two WAN links based on the number of active sessions. They want to ensure that new sessions are assigned to the link with the fewest current sessions. Which load balancing algorithm should they use?
Easy289A FortiGate administrator is troubleshooting a site-to-site IPsec tunnel that intermittently drops. The administrator runs 'diagnose vpn ike gateway list' and observes that the tunnel re-establishes every few minutes, and 'diagnose debug application ike -1' shows repeated INVALID_KE_PAYLOAD notifications. The remote peer is a third-party gateway that only supports a specific Diffie-Hellman group. What is the most likely cause of the repeated renegotiation?
Medium290An HA cluster of two FortiGates is experiencing split-brain. After investigation, you find that the heartbeat link is down on the primary unit. Which action will resolve the split-brain condition?
Hard291A FortiGate administrator is deploying ZTNA to replace SSL VPN for remote access. The requirement is that endpoint posture (antivirus status, OS patch level) must be verified before a user is allowed to reach internal web applications through the ZTNA proxy, and that posture must be re-evaluated on each new connection. Which FortiGate configuration element is required to enforce this dynamic, per-connection posture check?
Medium292A FortiManager administrator wants to push policy package changes to a managed FortiGate, but wants to see what changes will be applied before committing. Which FortiManager feature should the administrator use?
Medium293An administrator wants to create an automation stitch that responds to a high-severity IPS event by blocking the attacker IP. Which THREE components are required to build this automation stitch?
Medium294An administrator is troubleshooting an OSPF over IPsec VPN overlay. The OSPF neighbor state is stuck in EXSTART. The VPN tunnel is up. Which TWO issues could cause this?
Hard295A FortiGate administrator wants to implement ZTNA to control access to an internal application server. Users will access the application via FortiClient. Which configuration step is REQUIRED to allow FortiClient to forward traffic to the ZTNA gateway?
Medium296In FortiManager, what is an automation stitch?
Easy297An SD-WAN rule is configured to steer traffic based on SLA metrics. The administrator notices that traffic is not using the expected member interface even though the SLA is meeting thresholds. What should the administrator check FIRST?
Medium298An administrator wants to automatically block a file that FortiSandbox has determined to be malicious. The FortiGate is configured with an antivirus profile that includes FortiSandbox submission. Which verdict action should be set to 'block' in the antivirus profile to achieve this?
Medium299An administrator is configuring ZTNA inline CASB on a FortiGate to control access to a sanctioned SaaS application. The requirement is to block uploads of files containing credit card numbers while allowing normal business uploads. The administrator creates an access proxy rule and a CASB profile with a data loss prevention sensor. During testing, uploads of files with credit card numbers are still allowed. Which action should the administrator take to enforce the block?
Medium300A multi-tenant FortiGate uses VDOMs. The administrator notices that logins via SSH to the management VDOM succeed, but attempts to SSH to a traffic VDOM's management IP fail. The traffic VDOM has an administrative user configured. What is the most likely cause?
Medium301An administrator has configured an SD-WAN zone named 'virtual-wan-link' with two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'SLA1' is created and assigned to the zone. The administrator wants to ensure that SD-WAN rules use the SLA results to select the best member. Which statement correctly describes how the FortiGate uses the performance SLA results in SD-WAN rule selection?
Medium302An administrator is troubleshooting an HA cluster where both units show as primary after a link failure. What is the most likely cause of this split-brain scenario?
Easy303An administrator configures SD-WAN with multiple members. The SD-WAN rule uses the 'latency' strategy. The administrator notices that traffic is not switching to the best-performing member even when latency exceeds the threshold. What could be the issue?
Hard304A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?
Medium305An administrator is troubleshooting a scenario where traffic from VLAN 100 to a server at 10.1.2.100 is being blocked. The FortiGate has an active security policy allowing the traffic and the routing table shows a correct route. Which TWO diagnostic commands should the administrator run to identify the cause of the blockage?
Medium306Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?
Hard307An administrator deploys a FortiGate in transparent mode within a Layer 2 network. They apply a firewall policy with an antivirus profile to inspect traffic between two VLANs. What is a key characteristic of transparent mode that affects policy application?
Medium308A FortiGate administrator enables Dead Peer Detection (DPD) on an IPsec VPN tunnel. What is the primary purpose of DPD?
Easy309An administrator runs 'get router info bgp summary' and sees that the BGP session to a neighbor is in the 'Idle' state. The neighbor IP is reachable via ping. The BGP configuration uses loopback interfaces with 'update-source loopback1'. What is the MOST likely reason for the Idle state?
Hard310What is the function of a VRF (Virtual Routing and Forwarding) on a FortiGate?
Easy311A FortiGate has multiple IPsec VPNs to different branch offices. The administrator notices that one VPN tunnel is flapping (going up and down repeatedly). From the CLI, 'diagnose vpn ike gateway list' shows the gateway state as 'up' but then quickly goes to 'down'. What is the MOST likely cause?
Hard312An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links based on the source IP address of the traffic. Which load balancing algorithm should be used to achieve this?
Easy313An administrator configures two FortiGate units in an active-passive HA cluster. During a failover test, the administrator notices that the secondary unit becomes primary but the session table is empty, causing all existing connections to drop. Which configuration change should be made to preserve session information during failover?
Medium314A FortiGate 600E is running multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 each have an inter-VDOM link interface named 'ivl-1' and 'ivl-2' respectively, and both are assigned IP addresses in the 10.10.10.0/30 subnet. VDOM-1 has a static route to 192.168.2.0/24 via 10.10.10.2, and VDOM-2 has a static route to 192.168.1.0/24 via 10.10.10.1. A user in VDOM-1 (192.168.1.10) cannot ping a server in VDOM-2 (192.168.2.10). What is the most likely cause?
Medium315A company uses SSL VPN with FortiGate for remote access. Users report that after connecting, they can access internal web servers but cannot ping them. Which configuration is most likely missing?
Hard316What is the primary difference between using a Web Application Firewall (WAF) on FortiGate versus using FortiWeb?
Easy317An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The configuration uses certificates for authentication. The admin sees the following log message: 'Certificate validation failed: unable to get local issuer certificate.' What is the most likely cause?
Easy318An organization uses FortiManager to manage multiple FortiGates. A junior admin accidentally deleted a critical firewall policy on one device and the change was auto-installed. How can the senior admin revert the device to the previous configuration?
Medium319An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. After configuration, traffic from VDOM-A cannot reach VDOM-B. Which configuration step is MOST likely missing?
Medium320A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?
Medium321A FortiGate 600E is configured with multiple VDOMs in NAT mode. The administrator wants to route traffic between VDOM-1 and VDOM-2 without using physical interfaces. They create a VDOM link named 'vlink' with interfaces vlink0 and vlink1, assign vlink0 to VDOM-1 (IP 10.0.1.1/30) and vlink1 to VDOM-2 (IP 10.0.1.2/30). However, traffic from a host in VDOM-1 (192.168.1.0/24) to a server in VDOM-2 (192.168.2.0/24) fails. The administrator has added static routes in both VDOMs pointing to the respective VDOM link IPs. What is the most likely cause of the failure?
Medium322An organization wants to prevent zero-day attacks by using Content Disarm and Reconstruction (CDR) on email attachments. Which Fortinet product provides this capability?
Medium323An administrator has configured a FortiGate HA cluster with two units. The cluster uses a virtual cluster for load balancing in active-active mode. The administrator notices that traffic from one VDOM is not being load-balanced and is only handled by one unit. What is the most likely cause?
Medium324An administrator has deployed a ZTNA configuration on a FortiGate where remote users authenticate through FortiClient EMS. The administrator wants to ensure that only devices with an up-to-date operating system and active antivirus are granted access to an internal web application. The FortiGate is configured as the ZTNA access proxy. Which FortiGate component or configuration is required to enforce these device compliance checks?
Hard325An administrator is configuring a FortiGate with VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that routes in one VDOM do not affect another. Which statement about VDOM routing is correct?
Easy326Which FortiManager feature allows an administrator to roll back a policy package to a previous version?
Easy327A company with a hub-and-spoke SD-WAN topology uses FortiGates at each site. The hub has two WAN links: MPLS (10 Mbps) and broadband (100 Mbps). The spokes connect only via MPLS. The company deploys a new real-time application that requires low latency and low jitter. The network administrator creates an SD-WAN rule for this application with 'best quality' strategy and both MPLS and broadband as members. The SLA for MPLS is configured with latency < 10 ms and jitter < 5 ms. The SLA for broadband is configured with latency < 50 ms and jitter < 20 ms. The actual measured latency on MPLS is 12 ms, and jitter is 4 ms. The broadband latency is 25 ms, jitter 10 ms. Which path will the application traffic take?
Medium328An administrator wants to enforce that only devices with antivirus software installed and running can access a sensitive application via ZTNA. Which ZTNA feature should be used to verify this requirement?
Easy329A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?
Hard330A company uses FortiManager to manage multiple FortiGates. The admin wants to use a global ADOM to manage certain policies across all devices while allowing local customization. Which two statements about global ADOM are true? (Choose two.)
Medium331A security analyst wants to use automation stitches on FortiGate to automatically block an IP address when a critical severity event is logged. Which TWO components are essential to create this automation stitch? (Choose two.)
Medium332A FortiGate administrator wants to check if the device is experiencing high CPU usage due to a specific process. Which command should they use to display real-time process CPU usage?
Easy333An administrator needs to deploy a honeypot solution to detect and deceive attackers inside the network. Which Fortinet product is BEST suited for this purpose?
Medium334In FortiGate's ZTNA, what is the purpose of a 'ZTNA tag'?
Easy335A network administrator is troubleshooting a scenario where remote users can connect via FortiClient VPN but cannot access internal resources. The FortiGate has a valid IPsec VPN configuration. Which THREE checks should the administrator perform to resolve the issue?
Medium336A network security administrator is deploying a FortiSandbox appliance in a FortiGate environment. The administrator wants to ensure that when a zero-day malware sample is detonated, the FortiGate immediately blocks the file hash and the C2 callback. Which FortiSandbox integration method should the administrator configure on the FortiGate to achieve this?
Medium337You want to use policy-based routing (PBR) to send traffic from a specific subnet to a different next-hop than the default route. Which configuration is required?
Medium338A FortiGate administrator wants to use FortiManager to manage multiple FortiGates in different geographic regions. To isolate configuration changes, the administrator creates separate ADOMs for each region. Which type of ADOM should be used to allow some common objects (like address groups) to be shared across all regions?
Medium339A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?
Hard340In a hub-and-spoke VPN, spokes cannot communicate with each other directly. The administrator wants to allow direct spoke-to-spoke traffic without routing through the hub. Which technology should be configured?
Medium341An administrator has a FortiGate 600E running multiple VDOMs in NAT mode. The security team wants to inspect inter-VDOM traffic between VDOM-A and VDOM-B with a firewall policy that applies UTM profiles. The administrator has already created a VDOM link named vlink1 with interfaces vlink1-A in VDOM-A and vlink1-B in VDOM-B. What must the administrator do to ensure that inter-VDOM traffic is inspected by a security policy?
Medium342An administrator configures an automation stitch in FortiManager to execute a CLI script on a FortiGate when a specific event is triggered. The automation stitch is enabled but does not run when the event occurs. What is the most likely cause?
Hard343When troubleshooting an IPsec VPN phase 1 negotiation failure, which debug command should the administrator run to see detailed IKE negotiation messages?
Medium344A FortiGate administrator is configuring a multi-VDOM deployment. The administrator wants to use a single physical interface for multiple VDOMs. Which TWO methods allow this?
Medium345An administrator configured FortiGate to forward suspected malicious files to FortiSandbox. They set the action to 'block' for malicious verdicts. Some files are being blocked, but others with a 'clean' verdict are allowed. However, they notice that some files that should have been sent to FortiSandbox are not being forwarded. Which reason is MOST likely?
Hard346Based on the exhibit, what can be concluded about the session?
Hard347An administrator is configuring a FortiGate with multiple VDOMs in NAT/route mode. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. Which TWO statements about VDOM links are correct? (Choose two.)
Medium348A FortiGate administrator is configuring an IPsec VPN tunnel to a remote site that is behind a NAT device. The administrator notices that the tunnel establishes, but traffic intermittently fails. Which setting should be adjusted to improve reliability?
Medium349An administrator manages a FortiGate with VDOMs 'prod' and 'dev' on a single HA pair. The administrator wants 'prod' to fail over independently from 'dev' so that maintenance on the dev environment does not trigger a failover of prod. Which FortiGate feature should be configured?
Hard350A FortiGate administrator is setting up a ZTNA rule to allow access to an internal application only for users who are members of the 'Finance' group in FortiClient EMS. The administrator has already configured the ZTNA server and access proxy. Which additional configuration is required on the FortiGate to enforce this group membership?
Easy351A security engineer wants to implement advanced threat protection for email using FortiMail. Which THREE features should be enabled to provide comprehensive protection against sophisticated email threats? (Choose three.)
Hard352A FortiGate is deployed in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator creates an inter-VDOM link named IVL1 with interface ivl-1-0 in VDOM-1 and ivl-1-1 in VDOM-2. Static routes are configured in both VDOMs to route traffic across the link. However, traffic from VDOM-1 to VDOM-2 is dropped. What is the most likely reason?
Hard353During a ZTNA deployment, an administrator notices that traffic from a specific internal application is being routed through the ZTNA gateway but is not reaching the destination server. The FortiGate policy allows the traffic, and the client has a valid ZTNA connection. What is the most likely cause of the issue?
Hard354A FortiGate is configured as a ZTNA proxy. The administrator wants to ensure that only devices with a specific ZTNA tag assigned by FortiClient EMS are allowed to access the application. Which two configuration steps are required? (Choose two.)
Medium355A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing internal applications. The administrator wants to ensure that only authenticated and compliant devices can access the applications, and that all traffic is inspected. Which two actions are required to achieve this? (Choose two.)
Hard356An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and observes that the 'ipsengine' process is consuming a large amount of CPU. The administrator suspects that a specific IPS signature is causing the issue. Which command should the administrator use to identify which IPS signature is triggering the high CPU usage?
Hard357An administrator is investigating a security incident where a workstation is communicating with a known command and control (C2) server. The FortiGate has IPS enabled but did not block the traffic. Which TWO configuration issues could explain why the IPS did not detect the C2 communication? (Choose two.)
Medium358An administrator configures a route map on a FortiGate to redistribute connected routes into OSPF. The route map sets a metric of 100. After applying, the redistributed routes appear with metric 20. What is the most likely reason?
Medium359A network administrator is troubleshooting an IPsec VPN tunnel that is not coming up. The configuration uses IKEv2 with pre-shared keys. The administrator runs 'diagnose vpn ike log-filter' and sees no logs. What is the most likely cause?
Medium360A FortiGate is configured with VRF. Which statement about VRF is true?
Medium361A security administrator is configuring a FortiGate to use an external threat intelligence feed to block malicious IP addresses. The administrator wants the FortiGate to automatically update the list of malicious IPs from a threat feed and use it in firewall policies. Which FortiGate feature should be used?
Medium362An administrator configures inter-VDOM routing between VDOMs A and B using a VDOM link. The administrator can ping from VDOM A to an interface in VDOM B, but traffic from VDOM B to VDOM A times out. What is the most likely cause?
Medium363An administrator is troubleshooting an SD-WAN deployment where traffic is not being forwarded according to the configured SD-WAN rules. The FortiGate has two WAN interfaces, port1 and port2, both members of an SD-WAN zone. A performance SLA is configured and both members are within SLA. The administrator suspects that the SD-WAN rules are not being evaluated correctly. Which two statements about SD-WAN rule evaluation are correct? (Choose two.)
Hard364An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?
Medium365You are troubleshooting BFD on a FortiGate SD-WAN deployment. BFD is configured on two WAN interfaces (wan1, wan2) with a minimum transmit interval of 100 ms and a multiplier of 3. The network experiences occasional jitter causing packet loss. After a brief outage, the BFD session does not recover. Which setting should be adjusted to improve BFD resilience without significantly increasing failover time?
Hard366A network administrator is configuring VDOMs on a FortiGate and wants to separate management traffic from production data traffic. What is the best practice when using a management VDOM?
Easy367A FortiGate administrator wants to use FortiManager automation stitches to automatically block an IP address when a specific threat is detected. Which components must be configured within the automation stitch?
Medium368An administrator configures an automation stitch on FortiGate to automatically block an IP address when a specific IPS signature triggers. What must be configured as the trigger and action?
Medium369A FortiGate administrator is configuring an IPsec VPN with IKEv2. The remote peer is behind a NAT device and has a dynamic public IP. The administrator wants the FortiGate to act as the responder and allow the remote peer to initiate the tunnel, while ensuring that only the remote peer's unique ID (FQDN) is accepted. Which configuration on the FortiGate is required to achieve this?
Medium370What is the purpose of a header policy in a FortiManager policy package?
Easy371A FortiGate in an HA cluster is experiencing intermittent session synchronization failures. The administrator runs 'diagnose sys ha dump sync-status' and sees that sessions are not being synchronized properly. Which TWO potential causes should the administrator investigate?
Medium372An administrator has deployed a FortiGate at a branch with two WAN links: port1 (primary) and port2 (backup). They create an SD-WAN zone and a performance SLA named 'ISP-Health' that monitors 8.8.8.8 using ping. The SLA is configured with link-cost-factor latency and a threshold of 50 ms. After a week, they notice that the primary link is still being used for all traffic even though its latency frequently exceeds 150 ms. The backup link has 20 ms latency. What is the most likely reason the SD-WAN rule is not failing over?
Medium373Which FortiGate feature allows the creation of multiple virtual routing tables within a single VDOM?
Easy374An administrator wants to isolate tenant traffic in a single FortiGate by creating separate virtual firewalls with independent routing tables, administrators, and policies. Which feature should the administrator use?
Easy375A FortiGate administrator is configuring an IPsec VPN to a remote peer behind a device that performs NAT. The administrator notices that the tunnel establishes but rekeys fail after the Phase 1 lifetime expires. Which setting should the administrator enable on the FortiGate to allow the IKE negotiation to survive NAT and pass through the NAT device reliably?
Easy376You are troubleshooting an SD-WAN rule where traffic is not matching the expected SLA. The FortiGate shows 'SLA mismatch' in logs. What is the MOST likely cause?
Medium377An administrator needs to verify that a FortiGate is correctly matching a firewall policy for traffic from 192.168.1.0/24 to 10.0.0.0/8. Which command provides a list of policies that match a given source and destination?
Easy378A FortiGate 600E is running multiple VDOMs in NAT mode. The administrator wants to assign a VLAN subinterface to VDOM-A while the parent physical interface remains in the root VDOM. Which configuration step is required to accomplish this?
Medium379During a ZTNA implementation, the administrator configures a ZTNA rule for an internal application but users cannot connect. The FortiGate policy is correct and the application is reachable from the FortiGate. What is the most likely misconfiguration?
Hard380What is the difference between a global ADOM and a regular ADOM in FortiManager?
Easy381A company wants to use FortiMail to implement email authentication to prevent spoofing. Which THREE mechanisms should be configured in FortiMail's Authentication Profile?
Medium382Based on the debug flow output, what is the reason the packet is dropped?
Hard383A FortiGate is configured with ECMP load balancing for equal-cost routes. The administrator wants to ensure that all traffic from a specific source IP uses the same next hop. Which ECMP load balancing method should be selected?
Medium384An administrator is configuring a FortiGate to detect and block traffic to known malicious domains using DNS filtering. The administrator wants to ensure that DNS queries for malicious domains are blocked and that users are redirected to a block page. Which DNS filter action should be configured?
Medium385An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal web application. The current network uses FortiGate as the firewall. Which component is required to enforce ZTNA policies on the FortiGate?
Easy386During a security incident, the SOC team receives an alert from FortiSIEM about a user accessing a known malicious IP. The team wants to automatically block the IP on the FortiGate. Which FortiGate feature can be used to create an automated response based on a threat intelligence feed?
Hard387A FortiGate has two VDOMs: Root and CustomerA. The administrator wants to manage the CustomerA VDOM from FortiManager. What must be configured on FortiManager to allow management of the CustomerA VDOM?
Medium388An HA cluster of two FortiGates is experiencing split-brain. Which command should the administrator use to check the current HA status and identify which unit is the primary?
Easy389An administrator wants to configure a multi-peer IPsec VPN where one FortiGate (hub) connects to multiple remote FortiGates (spokes) using a single phase 1 interface with dynamic IP addresses. Which configuration is required on the hub?
Easy390Which FortiMail advanced feature allows the administrator to rewrite URLs in email bodies to redirect users to a safe scanning service when they click on a link?
Medium391A FortiGate is configured with BGP and OSPF. The administrator wants to ensure that routes learned via BGP are redistributed into OSPF, but only specific prefixes. Which three components are needed? (Select THREE.)
Hard392An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links. The administrator wants to distribute traffic based on the source IP address to ensure that each source uses a consistent path. Which load balancing algorithm should be used?
Easy393A FortiGate admin notices that HTTPS traffic to a web server is not being scanned by the antivirus profile applied to the firewall policy. The admin confirms the policy is correct and antivirus is enabled. What is the MOST likely reason the traffic is not being scanned?
Medium394During a failover test in an HA cluster, the administrator observes that the secondary unit becomes primary but does not have the latest configuration. What is the most likely cause?
Medium395Which of the following is a required step when enabling VDOMs on a FortiGate for the first time?
Easy396What is the purpose of configuring BFD (Bidirectional Forwarding Detection) on a FortiGate?
Easy397A FortiGate administrator is troubleshooting a policy that is supposed to allow HTTP traffic from an internal subnet to a web server. Users report that they cannot access the web server. The administrator runs 'diagnose debug flow' and sees that the traffic is being denied by policy 0. What is the most likely cause?
Easy398A FortiGate is configured with three VDOMs: root, Sales, and Engineering. The administrator wants to ensure that the Sales VDOM can access the internet through the root VDOM, but the Engineering VDOM must not have any internet access. All VDOMs are currently in NAT mode. Which configuration is required to achieve this?
Medium399A FortiGate administrator is configuring a firewall policy to inspect traffic for advanced threats. The administrator wants to ensure that the policy uses both antivirus and IPS inspection, and that the traffic is inspected in a way that minimizes latency while still detecting threats. Which two actions should the administrator take? (Choose two.)
Medium400A FortiGate is configured with ECMP load balancing for multiple equal-cost routes. The administrator wants to ensure that all packets belonging to the same session go out the same interface. Which ECMP load balancing method should be used?
Hard401An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is hosted on a server with IP 10.1.1.100. Which component acts as the intermediary between users and the application in FortiGate ZTNA?
Easy402A FortiGate with SD-WAN has two members: MPLS (port1) and Broadband (port2). The performance SLA is configured to monitor latency and packet loss. The administrator notices that after a brief outage on the MPLS link, traffic fails over to Broadband but does not fail back when MPLS recovers. What is the likely cause?
Medium403What is the primary function of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus profile?
Easy404What is the purpose of Dead Peer Detection (DPD) in an IPsec VPN?
Easy405An administrator needs to check the current CPU and memory usage of a FortiGate to determine if resource exhaustion is causing network delays. Which CLI command provides a real-time, top-like view of processes and their resource consumption?
Easy406A network administrator wants to ensure that files downloaded from the internet are analyzed by FortiSandbox before being delivered to the client. The FortiGate is configured with a FortiSandbox connection and an antivirus profile. Which setting must be enabled in the antivirus profile to submit files to FortiSandbox?
Medium407An administrator has configured BGP on a FortiGate with two upstream ISPs. They notice that traffic to a specific prefix is not load-balanced as expected; all traffic goes through ISP1 even though both paths are available. 'get router info bgp network' shows the prefix with two next hops. What is the MOST likely cause?
Hard408An administrator has configured a FortiGate with an SD-WAN zone named 'virtual-wan-link' containing two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'CriticalSLA' monitors a server at 8.8.8.8 using ICMP probes every 5 seconds, with failure thresholds: latency 200 ms, jitter 50 ms, packet loss 5%. The SLA status for port1 is 'alive' and for port2 is 'dead'. An SD-WAN rule is configured to use the 'lowest-cost' algorithm with the SLA target 'CriticalSLA'. The administrator notices that all traffic is being routed through port1, even though port2 has a lower cost metric. What is the most likely reason for this behavior?
Medium409What is the purpose of using a prefix list in route redistribution?
Easy410A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the phase 2 selectors are restricted to specific subnets. Which two configuration elements are required to meet these goals? (Choose two.)
Hard411A FortiGate administrator is troubleshooting a connectivity issue where users cannot access a web server behind the FortiGate from the internet. The administrator suspects that the virtual IP (VIP) configuration is incorrect. Which two commands should the administrator use to verify the VIP configuration and its associated firewall policy? (Choose two.)
Medium412An administrator needs to configure an SD-WAN rule that routes traffic from the guest VLAN to the Internet using the most cost-effective link. The SD-WAN zone contains three members: port1 (MPLS, cost 10), port2 (Broadband, cost 5), and port3 (LTE, cost 20). All members meet the performance SLA. Which load balancing algorithm should be used to ensure traffic uses the lowest-cost link?
Easy413An administrator configures a firewall policy with an application control profile to block social media. The administrator observes that some social media traffic is still passing through. The traffic is HTTPS. What additional configuration is REQUIRED for application control to effectively block HTTPS-based social media?
Hard414A FortiGate is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the process 'ipsengine' is using the most CPU. What is the most likely cause?
Easy415An administrator needs to monitor FortiGate session count and CPU usage over time using FortiAnalyzer. Which log type should be configured for this?
Easy416A FortiGate is configured with ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing credit card numbers. Which ZTNA inline CASB feature should be used?
Hard417An HA cluster (active-passive) is configured. The administrator wants to perform a failover test without causing service disruption. Which command should be used?
Medium418A FortiGate administrator is configuring an IPsec VPN with IKEv2 and wants to ensure that the tunnel uses perfect forward secrecy (PFS). Which phase2 configuration is required?
Easy419A network administrator is configuring SD-WAN on a FortiGate. The organization has two internet links: MPLS (primary) and broadband (backup). The administrator wants all traffic to use the MPLS link unless it fails, in which case traffic should fail over to the broadband link. Which SD-WAN configuration best achieves this requirement?
Easy420An enterprise uses multiple VDOMs on a FortiGate. The administrator needs to route traffic between VDOM-A and VDOM-B using a firewall policy. What is the correct configuration step?
Medium421A FortiGate administrator runs 'diagnose debug application sslvpn -1' and sees repeated messages: 'SSL VPN tunnel error: no response from client'. What is the most likely cause?
Medium422Which of the following is the primary purpose of BFD (Bidirectional Forwarding Detection) on a FortiGate?
Easy423An administrator configures BFD on a BGP session between two FortiGates. After enabling BFD, the BGP session flaps intermittently. What is the most likely cause?
Hard424An administrator sees the following output from 'get router info routing-table': S 0.0.0.0/0 [10/0] via 192.168.1.1, port1 S 0.0.0.0/0 [10/0] via 192.168.2.1, port2 They have configured ECMP load balancing. However, traffic to a specific destination IP is always using port1. What is the likely reason?
Medium425Which feature in FortiOS enables a FortiGate to act as a proxy for client-initiated connections to internal applications without requiring a VPN client, by verifying device posture and user identity?
Easy426A network admin needs to apply a common set of firewall rules at the beginning of every policy package for all VDOMs managed by FortiManager. The rules should be automatically inserted and not editable within each VDOM. What should be configured?
Medium427An administrator needs to enable automation stitches to automatically block a malicious IP address detected by FortiSandbox. Which two components are required? (Choose two.)
Medium428An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
Hard429A FortiGate administrator is deploying ZTNA with a FortiClient EMS that tags endpoints as 'compliant' or 'non-compliant'. The administrator wants the FortiGate to grant access only to endpoints that FortiClient EMS has tagged as compliant, while still allowing non-compliant endpoints to reach a remediation portal. Which two configuration elements on the FortiGate must be aligned to enforce this?
Hard430A security administrator is configuring a FortiGate to block outbound traffic to known command-and-control (C2) servers. The administrator wants to use a dynamic, cloud-based threat intelligence service that is continuously updated by Fortinet. Which FortiGuard service should be enabled to block traffic based on the latest C2 IP addresses and domains?
Medium431A FortiGate administrator is configuring an ADVPN with a hub-and-spoke topology. The administrator wants to ensure that spoke-to-spoke traffic can be dynamically established without traversing the hub for every packet. The administrator also wants to ensure that the shortcut tunnels are only established when necessary and are torn down when no longer used. Which two statements about ADVPN shortcut tunnels on FortiGate are correct? (Choose two.)
Hard432Which TWO actions are appropriate when troubleshooting a slow network connection through a FortiGate?
Medium433Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per SD-WAN member?
Easy434An administrator is integrating a FortiExtender with a FortiGate. The FortiExtender is connected to port5 and configured with a cellular WAN connection. What must be configured on the FortiGate to allow the FortiExtender to provide WAN connectivity as an SD-WAN member?
Hard435A customer reports intermittent connectivity issues between two internal subnets separated by a FortiGate firewall. The traffic is allowed by the policy, but users experience timeouts during peak hours. Which troubleshooting step should you take first?
Medium436Which FortiGate IPS feature allows administrators to create rules that detect network traffic patterns deviating from normal protocol behavior?
Easy437A company uses FortiMail for email security. They want to prevent email spoofing by verifying that incoming emails originate from authorized servers. Which email authentication method should be configured on FortiMail to check the sending server's IP against a published SPF record?
Medium438A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route for 192.168.100.0/24 into OSPF. After configuring 'config router ospf' with 'redistribute static' enabled, the route appears in the OSPF database but is not being advertised to other areas. What is the most likely cause?
Hard439A FortiGate administrator configures a ZTNA access proxy rule to allow access to an internal application only if the user's device has the tag 'Compliant'. The tag is assigned by FortiClient EMS. However, a user with a compliant device is still blocked. The admin sees in the ZTNA logs that the tag is not being received. What should the administrator check FIRST?
Medium440You run the following command on a FortiGate: 'diagnose vpn ike gateway list' and see that the DPD status for a VPN peer is 'dead'. What does this indicate?
Medium441A FortiGate is configured with a VIP (virtual IP) for an internal web server. Users report that the web server is unreachable from the internet, but it works from the internal network. The administrator runs 'diagnose sniffer packet any "host 203.0.113.10 and port 80" 4' and sees incoming packets on the wan1 interface but no outgoing packets on the internal interface. What is the MOST likely cause?
Hard442A network security team is evaluating options for web application security. They need to protect a critical web application from SQL injection and cross-site scripting (XSS) attacks, and they require granular control over HTTP request parameters. Which THREE factors should influence their decision between using FortiGate's WAF profiles versus deploying a dedicated FortiWeb appliance?
Hard443An administrator runs 'diagnose ips anomaly http' and sees many entries with 'type=SQLi' and 'score=0'. What does a score of 0 indicate?
Hard444An administrator is configuring FortiMail to improve email security. Which three of the following features are part of FortiMail's advanced threat protection? (Choose three.)
Hard445A FortiGate administrator is configuring ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing sensitive data while allowing other operations. Which ZTNA inline CASB configuration is required to achieve this?
Hard446An administrator needs to configure VRF to separate traffic for two departments. Which TWO components must be configured for each VRF?
Medium447Which FortiAnalyzer feature allows an administrator to create a sequence of automated response actions triggered by a specific log event?
Easy448A FortiGate administrator wants to use threat intelligence feeds to block known malicious IP addresses. Which TWO steps are required to accomplish this? (Choose two.)
Medium449An administrator configures two VDOMs as shown in the exhibit. They create an inter-VDOM link between VDOM1 and VDOM2. They then add a firewall policy in VDOM1 allowing traffic from port1 to the inter-VDOM link, and a policy in VDOM2 allowing traffic from the inter-VDOM link to port2. However, traffic from 192.168.1.10 to 10.10.10.50 fails. What is the most likely cause?
Medium450An admin runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?
Hard451A FortiGate administrator is using the built-in FortiGuard web filter to block malicious websites. Users report that they can still access a site that is categorized as 'Malware' by FortiGuard. The administrator verifies that the web filter profile is applied to the policy and that the category is set to block. What is the most likely reason for this issue?
Medium452An administrator configures a WAF profile on FortiGate to protect a web application. However, the administrator notices that SQL injection attacks are not being blocked. What should the administrator check first?
Medium453Which of the following best describes the function of FortiDeceptor in an enterprise network?
Easy454A FortiGate administrator is configuring SSL VPN for remote users. The administrator wants to ensure that users can only access specific internal resources based on their user group. Which SSL VPN configuration mode should be used to provide granular access control?
Easy455A FortiGate is deployed with two ISPs and SD-WAN. The organization uses OSPF to exchange routes with a remote branch. The administrator notices that the FortiGate is not installing OSPF-learned routes into the routing table. The OSPF configuration is verified to be correct, and neighbors are established. Which configuration could be causing the issue?
Hard456An administrator is configuring a FortiGate to block outbound traffic to known malicious IP addresses. They want the block list to be updated automatically from a commercial threat intelligence service that provides a REST API. Which FortiGate feature should be used?
Medium457An administrator is troubleshooting an SD-WAN rule that is not matching traffic as expected. The rule is configured with a source address of 'all', destination '10.0.0.0/24', and service 'HTTP'. The rule is placed after a rule that matches all traffic to '10.0.0.0/24' with service 'ALL'. The administrator notices that HTTP traffic to 10.0.0.0/24 is being handled by the first rule. What is the most likely cause?
Hard458An administrator wants to enforce that only devices with the latest antivirus signatures and a corporate disk encryption solution can access a sensitive application via ZTNA. Which two FortiClient EMS components must be configured? (Choose two.)
Easy459Drag and drop the steps to configure a FortiGate as a DHCP server into the correct order.
Medium460Which Fortinet product is designed specifically to detect and deceive attackers by creating decoy systems and luring them away from real assets?
Easy461An administrator configures a prefix list to filter routes received from a BGP neighbor. The prefix list permits 192.168.0.0/16 le 24. Which routes are permitted?
Medium462A FortiGate administrator is configuring a ZTNA rule to allow access to an internal web application only for users who authenticate with multi-factor authentication (MFA). The administrator has configured the ZTNA rule to require the 'MFA' tag from FortiClient EMS. However, users who have MFA enabled are still being denied access. What is the most likely reason?
Easy463An administrator wants to ensure that FortiGate validates the identity of the remote VPN peer using a certificate during IKEv2 phase 1. Which authentication method should the administrator select in the IPsec phase 1 configuration?
Easy464An administrator needs to ensure that all firewall policies in a FortiGate VDOM have a common set of inspection profiles added at the end of the policy list. Which FortiManager feature best achieves this?
Medium465A network administrator needs to configure SD-WAN on a FortiGate to distribute traffic across two WAN links based on session count. Which load balancing algorithm should be selected in the SD-WAN rule?
Easy466An administrator is configuring ZTNA inline CASB for a SaaS application. The goal is to block upload of files containing credit card numbers. Which configuration components are required?
Hard467A FortiGate is managed by FortiManager. The administrator creates a new policy package for VDOM 'Sales' and installs it. Later, they find that the previous configuration has been overwritten. What should the administrator do to avoid this in the future?
Medium468A network admin needs to configure a FortiGate to load balance traffic across two ISP links using SD-WAN. The requirement is to use both links simultaneously for different sessions based on source-destination IP hash. Which two settings are required? (Select TWO.)
Medium469A FortiGate administrator is troubleshooting an IPsec VPN where Phase 1 completes but Phase 2 fails to establish. The administrator reviews the Phase 2 configuration and notices that the local and remote subnets do not match between the two peers. Which action should the administrator take to resolve the Phase 2 failure?
Medium470An organization uses FortiWeb to protect its web applications. The security team wants to block requests that contain a specific custom pattern in the URL. Which feature should be used?
Medium471A FortiGate is configured with multiple VDOMs. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B. The administrator creates an inter-VDOM link and assigns IP addresses to both ends. Which additional configuration is required to allow traffic to pass between the VDOMs?
Medium472What is the primary purpose of Content Disarm and Reconstruction (CDR) in advanced antivirus protection?
Easy473A BGP peering between two FortiGates is not establishing. The administrator runs 'get router info bgp neighbor' and sees that the neighbor state is 'Idle' and the BGP configuration appears correct. What should the administrator check next?
Hard474During a failover test in an HA cluster, the primary FortiGate fails over to the secondary. After failover, some existing TCP sessions are dropped. What is the MOST likely reason?
Medium475A FortiGate is configured with a VIP (virtual IP) to publish an internal web server to the internet. External users report that they cannot access the web server, but internal users can access it using its private IP. The administrator runs 'diagnose debug flow' and sees that traffic from external users is being dropped with the message 'iprope_in_check() check failed, drop'. What is the most likely cause?
Hard476An organization wants to implement a solution that can detect and automatically respond to threats across multiple Fortinet security products. Which product should they use?
Medium477An administrator has configured FortiSandbox integration with FortiGate. Files are being submitted, but the firewall is not blocking subsequent downloads of files that FortiSandbox later identifies as malicious. The administrator verifies that the FortiSandbox license is valid and the connection is up. Which configuration is most likely missing?
Hard478What is the primary purpose of FortiGuard Outbreak Prevention service?
Easy479A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up but traffic is not passing. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA has been established. However, 'diagnose vpn tunnel list' shows no IPsec SA entries. What is the most likely cause?
Medium480An administrator configures a hub-and-spoke ADVPN with FortiGate at the hub and multiple remote sites. After setup, spokes establish shortcuts directly. However, traffic between two spokes consistently goes through the hub even though shortcuts should exist. Running 'diagnose npu np6 ipsec peercache' shows no shortcut entries. What is the MOST likely reason?
Hard481An organization wants to prevent users from downloading malicious files from the internet. Which FortiGate security profile should be applied to the outbound firewall policy to block files based on their hash if they have been identified as malicious by FortiSandbox?
Easy482A FortiGate is configured with two VRF instances: VRF10 (for the finance department) and VRF20 (for the engineering department). Each VRF has its own routing table and interfaces. The administrator needs to allow a server in VRF10 (10.10.10.10) to communicate with a server in VRF20 (10.20.20.20). The administrator has already configured the necessary firewall policies to allow the traffic. However, pings from 10.10.10.10 to 10.20.20.20 fail. What is the most likely cause?
Hard483An organization uses FortiClient EMS to enforce compliance on endpoints. They want to ensure that only devices with updated antivirus definitions can access the corporate VPN. Which FortiClient configuration should be applied?
Easy484A FortiGate administrator wants to stop outbound DNS queries to a known malicious domain that is not present in any static blocklist. The administrator has already licensed FortiGuard DNS Filtering and enabled DNS filtering on the firewall policy. Which FortiGuard service must the FortiGate resolve the domain against so that the query is blocked based on the latest threat intelligence?
Medium485A network administrator is troubleshooting a scenario where FortiView in FortiAnalyzer shows no traffic data for a specific FortiGate, but logs are being received. Which two possible causes should the administrator investigate? (Choose two.)
Hard486A FortiGate administrator is troubleshooting an issue where IPsec VPN traffic is not being forwarded correctly in a multi-VDOM environment. Which TWO factors should the administrator verify?
Medium487An administrator is configuring an SD-WAN rule to prefer a specific overlay tunnel for VoIP traffic. The rule uses the 'SLA' strategy with a performance SLA that measures jitter and latency. After applying the rule, the administrator notices that VoIP traffic is still being routed over a different member that does not meet the SLA. What is the most likely cause?
Medium488A FortiGate administrator is troubleshooting why a custom IPS signature is not triggering on traffic matching the pattern. Which TWO checks should be performed?
Hard489A multinational company uses FortiGate devices as VPN gateways to connect its headquarters (HQ) and branch offices via IPsec VPN tunnels. The company is migrating its remote access solution from IPsec VPN to SSL VPN using FortiClient. Currently, 500 remote users connect via IPsec VPN with pre-shared keys and XAuth authentication. The migration must be seamless with minimal downtime, and users must continue to authenticate using their existing Active Directory credentials. The SSL VPN portal must provide access to internal web applications and some legacy TCP-based applications that do not support HTTP. The security team requires that all traffic between remote users and the internal network be encrypted and that the SSL VPN use a certificate from a public CA to avoid certificate warnings on client devices. The IT team wants to use FortiToken for two-factor authentication (2FA) for all VPN users. Which of the following is the most appropriate course of action to meet all requirements?
Easy490A FortiGate is configured with multiple VDOMs. The administrator needs to provide a network engineer with read-only access to all VDOMs, but the engineer should not be able to make any configuration changes. Which administrative profile configuration should the administrator use?
Medium491A FortiGate admin sees the following log: 'Action=blocked, Service=HTTP, Application=Outbreak, File=invoice.doc, ThreatScore=95'. What is the MOST likely explanation for this block?
Hard492An administrator needs to back up the configuration of a FortiGate managed by FortiManager before making major changes. Which feature in FortiManager should the administrator use?
Easy493Which Fortinet product is designed to deploy decoy systems to lure attackers and detect lateral movement within the network?
Easy494An administrator runs 'diagnose sys session list' and sees sessions with 'proto=6 proto_state=02' and a long duration. The administrator is troubleshooting why sessions are not being terminated after a policy change that should block the traffic. What does 'proto_state=02' indicate?
Hard495An administrator wants to create an automation stitch that sends a webhook notification when an IPS attack is detected. Which trigger and action should be used?
Medium496A FortiGate 600E is running in multi-VDOM mode and is managed by FortiManager. The administrator needs to assign CPU and memory resource limits to a specific VDOM so that it cannot consume more than 30% of the system's resources. Which FortiGate feature should the administrator configure?
Medium497You run 'diagnose sys session filter dport 179' on a FortiGate and see many sessions with proto=6 and proto_state=01. What does this indicate about the BGP sessions?
Hard498Which FortiGate feature is used to detect link failures within milliseconds, allowing rapid convergence for routing protocols like OSPF and BGP?
Easy499An administrator notices that a FortiGate's CPU is consistently high, and the performance dashboard shows the 'ipsengine' process consuming most CPU. The administrator suspects a specific traffic pattern is overwhelming the IPS engine. Which CLI command should be used to identify the top sessions by bandwidth that may be triggering the IPS engine?
Medium500Refer to the exhibit. A user reports that accessing a legitimate HTTPS website is blocked. The FortiGate logs show that the connection was denied by the antivirus profile. What is the most likely cause?
Medium501An administrator is configuring FortiClient EMS to enforce compliance for ZTNA. Which TWO settings are required on FortiGate to use compliance-based ZTNA tags?
Medium502A FortiGate administrator is configuring a ZTNA rule that uses a proxy-based policy to inspect traffic to a web application. The administrator wants to ensure that only users who have a valid certificate installed on their endpoint are allowed access. The certificate is issued by the corporate PKI and is stored in the user's certificate store. Which ZTNA configuration element should the administrator use to enforce this requirement?
Hard503Which FortiGate security feature removes potentially malicious active content from files (e.g., macros, scripts) before delivering them to end users?
Easy504Which routing protocol is commonly used in SD-WAN deployments to exchange routes between FortiGate and the provider edge router in an MPLS network?
Easy505What is the role of FortiGuard Outbreak Prevention in FortiGate's security suite?
Easy506A FortiGate admin configures a firewall policy with an antivirus profile in flow-based inspection mode. The admin notices that some large files are being scanned but others are allowed without scanning. What is the most likely cause?
Hard507A FortiGate is configured with an IPsec VPN tunnel to a remote peer. The tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. The administrator then runs 'diagnose debug flow' and sees that traffic is being dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause of the drop?
Hard508An administrator is configuring a FortiGate in multi-VDOM mode. The administrator wants to assign a physical interface to a non-management VDOM. The interface currently belongs to the root VDOM and has an IP address. What must the administrator do first?
Medium509An administrator configures an automation stitch to respond to a high severity event. The trigger is 'event' and the action is 'CLI script'. What must be defined for the action to execute properly?
Medium510A FortiGate administrator is investigating a slow network issue. The 'diagnose sys session stat' shows a high number of sessions. Which THREE commands can help identify the source of the high session count?
Hard511A FortiGate is configured with a VIP (virtual IP) for an internal web server at 10.0.0.10, mapping to public IP 203.0.113.5. External users report that they cannot access the web server, but internal users can access it using the private IP. The administrator runs 'diagnose debug flow filter addr 203.0.113.5' and 'diagnose debug flow show function-name enable' and sees the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 203.0.113.5:443->198.51.100.10:54321) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-10.0.0.10 via port2"'. No further output appears. What is the MOST likely cause of the issue?
Hard512Which feature allows a FortiGate to participate in multiple routing tables simultaneously, enabling network segmentation and overlapping IP address spaces?
Easy513An administrator needs to view real-time traffic logs and top applications for a specific VDOM on FortiAnalyzer. Which tool should be used?
Easy514A company uses an advanced antivirus profile with machine learning engine enabled. After a recent outbreak, several files that were previously undetected are now flagged. How does the outbreak prevention feature help in this situation?
Hard515An administrator is troubleshooting why a FortiGate is dropping traffic from a specific source IP (10.1.1.100). The administrator wants to see real-time per-packet details including the reason for drops. Which CLI command should the administrator use?
Medium516A FortiGate 600E is deployed with multiple VDOMs in NAT/route mode. The administrator assigns VLAN 100 to VDOM-A on port1 and VLAN 200 to VDOM-B on port1, then configures the VLAN interfaces as management interfaces for each VDOM. Users in VDOM-A report intermittent connectivity to servers in VDOM-B, while pings between the VLAN interface IPs fail. What is the most likely cause?
Medium517An organization wants to use FortiManager to manage multiple FortiGate devices. The administrator needs to ensure that each device group has separate policy and object configurations. Which FortiManager feature should be configured?
Medium518What is the purpose of a management VDOM on a FortiGate?
Easy519A FortiGate administrator is configuring an IPsec VPN with multiple peers for redundancy. The administrator wants to ensure that if the primary peer becomes unreachable, the tunnel fails over to the secondary peer automatically. Which configuration is required to achieve this?
Medium520A company's FortiGate is configured with multiple IPsec VPN tunnels to branch offices. One tunnel keeps dropping and re-establishing every few minutes. The logs show 'IPsec SA negotiation failed' with error 'proposal mismatch'. What is the most likely cause?
Medium521An administrator sees the following error when trying to commit changes from FortiManager to a FortiGate: 'Policy check failed: Policy ID 5 uses a zone that does not exist on the device.' What is the most likely cause?
Medium522An administrator wants to secure email traffic by ensuring that incoming emails are verified against the sender's domain SPF record. Which email authentication method provides this verification?
Easy523An administrator is troubleshooting SD-WAN and runs the following CLI command: 'execute sdwan-health-check status' The output shows that one SD-WAN member has a status of 'dead'. What does this indicate?
Medium524An administrator is configuring FortiAnalyzer to receive logs from FortiGates in a multi-VDOM environment. The admin wants to ensure that logs from each VDOM are separated into their own datasets. What must be configured?
Hard525Which FortiManager feature allows administrators to view the exact configuration changes that would be applied to a managed FortiGate before committing them?
Easy526A security administrator is deploying FortiDeceptor in a data center network. They want to detect an attacker who is performing internal reconnaissance by scanning the subnet for live hosts. Which FortiDeceptor component should the administrator deploy to generate a decoy IP address that responds to such scans and alerts on any interaction?
Medium527An administrator is configuring SSL VPN on FortiGate and wants to allow users to access internal applications via a web portal without installing any client software. Which SSL VPN mode should be used?
Easy528A network administrator is troubleshooting an SD-WAN setup where a specific application is not using the intended overlay tunnel. The SD-WAN rule is configured with a destination of 'all' and a source of 'all', and the strategy is set to 'manual' with the overlay tunnel as the preferred member. However, traffic is still going out via the underlay. What is the most likely reason?
Medium529A FortiGate admin notices that sessions to a particular server are not being logged in FortiAnalyzer. The firewall policy has logging enabled. What is the MOST likely reason?
Medium530An administrator needs to generate a report showing top applications by bandwidth usage across all VDOMs for the last 30 days. Which FortiAnalyzer feature should be used?
Medium531An administrator wants to see the current sessions for a specific source IP address 192.168.1.10. Which CLI command should be used?
Easy532A FortiGate administrator is configuring an antivirus profile to protect against unknown malware. The administrator wants to use machine learning to detect malicious files based on their behavior and characteristics without relying solely on signatures. Which antivirus feature should be enabled to meet this requirement?
Easy533An administrator deploys ZTNA with FortiGate as the access proxy for internal web applications. Users authenticate through FortiClient EMS, and device posture checks must be enforced before access is granted. A user with a compliant laptop can reach the application, but when the same user connects from a personal device that fails the posture check, the connection is still allowed. The administrator verifies the ZTNA rule is enabled and the EMS connector is up. Which configuration element is most likely missing to enforce device posture?
Medium534Which feature in FortiMail provides an additional layer of protection by analyzing the behavior of email attachments in a sandbox environment?
Easy535A security administrator wants to generate a weekly report in FortiAnalyzer that shows the top threats detected by the FortiGate. Which feature should the administrator use to create this report?
Medium536An administrator is configuring an SD-WAN rule that uses the 'volume' load balancing algorithm. The rule includes two members: port1 with a volume ratio of 3, and port2 with a volume ratio of 1. Which two statements correctly describe how the FortiGate will distribute sessions? (Choose two.)
Medium537A FortiGate administrator is setting up a ZTNA environment where FortiClient EMS is used to tag endpoints. The administrator wants to create a firewall policy that allows access to a web application only for users whose endpoints have the tag 'Compliant'. Which configuration step is required to use the tag in the firewall policy?
Easy538An administrator wants to integrate a FortiExtender into an existing SD-WAN deployment. Which TWO steps are required for proper integration?
Medium539What is the purpose of a management VDOM in a multi-VDOM FortiGate deployment?
Easy540A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE gateway is stuck in the 'connecting' state. The administrator confirms that the pre-shared key matches on both peers. Which action should the administrator take next to identify the cause?
Medium541An administrator has an SD-WAN deployment with two members, port1 (primary, low latency) and port2 (secondary, high latency). A performance SLA is configured using a ping probe to 8.8.8.8 with a 100 ms latency threshold. The SLA status for port1 is 'alive' and for port2 is 'dead'. The administrator creates an SD-WAN rule with the 'SLA' strategy that includes both members. They expect traffic to use port1 and, if it fails, port2. However, after applying the rule, all traffic is still going out port1 and never uses port2. What is the cause of this behavior?
Medium542A FortiGate administrator is troubleshooting an IPsec VPN that uses IKEv2 and certificate authentication. The tunnel fails to establish, and the administrator sees that the phase 1 negotiation reaches the point of exchanging certificates but then fails. The administrator wants to verify the certificate-related configuration. Which two actions should the administrator take to resolve the issue? (Choose two.)
Hard543Which THREE conditions must be met for an IPsec VPN to successfully establish phase2?
Medium544A company uses FortiGate ZTNA to provide remote access to an internal web application. The application requires client certificates for authentication. The administrator has configured the ZTNA rule to use certificate authentication. However, users report that they are prompted for credentials repeatedly. What is the most likely cause?
Medium545What is the function of a route map in FortiGate routing?
Easy546An administrator is configuring a FortiGate to detect and block command and control (C2) traffic using FortiGuard's Indicator of Compromise (IoC) service. The administrator wants to ensure that the firewall checks DNS queries and HTTP requests against the IoC database. Which feature should be enabled on the FortiGate to accomplish this?
Medium547A FortiGate is configured with an SSL inspection profile that uses a deep-inspection mode. Users complain that a banking website fails to load, but HTTP sites work. The administrator confirms the site uses TLS 1.3 with Encrypted Client Hello (ECH) and certificate pinning. Which action should the administrator take to restore access while maintaining visibility for other traffic?
Hard548An administrator configures FortiGate as a SAML identity provider (IdP) for a cloud application. The application (SP) initiates the login. Users are redirected to the FortiGate login page and authenticate successfully, but then receive an error from the SP. What is a common cause?
Medium549An administrator configures a custom IPS signature to detect traffic to a specific malicious domain. Which syntax is correct for a custom IPS signature in FortiGate?
Hard550An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The Phase 1 status shows 'init' and the debug output indicates 'no suitable proposal found'. The remote peer is a third-party VPN device. Which of the following is the MOST likely cause?
Hard551In a multi-VDOM deployment, an administrator needs to route traffic between VDOM-A and VDOM-B. The administrator creates a VDOM link between the two VDOMs. What additional configuration is required on each VDOM to enable inter-VDOM traffic?
Medium552An administrator has deployed a FortiGate in an SD-WAN hub-and-spoke topology. Spoke sites use IPsec tunnels to the hub, and the hub advertises a default route to the spokes. The administrator wants traffic from any spoke to another spoke to flow through the hub without requiring additional tunnels between spokes. Which SD-WAN feature should be configured on the hub to achieve this?
Medium553What is the purpose of a global ADOM in FortiManager?
Easy554A FortiGate is deployed in multi-VDOM mode. The administrator has created VDOM-A and VDOM-B, and configured an inter-VDOM link between them. Users in VDOM-A need to access a web server in VDOM-B. The administrator has added a static route in VDOM-A for the server's subnet pointing to the VDOM link interface, and a return route in VDOM-B. Which TWO additional configurations are required to allow the traffic? (Choose two.)
Hard555In a multi-VDOM deployment, inter-VDOM routing is configured using VDOM links. After configuring the VDOM links and adding static routes, traffic between VDOMs is not working. The administrator verifies that the VDOM link interfaces are up and have correct IP addresses. What is the most likely missing configuration?
Hard556An administrator wants to verify which SD-WAN member is currently being used for a specific traffic flow. Which command should they use on the FortiGate?
Easy557An administrator is investigating a security incident and needs to determine which firewall policy allowed a specific malicious traffic flow. The traffic is no longer active. Which FortiAnalyzer log type should the admin query?
Hard558An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that the 'Management' VDOM can be accessed via HTTPS and SSH from the internal network, while other VDOMs should not have management access enabled on their interfaces. Which TWO actions must the administrator perform? (Choose two.)
Medium559A FortiGate administrator is planning to deploy VDOMs to separate customer traffic. The administrator wants to use FortiManager for centralized management. Which TWO prerequisites must be met before the VDOMs can be managed from FortiManager?
Easy560An administrator wants to monitor CPU usage of specific processes on a FortiGate. Which command should be used?
Easy561A FortiGate with two WAN interfaces configured in an SD-WAN setup uses the 'lowest-cost' load balancing algorithm. The performance SLA monitors latency and jitter. If wan1 has a cost of 10 and wan2 has a cost of 20, but wan1 is experiencing 50% packet loss, what will happen to traffic?
Hard562What is the function of FortiAnalyzer in a Fortinet Security Fabric?
Easy563A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The VPN tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. Which two commands should the administrator use to further troubleshoot why traffic is not passing through the tunnel? (Choose two.)
Hard564A FortiGate has two WAN interfaces (port1, port2) as SD-WAN members. The performance SLA monitor is configured for both with a latency threshold of 50 ms. The measured latency on port1 is 45 ms and on port2 is 55 ms. An SD-WAN rule uses 'lowest-cost' algorithm. Which interface will be selected for new sessions?
Hard565A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route (192.168.100.0/24) into OSPF area 0. The route is configured as a static route on the FortiGate. Which configuration step is essential to ensure the static route is redistributed into OSPF?
Hard566A company uses FortiManager to manage multiple FortiGate firewalls. After making changes to a policy package, the administrator runs an install preview and sees a warning: 'Policy ID 10 will be deleted on device XYZ'. What is the most likely reason for this warning?
Medium567A FortiGate administrator configures inter-VDOM routing. Traffic from VDOM-A to VDOM-B is blocked. The administrator checks the policy in VDOM-A allowing traffic to the VDOM link interface. What else must be verified?
Medium568An administrator runs 'diagnose debug application ipsmonitor -1' and sees repeated messages: 'IPS engine restarting'. What is the MOST likely cause of this behavior?
Medium569An administrator is configuring an SD-WAN rule to route VoIP traffic (identified by application 'VoIP') over the best available link. The SD-WAN zone 'virtual-wan-link' contains three members: port1 (cost 10), port2 (cost 20), and port3 (cost 30). A performance SLA named 'VoIP-SLA' is applied to the rule, monitoring latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest latency that meets the SLA. Which SD-WAN algorithm should be used?
Hard570A FortiGate administrator is investigating a security incident and needs to identify which user initiated a specific outbound connection to a malicious IP address. The company uses FSSO for authentication. Which THREE pieces of information from FortiAnalyzer logs would be MOST useful? (Choose three.)
Medium571An administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA state is 'UP' but the IPsec SA state is 'DOWN'. The remote peer is a FortiGate. What is the most likely cause of this issue?
Hard572A security analyst is reviewing logs from a FortiGate that uses FortiGuard IPS. The analyst notices that a signature for a recent Apache Struts vulnerability is not triggering even though the vulnerable service is exposed. The FortiGate is running the latest IPS engine and signature database. Which action should the analyst take to verify whether the signature is enabled and properly applied to the traffic?
Hard573A network administrator is configuring SD-WAN rules with load balancing. They want to distribute HTTP traffic evenly across two WAN links based on the number of sessions. Which TWO settings should they use? (Choose two.)
Medium574A FortiGate administrator is configuring an IPsec VPN with IKEv2. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) for phase 2. Which parameter must be configured in the phase 2 proposal?
Medium575A FortiGate has an SD-WAN rule with two members: port1 and port2. The rule uses the 'lowest-cost' algorithm. The administrator configures a performance SLA that monitors latency to a remote server. The SLA is applied to both members. After some time, port1's latency exceeds the SLA threshold and its status becomes 'dead'. What happens to new sessions that match the SD-WAN rule?
Hard576In a multi-VDOM deployment, what is the purpose of inter-VDOM routing?
Easy577During a BGP troubleshooting session, an administrator sees that the BGP neighbor state is 'Active'. Which three conditions could cause this state? (Choose THREE.)
Hard578An administrator wants to ensure that all traffic from a specific LAN subnet (192.168.10.0/24) to the internet uses a particular WAN interface (wan1) in an SD-WAN setup, while other traffic uses wan2. What is the correct configuration to achieve this?
Medium579An administrator has configured a FortiGate with two VRF instances: VRF10 and VRF20. They need to allow a server in VRF10 (10.10.10.0/24) to communicate with a server in VRF20 (10.20.20.0/24). The administrator creates a firewall policy with source interface VRF10 and destination interface VRF20, but traffic is not passing. What is the most likely cause?
Hard580An administrator configures FortiManager automation stitches to respond to high CPU usage on a FortiGate. The stitch should trigger a script to run diagnostics. Which THREE components are required in an automation stitch?
Hard581A FortiGate administrator wants to verify whether a specific session is being offloaded to the NP6 processor. Which CLI command should the administrator use?
Easy582Which FortiGate feature allows multiple independent routing tables on a single device, enabling traffic separation for different departments or customers?
Easy583A network administrator is configuring SD-WAN on a FortiGate and wants to ensure that VoIP traffic uses the link with the lowest latency while bulk download traffic uses the link with the highest bandwidth. Which TWO configuration steps are required?
Medium584A FortiGate is receiving BGP routes from a neighbor but not advertising them to other peers. The administrator runs 'get router info bgp network' and sees the routes are in the BGP table but not advertised. What is the most likely cause?
Medium585An administrator is deploying ZTNA for a legacy application that uses a fixed IP address and port. Which ZTNA component is responsible for securely proxying traffic from the user to the application without exposing the application's actual network location?
Medium586A FortiGate has two WAN interfaces configured as SD-WAN members. The administrator wants traffic to specific destination IP addresses to use a particular member. Which SD-WAN configuration object should be used to achieve this?
Medium587Drag and drop the steps to configure a FortiGate to use an external authentication server (e.g., RADIUS) for admin login into the correct order.
Medium588An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator wants to identify which processes are consuming the most CPU. Which command should be used?
Easy589Which THREE statements are true about FortiGate SD-WAN health-check configuration?
Medium590You receive an alert that FortiAnalyzer log disk usage is at 95%. Which action should you take to immediately free up space without losing important logs?
Easy591Which FortiGate security feature can reconstruct files to remove potentially malicious content while preserving the file's usability?
Easy592An administrator is building an ADVPN with a single hub and many spokes. Spokes are behind NAT devices and receive dynamic public IP addresses. The administrator wants shortcuts to form directly between spokes without routing traffic through the hub. Which combination of features must be configured on the hub and spokes to allow shortcut negotiation to succeed in this environment?
Hard593A network engineer is deploying a FortiGate in transparent mode at a branch office. The goal is to insert the firewall without changing the existing IP subnet scheme. Which statement about transparent mode is TRUE?
Easy594An administrator is configuring FortiMail to be more secure against advanced email threats. Which THREE features should they enable to protect against email-based phishing attacks?
Easy595A security analyst is investigating alerts from FortiGate's IPS. They notice that an attack was detected but not blocked, even though the IPS profile is set to block. The log shows the action as 'detected'. What is the most likely reason for this behavior?
Medium596An administrator configures OSPF on a FortiGate with multiple areas. After configuration, the FortiGate does not become an ABR. What is the most likely reason?
Hard597Which load balancing algorithm in SD-WAN sends new sessions to the member interface with the least number of active sessions?
Easy598An administrator wants to verify that a BGP route is being advertised to a neighbor. Which command displays the routes that FortiGate is advertising to a specific BGP neighbor?
Easy599Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per interface?
Easy600A network administrator notices that several endpoints are infected with ransomware despite having FortiGate ATP enabled. The logs show that the files were downloaded over HTTPS, and the antivirus profile did not detect them. What is the most likely reason?
Medium601A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?
Medium602An administrator is configuring a FortiGate in transparent mode for a data center segment. Which of the following is true about transparent mode operation in an enterprise environment?
Medium603A network administrator notices that FortiGate is not blocking a known malicious file that was submitted to FortiSandbox and received a 'malicious' verdict. The firewall policy includes a FortiSandbox inline scan profile. What is the MOST likely cause?
Medium604An administrator is configuring a FortiGate to use the external threat feed feature to block traffic from known malicious IP addresses. They want to ensure that the feed is automatically updated and that the firewall blocks traffic based on the feed. Which two actions must the administrator perform? (Choose two.)
Hard605What is the primary function of FortiDeceptor in a network security architecture?
Easy606An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?
Medium607A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?
Medium608A FortiGate is configured with a site-to-site IPsec VPN to a remote office. Users at the remote office report that they cannot access resources at the main office. The administrator checks the VPN status and sees that the tunnel is up. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)
Hard609An administrator configures ZTNA with FortiClient EMS. The goal is to restrict access to an internal application based on device posture. The administrator configures a ZTNA tag for 'Compliant' that checks antivirus and OS patch status. Which TWO additional steps are required on the FortiGate to enforce access based on this tag?
Hard610A FortiGate 600F is running in multi-VDOM mode with VDOMs named 'root', 'finance', and 'guest'. The administrator notices that a firewall policy created in the 'finance' VDOM does not appear when logging into the 'guest' VDOM and wants to confirm that policies, address objects, and routing tables are kept completely separate per VDOM. Which FortiGate feature provides this separation by default?
Medium611A FortiGate administrator is implementing Zero Trust Network Access using ZTNA tags from FortiClient EMS to control access to internal applications. The administrator must ensure that devices losing compliance are denied access and that only managed endpoints can reach the applications. Which two configuration actions are required to meet these goals? (Choose two.)
Hard612An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which two actions should the administrator take to further diagnose and potentially resolve the issue? (Choose two.)
Hard613A FortiGate administrator uses FortiAnalyzer for log analysis and wants to identify all sessions that were blocked by a specific firewall policy ID 10. Which log filter should be applied?
Medium614Which SD-WAN load balancing algorithm distributes new sessions based on the number of active sessions on each link?
Easy615Drag and drop the steps to configure a FortiGate as a DNS server (DNS proxy) into the correct order.
Medium616An admin wants to ensure that office documents (e.g., Word, Excel) downloaded from the internet are safe before users open them. Which feature should be used to remove potentially malicious macros and active content?
Medium617You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?
Medium618A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing an internal web application. The administrator wants to ensure that only users who have authenticated and whose devices meet posture requirements can reach the application, and that the application itself is never directly exposed to the internet. Which two FortiGate configuration steps are required to achieve this? (Choose two.)
Medium619An administrator wants to use FortiManager to manage multiple FortiGates, each in a separate customer environment. The administrator needs to isolate configuration changes per customer and ensure each customer's admin can only see their own devices. What FortiManager feature should be used?
Medium620A FortiGate with FortiExtender is using LTE as a backup WAN link. When the primary link fails, the LTE link does not take over. What could be the cause?
Hard621A FortiGate administrator is configuring a ZTNA rule to protect an internal web server. The administrator wants to ensure that only users who authenticate via SAML and whose devices have the latest antivirus signature are allowed access. Which FortiGate feature must be used to enforce this?
Medium622What is the purpose of FortiDeceptor in an enterprise security architecture?
Easy623A FortiGate administrator is configuring a web filter profile to block access to known malicious websites. The administrator wants to ensure that the firewall blocks sites based on FortiGuard category 'Malicious Websites' and also logs the blocked attempts. Which action should the administrator take?
Medium624An administrator configures SD-WAN with two members (wan1, wan2) and a performance SLA for ICMP to 1.1.1.1. The SD-WAN rule is set to 'Best Quality' with 'latency' metric. The admin notices that traffic sometimes switches to the other link even when the current link has acceptable latency. Which action can reduce unnecessary flapping?
Medium625An admin receives an email from FortiMail regarding a message that was rejected due to SPF failure. What does this indicate about the email?
Medium626An administrator is troubleshooting a FortiGate that is dropping traffic from a specific VLAN. The administrator runs 'diagnose debug flow' with a filter for the VLAN's subnet and sees the trace terminate with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?
Hard627What is the primary benefit of using FortiClient with ATP features in conjunction with FortiGate?
Easy628An administrator wants to detect lateral movement and early stages of an attack using decoy systems that mimic production assets. Which Fortinet product should they deploy?
Medium629A company uses FortiWeb to protect its web application. They want to block SQL injection attempts. Which FortiWeb feature should be configured to inspect HTTP requests for malicious SQL patterns?
Hard630An administrator is configuring FortiDeceptor to detect threats within the network. Which TWO statements about FortiDeceptor are correct?
Medium631A FortiGate administrator is troubleshooting a scenario where traffic between two VDOMs is not working. The admin has configured inter-VDOM routing. Which TWO steps should the administrator verify? (Choose two.)
Medium632A FortiGate is configured with OSPF multi-area. The administrator wants to ensure that routes from area 0 are redistributed into area 1. Which OSPF configuration is required?
Easy633A FortiGate is configured with SD-WAN and multiple members. The administrator notices that traffic to a critical application is consistently routed over a low-quality link, even though a better link is available. The SD-WAN rule uses the 'Best Quality' strategy with a performance SLA. What is the most likely reason?
Medium634In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?
Easy635A company wants to ensure that only company-managed laptops with up-to-date antivirus can access the internal file server remotely. Which Fortinet solution integrates with FortiGate to enforce device compliance before granting ZTNA access?
Easy636An administrator is deploying a FortiGate in transparent mode to seamlessly integrate into an existing network. The administrator needs to manage the FortiGate remotely over the network. Which configuration is required?
Medium637A company has deployed FortiClient with advanced threat protection (ATP) features. Which TWO capabilities does FortiClient ATP provide beyond basic antivirus?
Medium638An administrator is setting up a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own set of administrators and that administrators of one VDOM cannot view or modify settings in another VDOM. Which feature should the administrator configure to achieve this?
Easy639An admin wants to block malicious files detected by FortiSandbox at the FortiGate level. Which configuration is required on the FortiGate to automatically block files based on FortiSandbox verdict?
Medium640In FortiManager, what is the purpose of an automation stitch?
Hard641Which FortiClient feature is specifically designed to prevent the execution of unknown malware by analyzing behavior in real-time?
Easy642An administrator wants to protect against zero-day malware that has not yet been discovered by signature-based detection. Which TWO technologies can help mitigate such threats?
Medium643A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?
Hard644A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?
Hard645A FortiGate administrator is configuring ZTNA to protect an internal application and wants to ensure that only users who authenticate with a valid client certificate and whose devices pass posture checks can connect. The administrator has configured FortiClient EMS integration and a ZTNA access proxy rule. During testing, users without client certificates are still able to reach the application after providing username and password. Which setting should the administrator verify to enforce certificate-based authentication?
Medium646An administrator wants to use FortiManager to push a new firewall policy to a managed FortiGate. Before installing, the administrator wants to review what changes will be applied. Which FortiManager feature should be used?
Easy647An administrator is troubleshooting a FortiGate that is experiencing intermittent packet loss for traffic passing through an IPsec VPN tunnel. The administrator wants to capture packets on the VPN interface to analyze the issue. Which command should the administrator use to capture packets on the IPsec tunnel interface named 'vpn1'?
Hard648An administrator runs the following CLI output: 'diagnose sys session filter dport 443' and sees 'proto=6 proto_state=01 duration=3600 expire=3599'. Which statement BEST describes the session?
Hard649An administrator has configured an SD-WAN rule with the 'lowest-cost' strategy. The rule includes two members: port1 and port2. The administrator notices that all traffic is being sent over port1, even though port2 has a lower latency. Which factor is most likely causing this behavior?
Medium650An administrator has a FortiGate 600E running multiple VDOMs. The administrator wants to ensure that when a VDOM is deleted, all associated firewall policies, addresses, and routes are also removed to avoid orphaned objects. Which action should the administrator take?
Medium651A FortiGate is configured with two WAN interfaces in an SD-WAN zone. The administrator wants to ensure that Voice over IP (VoIP) traffic uses the link with the lowest latency, while all other traffic uses the link with the highest available bandwidth. The performance SLA 'VoIP_SLA' monitors latency to a VoIP provider. Which SD-WAN configuration should the administrator implement to meet these requirements?
Medium652A FortiGate administrator is implementing ZTNA to control access to internal web applications. The administrator wants to ensure that only devices with a valid FortiClient EMS tag can access the applications. Which ZTNA component must be configured on the FortiGate to enforce this?
Hard653An administrator has a FortiGate with multiple VDOMs in NAT mode. The administrator wants to configure a global policy that applies to all VDOMs to block traffic from a known malicious IP block. Which statement is correct about global policies?
Medium654A FortiGate administrator is deploying a multi-VDOM setup for a service provider. The provider wants each customer VDOM to have its own administrative access, yet the overall device management (including firmware upgrades) should be centralized from the management VDOM. Which TWO statements are true regarding administrative VDOMs?
Medium655A FortiGate is deployed in multi-VDOM mode with two VDOMs: VDOM-1 and VDOM-2. The administrator needs to enable communication between these VDOMs using a VDOM link. Which TWO statements about VDOM link configuration are correct? (Choose two.)
Hard656What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?
Easy657A network admin runs 'diagnose sys top' on a FortiGate and sees that the process 'httpsd' is consistently using 95% CPU. Which of the following actions is MOST appropriate to troubleshoot this issue?
Medium658A FortiGate administrator wants to implement Content Disarm and Reconstruction (CDR) for email attachments. Which security profile must be configured to enable CDR?
Medium659An admin configures a FortiManager ADOM for a customer with multiple FortiGates. The admin wants to use meta fields to group firewalls by location. After defining a meta field 'Location' and assigning values to devices, where can the admin use the meta field for policy targeting?
Hard660An administrator wants to monitor real-time CPU usage per process on a FortiGate. Which command should be used?
Easy661A FortiGate administrator is troubleshooting an IKEv2 VPN tunnel that fails to establish. The remote peer logs show 'no acceptable proposal' error. Which TWO possible causes should the administrator check?
Medium662An administrator is configuring SD-WAN and wants to ensure that voice traffic uses the lowest latency link. Which two configurations are required to achieve this? (Choose TWO.)
Medium663An administrator wants to create a separate virtual firewall instance on a FortiGate to isolate a DMZ environment. The DMZ must have its own routing table, firewall policies, and administrators. Which FortiGate feature should be used?
Easy664A FortiGate has two equal-cost paths to a destination network. ECMP is enabled. The administrator notices that all traffic uses the first path. What is the most likely cause?
Hard665An IPS administrator wants to detect a new custom attack that sends malformed HTTP headers. The attack pattern is a specific sequence of bytes that is not covered by existing signatures. What is the BEST way to detect this attack on FortiGate?
Medium666A FortiGate with SD-WAN enabled uses two members: MPLS (10 ms latency) and Internet (40 ms latency). The SD-WAN rule uses 'Best Quality' strategy with latency as the metric. Traffic to a critical application (10.1.1.0/24) is currently using the MPLS link. The MPLS link's latency increases to 60 ms due to a routing issue. How will FortiGate handle new sessions to 10.1.1.0/24?
Medium667An administrator is planning a multi-VDOM deployment with a management VDOM. Which TWO statements about management VDOMs are correct? (Choose two.)
Medium668An administrator configures a FortiGate in transparent mode for a VDOM. After switching to transparent mode, the administrator notices that the default route disappears and traffic fails. What must be configured to restore routing?
Medium669A FortiGate administrator is configuring a route-based IPsec VPN to a cloud provider. The provider requires that only traffic for the 10.20.0.0/16 network be sent through the tunnel, and that the FortiGate present a specific local subnet of 192.168.10.0/24 as its source. The administrator wants to avoid policy-based VPN configuration. Which configuration approach correctly defines the traffic selectors for this route-based tunnel?
Easy670A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator has created a VDOM link between VDOM-1 and VDOM-2 and assigned IP addresses to both ends. A server in VDOM-1 (10.1.1.10/24) needs to reach a server in VDOM-2 (10.2.2.10/24). The administrator has added a static route in VDOM-1 for 10.2.2.0/24 pointing to the VDOM-2 link interface IP, and a static route in VDOM-2 for 10.1.1.0/24 pointing to the VDOM-1 link interface IP. However, traffic is not passing. Which additional configuration is required on the FortiGate to allow the traffic to flow?
Medium671A FortiGate is configured as a ZTNA proxy for a web application. Users report that after authenticating, they receive a '502 Bad Gateway' error. What is the most likely cause?
Easy672A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. The administrator then runs 'diagnose debug flow filter addr 10.1.1.1' (the remote subnet) and 'diagnose debug flow show function-name enable', and observes the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 10.1.1.1:80->192.168.1.100:12345) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-192.168.1.1 via port2"'. No further output appears. What is the MOST likely cause of the issue?
Hard673An email security administrator wants to prevent attackers from spoofing the company's domain. Which email authentication mechanism should be configured to allow receiving servers to verify that emails claiming to be from the domain are sent from authorized mail servers?
Medium674An administrator has configured an SD-WAN zone named 'virtual-wan' containing two members: port1 and port2. They want to apply different SD-WAN rules based on the destination IP address. Which FortiGate configuration object should they use to define the destination IP address for matching traffic in an SD-WAN rule?
Medium675A FortiGate administrator configures a custom IPS signature with the pattern 'attack' in the HTTP request URI. After applying the signature, no alerts are generated even though the traffic matches. What is the MOST likely cause?
Hard676An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)
Medium677An administrator receives an error when trying to create a ZTNA proxy rule: 'The ZTNA proxy rule requires a valid application mapping.' What does this indicate?
Medium678A company is implementing Zero Trust Network Access using Fortinet's ZTNA solution. They have deployed a FortiGate as the ZTNA gateway and are using FortiClient as the ZTNA agent. Users report that they can initiate ZTNA connections but the connections drop after a few minutes. The FortiGate logs show that the ZTNA session is being terminated due to a endpoint compliance check failure. Which action should the administrator take to resolve this issue?
Medium679A FortiGate cluster (A-P) has a session that is not synchronizing to the secondary unit. The administrator runs 'diagnose sys ha session-sync status' and sees that the session count is different between primary and secondary. Which is the most likely cause?
Hard680A FortiGate administrator has configured a firewall policy with a web filter profile that uses a FortiGuard category action to block 'Malware' websites. Users report that they can still access some known malicious sites that are categorized as 'Malware'. The administrator verifies that the FortiGuard service is reachable and the license is valid. What is the most likely cause?
Medium681A FortiGate administrator wants to quickly identify which process is consuming the most CPU on the device. Which CLI command should be used?
Easy682A FortiGate in an HA cluster with VDOMs enabled experiences a failover. After the failover, traffic that was passing before is now being dropped. The configuration is synchronized between the primary and secondary units. What is the most likely reason?
Hard683An administrator configures a VDOM link between VDOMs A and B. In VDOM A, the VDOM link interface is assigned IP 10.10.10.1/24, and in VDOM B, it is assigned 10.10.10.2/24. A firewall policy on VDOM A allows traffic from a subnet in VDOM A to a subnet in VDOM B. However, traffic fails. The admin checks the routing table in VDOM A and sees a route to the destination subnet via 10.10.10.2. What is the most likely cause?
Medium684An administrator configures a VDOM on a FortiGate and assigns two interfaces (port1, port2) to it. The administrator wants to route traffic between two different subnets within the same VDOM. Which configuration is required?
Medium685An administrator is configuring a FortiGate with multiple VDOMs. The administrator needs to allow a VDOM to use a shared physical interface with another VDOM. Which feature should be used?
Medium686Which of the following is a requirement for FortiGate to act as a SAML Identity Provider (IdP) for ZTNA?
Easy687A FortiGate administrator is deploying ZTNA for remote users who connect through FortiClient. The administrator wants to enforce device compliance based on the FortiClient EMS tags. The FortiGate is already integrated with FortiClient EMS. Which configuration step is required to use EMS tags in a ZTNA policy?
Medium688An administrator is configuring a FortiGate to inspect SMTP traffic for spam and viruses. The traffic must be decrypted to inspect the content. Which THREE elements are required for this configuration? (Choose three.)
Medium689An administrator is troubleshooting BGP with SD-WAN. They have configured BGP on the FortiGate and the SD-WAN rule uses 'best quality' strategy. However, failover does not happen when a WAN link goes down. The BGP session is still up. What is the most likely reason?
Medium690An NSE7 administrator is configuring a FortiGate to use the built-in intrusion prevention system (IPS) to detect and block exploits targeting a custom web application. The administrator wants to ensure that the IPS engine inspects all HTTP traffic, including encrypted sessions, without impacting performance. Which FortiGate feature should be enabled to allow IPS inspection of SSL/TLS traffic?
Medium691A FortiGate running FortiOS 7.4 is configured with a firewall policy that references an IPS sensor. The sensor uses a custom signature to detect a recently discovered exploit. Users report that the exploit traffic is not being blocked even though the signature is enabled. The administrator confirms the traffic matches the signature and that the policy is in flow-based inspection mode. Which action should the administrator take to ensure the IPS sensor can block the exploit?
Medium692A FortiGate administrator is implementing ZTNA in reverse-proxy mode to protect an internal web application. Remote users authenticate through FortiClient with EMS tags, and the administrator wants to enforce that only users with a valid certificate and a compliant endpoint can access the application. After configuring the ZTNA server and access proxy, the administrator notices that users without the certificate are still able to reach the application. What is the most likely cause?
Medium693An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that the VDOMs can use overlapping IP addresses on their respective interfaces. Which setting must be enabled to allow this?
Medium694A FortiGate administrator wants to use SAML SSO to authenticate VPN users. The FortiGate will act as the service provider (SP) and an external identity provider (IdP) will be used. Which of the following must be configured on the FortiGate to enable SAML authentication for SSL VPN?
Medium695Which Fortinet product provides endpoint detection and response (EDR) capabilities, including automated threat containment?
Easy696A network administrator is configuring inter-VDOM routing between two VDOMs: VDOM-A and VDOM-B. The administrator creates a inter-VDOM link and adds routes pointing to the link. However, traffic from VDOM-A to VDOM-B fails. What is the most likely missing configuration?
Medium697A company is deploying FortiClient ATP to protect endpoints. They want to block ransomware behavior in real time. Which FortiClient feature should be enabled?
Medium698A FortiGate is configured with SD-WAN using load balancing algorithm 'source-dest-ip'. What is the primary characteristic of this algorithm?
Easy699In FortiManager, what is the purpose of header and footer policies in a policy package?
Medium700An administrator needs to apply different routing policies for traffic based on source IP address, overriding the normal routing table. Which feature should be configured?
Medium701A network administrator is deploying FortiGate to protect against unknown malware. They want to use machine learning to detect and block malicious files without relying on signatures. Which antivirus scanning technique should be enabled to achieve this?
Easy702A FortiGate is configured with two SD-WAN members: port1 (WAN1) and port2 (WAN2). An SD-WAN rule routes traffic from the internal subnet 10.0.1.0/24 to the internet using the 'volume' load-balancing algorithm. The rule is configured with a volume ratio of 70:30 for port1:port2. After some time, the administrator notices that port1 is handling approximately 90% of the traffic volume, while port2 handles only 10%. What is the most likely cause of this imbalance?
Medium703An administrator runs 'diagnose debug application sslvpn -1' and sees repeated 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate'. The SSL-VPN is configured to require client certificates. What is the cause?
Hard704Which two commands display the current session count on a FortiGate?
Easy705A FortiGate administrator is configuring ZTNA to provide secure access to an internal application. The application is hosted on a server with IP 10.0.1.100 and port 8080. The administrator creates a ZTNA rule on the FortiGate as an access proxy. What is the correct configuration for the ZTNA rule's 'Application Access' entry?
Medium706An administrator has a FortiGate with VDOMs 'VDOM-A' and 'VDOM-B' connected by an inter-VDOM link. Users in VDOM-A can reach a web server in VDOM-B, but return traffic from the server to clients is being dropped. The administrator has already created policies in both directions. Which action should the administrator take to resolve the dropped return traffic?
Hard707A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is established but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees 'no matching policy for this IPsec SA'. What is the most likely cause?
Medium708A network administrator is deploying a FortiGate in transparent mode to replace an existing layer 2 switch. Which statement about transparent mode is true?
Easy709A FortiGate administrator wants to ensure that only devices with an up-to-date antivirus and OS patch level can access a sensitive application published via ZTNA. Which ZTNA component should the administrator configure to enforce this requirement?
Easy710A FortiGate administrator is troubleshooting a ZTNA deployment. Users report that they can access the ZTNA application, but the EMS tags are not being enforced. The administrator verifies that the FortiGate is connected to FortiClient EMS and that the EMS tags exist. What is the most likely cause?
Medium711A FortiGate administrator has configured an antivirus profile with sandbox inspection and applied it to a firewall policy. Users report that downloads of executable files are delayed significantly, but eventually complete. The administrator wants to reduce the delay while still blocking malicious files before they reach the endpoint. Which change should the administrator make?
Hard712A FortiManager administrator wants to push a policy package that includes both global header/footer policies and VDOM-specific policies. Which statement about header/footer policies is correct?
Medium713An administrator wants to add custom fields to device objects in FortiManager to track location and contact info. Which feature should be used?
Medium714A FortiGate is configured with two WAN members in an SD-WAN zone. The performance SLA monitors latency to a probe server. The rule uses 'best quality' strategy. After some time, one member fails the SLA. Which action does the FortiGate take for existing sessions that were using that member?
Hard715An administrator is troubleshooting an issue where a FortiGate is not forwarding traffic between two internal subnets. The administrator runs 'diagnose debug flow' and sees that packets are entering the FortiGate but are dropped with the message 'reverse path check fail, drop'. What is the MOST likely cause?
Hard716When troubleshooting an IPsec VPN phase 1 failure, you run 'diagnose vpn ike config' and see that the remote gateway IP address is incorrect. Which command is used to correct the peer IP configuration?
Medium717A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?
Easy718A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?
MediumOther domains
All NSE7 exam domains
Frequently asked questions
- What does the scenario questions domain cover on the NSE7 exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 718 scenario questions questions in the NSE7 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.