Courseiva

NSE7 · domain

scenario questions

Practise Fortinet NSE 7 Advanced Security NSE7 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

718 questions198 easy335 medium185 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (718)

Click any question to see the full explanation, or start a practice session above.

1

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a specific physical interface to a non-management VDOM and ensure that the interface is not visible or configurable from other VDOMs. The interface is currently assigned to the root VDOM. What is the correct procedure to reassign the interface to VDOM-1?

Hard
2

An administrator is troubleshooting why a FortiGate is not applying the expected application control profile to traffic from a specific subnet. The administrator wants to verify which application signature is matching a live session in real time. Which CLI command should be used to display the application name and category for active sessions?

Medium
3

What is the purpose of BFD (Bidirectional Forwarding Detection) in a FortiGate routing configuration?

Easy
4

An administrator wants to use a FortiGate to manage FortiSwitch units via the LAN. Which interface configuration is required on the FortiGate to allow this management?

Easy
5

Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?

Easy
6

An administrator needs to monitor traffic flows across multiple FortiGate devices in a Security Fabric. The administrator wants to see a unified view of all traffic, including inter-device traffic, from a single pane. Which Fortinet tool provides this capability?

Easy
7

A FortiGate administrator is deploying ZTNA to provide access to internal applications for remote users. The administrator wants to ensure that users can only access the specific applications they are authorized for, and that the ZTNA access proxy performs authentication and authorization before forwarding traffic. Which FortiGate component must be configured to define the protected applications and the authentication rules for ZTNA access?

Medium
8

A FortiGate in HA active-passive mode has two VDOMs. VDOM-1 is configured for management (management VDOM). The administrator connects to the management VDOM IP to manage the device. What is a characteristic of the management VDOM?

Medium
9

A FortiGate is configured to send logs to FortiAnalyzer. The administrator notices that logs are not appearing on FortiAnalyzer. Running 'diagnose log device show' shows 'connected=no'. What is the most likely cause?

Medium
10

Which TWO of the following are required components for a Fortinet ZTNA solution? (Select two.)

Medium
11

An admin creates a VDOM named 'CustomerA' with inter-VDOM link to the management VDOM. The admin wants CustomerA administrators to manage only their own VDOM. Which configuration step is required?

Hard
12

What is the primary function of FortiAnalyzer's FortiView feature?

Easy
13

An organization uses FortiAnalyzer for centralized logging. The security team wants to use playbooks to automate responses to detected incidents. Which THREE components are essential for a playbook to function?

Hard
14

A FortiGate administrator needs to integrate with FortiNAC to enforce network access control for wired and wireless devices. The administrator wants FortiNAC to dynamically assign VLANs based on the device's security posture. Which FortiNAC feature enables this?

Medium
15

An administrator is troubleshooting an SD-WAN scenario where traffic from a branch office to a critical SaaS application is experiencing high latency. The SD-WAN rule uses the best quality SLA strategy. The administrator runs 'diagnose sys sdwan neighbor' and sees that both WAN links have SLA compliance above 90%. However, traffic still uses the slower link. The administrator then runs 'diagnose sys sdwan health-check list' and notices that the health-check server IP is different from the SaaS application's server IP. What is the MOST likely reason the traffic is not using the best-performing link?

Hard
16

Which FortiClient ATP feature provides protection against zero-day malware by monitoring process behavior and blocking suspicious activities at the endpoint?

Easy
17

An administrator configures a new ADOM in FortiManager for a set of FortiGates. The administrator wants to assign meta fields to devices in this ADOM. Where should the meta fields be defined?

Medium
18

A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)

Medium
19

A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?

Hard
20

A FortiGate admin configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The admin wants traffic from VDOM-A to reach a server in VDOM-B. Which three configuration steps are required? (Choose three.)

Hard
21

An administrator wants to use FortiExtender to provide LTE WAN connectivity. After connecting the FortiExtender to the FortiGate, the LTE interface is not showing up. What is the first troubleshooting step?

Medium
22

A network administrator runs 'get system ha status' on a FortiGate HA cluster and sees that only one unit shows as primary. The secondary unit shows as 'standalone' with no HA peer detected. What is the MOST likely cause of this issue?

Easy
23

An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is accessed via HTTPS. Which component must be configured on the FortiGate to act as a reverse proxy for the application?

Easy
24

An administrator configures BGP route advertisement but the routes are not being sent to the neighbor. The BGP session is established. What is the MOST likely cause?

Medium
25

An administrator is troubleshooting high CPU usage on a FortiGate. The administrator suspects that a specific process is causing the issue. Which TWO commands should the administrator use to identify the top CPU-consuming processes? (Choose two.)

Medium
26

A network administrator wants to delegate management of a specific VDOM to a junior administrator. The junior should be able to modify firewall policies and objects within that VDOM but not change system settings or other VDOMs. Which administrative access configuration meets this requirement?

Easy
27

A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)

Hard
28

What is the purpose of FortiAnalyzer in a Fortinet security fabric?

Easy
29

An administrator configures a FortiGate with VDOMs and notices that the 'config vdom' command lists multiple VDOMs, but only one VDOM is shown in the 'show full-configuration' output. What is the most likely reason?

Medium
30

An administrator is troubleshooting an SD-WAN setup where a specific application's traffic is not being steered according to the configured SD-WAN rule. The rule uses a performance SLA and the 'lowest-cost' strategy. The administrator runs 'diagnose sys sdwan health-check' and sees that both members are alive and meeting the SLA. However, traffic still goes over the higher-cost member. What is the most likely cause?

Hard
31

A network admin configures OSPF on a FortiGate with multiple areas, including one area that is not directly connected to the backbone (Area 0). To ensure that routes from that area are advertised into other areas, which OSPF feature must be properly configured?

Medium
32

An administrator needs to monitor the FortiGate's CPU usage in real-time from the CLI. Which command should be used?

Easy
33

Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?

Easy
34

Which SD-WAN load balancing algorithm is best for ensuring that all traffic from a specific source-destination pair uses the same WAN link?

Easy
35

An administrator wants to group firewall objects by department (e.g., Sales, Engineering) and easily filter them in FortiManager policy packages. Which feature should be used?

Medium
36

An administrator wants to enforce that only devices with antivirus software installed and up-to-date can access the corporate network. Which FortiGate feature should be used?

Easy
37

An administrator needs to verify if a FortiGate is receiving BGP routes from a peer. Which command should the admin run to see the BGP routing table?

Easy
38

An administrator wants to integrate FortiGate with an external threat intelligence feed to block known malicious IP addresses automatically. Which object should be used to consume the feed?

Medium
39

A FortiGate is configured with multiple virtual routers (VRFs). The administrator wants to allow communication between two VRFs using a firewall policy. Which type of interface is required for the policy?

Easy
40

Which FortiManager feature allows an administrator to view the exact CLI commands that will be pushed to a managed FortiGate before installation?

Easy
41

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGate devices. The tunnel is established, but traffic is not passing. Which configuration should the administrator check first?

Medium
42

In a FortiManager deployment with global ADOM enabled, an administrator creates a firewall policy in the global ADOM. What is the effect of this policy on the per-ADOM devices?

Hard
43

An administrator is troubleshooting why a new firewall policy on a managed FortiGate is not taking effect. The policy was created in FortiManager and installed successfully. Which TWO steps should the administrator verify to identify the issue? (Select TWO.)

Medium
44

An admin wants to create a custom IPS signature to detect a specific exploit that sends a string 'EXPLOIT' in the HTTP Host header. Which signature syntax is correct?

Medium
45

A security team is configuring FortiMail for email security. They want to ensure that incoming emails are authenticated using SPF, DKIM, and DMARC, and that emails failing authentication are quarantined. Which THREE settings must be configured in FortiMail? (Choose three.)

Hard
46

An administrator is troubleshooting a ZTNA issue where users are able to authenticate but the application access is still blocked. The ZTNA status on FortiClient shows 'Connected' but the application does not load. What is the MOST likely cause?

Hard
47

A multi-area OSPF network includes a FortiGate as an ABR. The administrator needs to redistribute a static route into OSPF. Which command is required on the FortiGate to achieve this?

Medium
48

An administrator sees the following log entry: 'id=13593 msg="CDR: File attachment sanitized"' Which feature generated this log?

Medium
49

An administrator wants to integrate a FortiExtender with a FortiGate to provide cellular WAN connectivity. Which configuration step is required on the FortiGate to use the FortiExtender as an SD-WAN member?

Medium
50

An administrator has a FortiGate with multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 are connected via an inter-VDOM link. The administrator wants to apply security profiles to traffic passing between the VDOMs. However, when checking the policy list in VDOM-1, no policy is shown for traffic destined to VDOM-2. What is the most likely reason?

Hard
51

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM so that it can be used for that VDOM's traffic. Which configuration step is required?

Medium
52

An administrator is deploying a FortiGate in multi-VDOM mode for a managed services provider. Each customer must have an isolated logical firewall with its own interfaces, policies, and administrators, and the provider wants to limit each customer administrator to only their own VDOM. Which configuration accomplishes this?

Easy
53

An administrator has a FortiGate in multi-VDOM mode. VDOM-1 is assigned to the marketing team and VDOM-2 to the finance team. The administrator wants both VDOMs to be able to reach a shared DNS server at 10.10.10.53 that sits behind the root VDOM's wan1 interface, without giving either team access to the other's traffic. Which configuration accomplishes this?

Medium
54

Which load balancing algorithm in SD-WAN distributes new sessions based on the source and destination IP addresses, ensuring that all sessions from a given source-destination pair go to the same member?

Easy
55

In FortiAnalyzer, which tool provides real-time traffic monitoring and allows drilling down into details such as top talkers, applications, and threats?

Easy
56

A FortiGate administrator is deploying ZTNA to protect an internal application. Users connect with FortiClient, which establishes a tunnel to the FortiGate. The administrator wants the FortiGate to verify the user's identity and device posture before allowing access to the application. Which FortiGate feature performs this verification as part of the ZTNA access proxy?

Easy
57

An administrator is deploying ZTNA with FortiClient EMS to secure access to a corporate web application. Which THREE components are required for a successful ZTNA deployment? (Choose three.)

Medium
58

A FortiGate has an IPsec VPN with a remote peer that uses IKEv2. The administrator wants to ensure that child SA rekeying uses PFS (Perfect Forward Secrecy) with Diffie-Hellman group 14. Which CLI command should the administrator configure on the FortiGate's phase 2 proposal?

Hard
59

A FortiGate is configured with an IPsec VPN that uses certificate-based authentication. The VPN fails to establish. The administrator checks the phase1 debug and sees the message: 'no suitable certificate found'. What is the most likely cause?

Hard
60

A FortiGate administrator is investigating a slow network performance issue. The administrator suspects that session table limits are being reached. Which TWO metrics should be monitored to confirm this? (Choose two.)

Hard
61

A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?

Easy
62

A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?

Hard
63

A network administrator wants to block known malicious IP addresses using threat intelligence feeds on FortiGate. Which feature should they use?

Easy
64

An administrator is troubleshooting an IPsec VPN tunnel that establishes phase 1 but fails to establish phase 2. The phase 2 configuration shows 'set proposal aes128-sha256' on both sides. Which TWO configuration items should the administrator verify?

Medium
65

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?

Hard
66

A FortiGate administrator wants to monitor performance thresholds to be alerted when the firewall is under heavy load. Which THREE metrics can be monitored using the built-in performance monitoring features (e.g., 'diagnose sys top' or SNMP)?

Easy
67

An administrator is troubleshooting an IPsec VPN Phase 2 negotiation failure. The debug shows 'no matching phase 2 proposal' from the remote peer. Which TWO of the following are likely causes? (Choose two.)

Hard
68

What is the purpose of BFD on a FortiGate?

Easy
69

An administrator needs to isolate customer traffic in a FortiGate deployed at a service provider. Each customer should have independent administrators and security policies. Which feature should be used?

Easy
70

A FortiGate admin configures an automation stitch to send an email alert when a high-severity IPS event occurs. The trigger is 'IPS Event' and the action is 'Email'. After testing, no email is sent despite events being logged. What is the most likely cause?

Medium
71

A network administrator is troubleshooting a split-brain scenario in an HA cluster. Which TWO conditions can cause split-brain? (Choose two.)

Medium
72

An administrator manages a FortiGate 500E with multiple VDOMs. The administrator needs to configure a new VDOM named 'Partner' and ensure that the Partner VDOM can use a dedicated physical interface for WAN connectivity. The FortiGate has an unused interface 'port5'. The administrator wants to assign port5 to the Partner VDOM and configure it with an IP address. Which sequence of steps is correct?

Hard
73

Drag and drop the steps to configure a FortiGate to send logs to a FortiAnalyzer into the correct order.

Medium
74

A FortiGate administrator is troubleshooting a ZTNA problem where users are unable to connect to an internal application via FortiClient. FortiClient reports 'Connection refused'. The FortiGate ZTNA gateway is configured correctly. Which THREE steps should the administrator take to diagnose the issue?

Hard
75

An administrator wants to load balance traffic across two WAN links by session count. Which SD-WAN load balancing algorithm should they use?

Easy
76

An admin is troubleshooting an IPsec VPN tunnel that is failing phase 2. The IKE debug shows 'no matching proposal'. Which TWO settings should the admin verify on both sides? (Choose two.)

Medium
77

An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?

Medium
78

Match each Fortinet component to its description.

Medium
79

A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?

Hard
80

A company has deployed two FortiGate-600Es in an active-passive HA cluster. The cluster is configured with three VDOMs: VDOM-A (corporate LAN), VDOM-B (guest Wi-Fi), and VDOM-C (DMZ). Each VDOM has its own set of interfaces and policies. The cluster is also configured to use FGCP with session pickup enabled. Recently, the network team noticed that after a failover event, some user sessions in VDOM-B are not being picked up, causing disruption for guest users. The session pickup feature is enabled globally. The administrator checks the configuration and finds the following settings on the primary FortiGate: - config system ha set session-pickup enable set session-pickup-connectionless enable end - config vdom edit VDOM-A config system ha set session-pickup enable end next edit VDOM-B config system ha set session-pickup disable end next edit VDOM-C config system ha set session-pickup enable end next Based on this configuration, what is the most likely reason that sessions in VDOM-B are not being picked up?

Hard
81

An administrator is reviewing the HA configuration shown in the exhibit. The primary unit has failed, and the secondary unit (with priority 100) has taken over. However, the administrator notices that the secondary unit has an IP address of 10.10.10.2 on port3, but cannot ping the management gateway 10.10.10.1. What is the most likely cause?

Easy
82

A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)

Hard
83

An administrator is configuring an SD-WAN rule on a FortiGate. They want to load balance traffic across three WAN links based on the volume of traffic sent. Which load balancing algorithm should they use?

Easy
84

A FortiGate administrator is troubleshooting a VPN tunnel that connects to a remote site. The tunnel is up, but traffic is not passing. The administrator checks the Phase 2 settings and sees that the local and remote subnets are correctly defined. What is the next step to diagnose the issue?

Medium
85

An organization wants to implement multiple layers of defense against advanced persistent threats. Which three Fortinet solutions would be most effective in an ATP strategy? (Choose three.)

Medium
86

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to assign a physical interface to a specific VDOM and ensure that the interface is dedicated to that VDOM only. Which action should the administrator take?

Easy
87

A network administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The remote gateway logs show a proposal mismatch. On FortiGate, the administrator runs 'diagnose vpn ike config' and sees 'proposal: aes128-sha1, aes256-sha256'. The remote side expects 'aes256-sha1'. What is the most likely cause?

Medium
88

A FortiGate running FortiOS 7.2 has multiple VDOMs. The administrator notices that inter-VDOM routing between two VDOMs is not working. Configuration shows a firewall policy allowing the traffic, and the route table shows routes to the destination VDOM. What additional configuration is required?

Hard
89

An administrator wants to monitor the session count on a FortiGate in real time. Which CLI command provides this information?

Easy
90

A security analyst is reviewing alerts from FortiEDR and wants to automatically isolate an infected endpoint from the network when a malicious process is detected. Which FortiEDR feature should the analyst configure to achieve this?

Easy
91

A FortiGate administrator configures a VDOM with a limit on the number of firewall policies. The VDOM has 200 policies, and the limit is set to 250. The administrator attempts to add a new policy but receives an error indicating the limit has been reached. What is the MOST likely reason?

Hard
92

A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?

Hard
93

A FortiGate has multiple VRFs configured. An administrator wants to allow traffic from VRF 1 to reach a server in VRF 2. What configuration is required?

Medium
94

A FortiGate HA cluster is configured with two units in active-passive mode. The administrator needs to perform a firmware upgrade on the cluster with minimal downtime. The current firmware version is 7.2.5 and the target is 7.2.7. The cluster uses FGCP with session synchronization enabled. Which procedure should the administrator follow?

Hard
95

A FortiGate is the hub of an IPsec VPN and also terminates SSL VPN for remote users. The administrator wants remote users to access internal resources only after the FortiGate validates the endpoint's compliance through FortiClient EMS, and wants the validation to happen before the user is placed in a VPN address pool. Which SSL VPN configuration element enforces endpoint compliance during the connection handshake?

Hard
96

A FortiGate administrator has enabled FortiGuard Outbreak Prevention and selects the 'Use Outbreak Prevention Database' option. After a new outbreak is detected, the administrator verifies that the IPS signature is applied to all applicable policies. However, the administrator wants to ensure that the FortiGate dynamically updates its protection without requiring a full IPS engine update. Which FortiGuard service must be reachable for the FortiGate to receive outbreak prevention updates?

Medium
97

An administrator applies the above policy but users from 10.0.1.0/24 cannot access web servers at 10.0.2.0/24. However, they can ping the servers. What is the most likely cause?

Easy
98

A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?

Hard
99

A FortiGate administrator is deploying ZTNA to provide secure access to internal web applications. The administrator wants to ensure that only devices with up-to-date antivirus signatures are granted access. Which FortiGate component should be used to enforce this requirement?

Hard
100

A network administrator wants to logically separate two departments on a single FortiGate. Each department must have its own firewall policies, routing table, and administrators. Which feature should be used?

Easy
101

An administrator is investigating a security incident and needs to view raw logs from a FortiAnalyzer for a specific time range. The administrator wants to ensure the logs are not aggregated or summarized. Which type of log view should be used?

Hard
102

An administrator is deploying a FortiGate with multiple VDOMs in NAT mode. The administrator wants to ensure that traffic between VDOMs is inspected by security profiles and that inter-VDOM traffic does not bypass the firewall policy engine. Which configuration is required to achieve this?

Medium
103

An administrator runs 'diagnose sys session filter dport 443' and sees: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

Medium
104

An administrator configures a multi-VDOM FortiGate in transparent mode. The admin notices that the management IP is reachable from both interfaces, but traffic passing through the device is not being inspected. What is the likely issue?

Hard
105

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The default route in VDOM-A points to a next-hop router, and VDOM-B has a static route to a subnet behind VDOM-A. Users in VDOM-B cannot reach that subnet. The administrator runs 'diagnose ip route list' in both VDOMs and sees the routes are present. What is the most likely cause?

Hard
106

A FortiGate has multiple equal-cost routes to the same destination via two different interfaces. ECMP load balancing is enabled. What determines how traffic is distributed among the routes?

Medium
107

A network administrator configures an SD-WAN zone with two members (port1 and port2) and sets the load balancing algorithm to 'spillover'. The spillover threshold is set to 100 Mbps on port1. If traffic reaches 120 Mbps on port1, what happens to new sessions?

Medium
108

A FortiGate is configured with an antivirus profile that has the machine learning engine enabled. An administrator notices that some files are being detected by the ML engine but the verdict is 'probably clean'. What does this verdict indicate?

Hard
109

Which FortiGate feature allows an administrator to define a granular policy based on the security posture of the endpoint device, such as OS version, antivirus status, and disk encryption, before granting access to a protected application?

Easy
110

An administrator configures automation stitches on FortiManager to trigger a script when a specific event log is received. The script should block the source IP on the firewall. However, the script does not run when the event occurs. What is a likely cause?

Hard
111

A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?

Easy
112

A FortiGate administrator notices that traffic classified as 'unknown' by the antivirus is being allowed. The administrator wants to ensure that such files are submitted to FortiSandbox for analysis and blocked until a verdict is received. Which configuration is required?

Medium
113

What does FortiGuard Outbreak Prevention use to protect against newly discovered malware outbreaks before traditional signatures are available?

Easy
114

An administrator is troubleshooting an HA cluster (active-passive) where both units show 'primary' in 'get system ha status'. The cluster is not synchronizing configurations. What is the MOST likely cause?

Hard
115

A FortiGate is configured as a hub in an ADVPN with multiple spokes. The administrator notices that some spokes are not learning routes from other spokes, even though the ADVPN tunnel is up. The hub is using BGP for routing. Which configuration on the hub is required to enable spoke-to-spoke route propagation?

Hard
116

What is the purpose of header and footer policies in a FortiManager policy package?

Easy
117

What is the primary purpose of an administrative VDOM on a FortiGate?

Easy
118

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that a specific VDOM can use more system resources, such as sessions and CPU, than other VDOMs. Which FortiGate feature should the administrator use?

Easy
119

Which FortiAnalyzer feature allows administrators to create automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected?

Easy
120

What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?

Easy
121

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

Medium
122

An administrator wants to ensure that voice traffic (UDP 16384-32768) always uses the MPLS link, while internet-bound traffic uses broadband. Which SD-WAN feature should be configured to achieve this?

Easy
123

A FortiGate 600E is running in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator assigns physical port3 to VDOM-1 as a dedicated interface, then creates a VLAN subinterface (VLAN 100) on port3 for VDOM-2. After configuration, VLAN 100 traffic is dropped even though the VLAN interface is up. Which action resolves the issue?

Medium
124

A FortiGate VPN tunnel shows 'phase1 negotiation failed' in the logs. The remote gateway is a third-party device. The debug command 'diagnose vpn ike config' shows mismatched proposals. Which setting is MOST likely incorrect on the FortiGate?

Medium
125

An administrator is configuring a FortiGate for SD-WAN and wants to ensure that outgoing traffic from the internal network is distributed across two WAN links based on the number of active sessions. Which SD-WAN load balancing algorithm should be used?

Easy
126

A FortiGate administrator wants to use BFD to quickly detect link failures in an SD-WAN deployment. Which statement about BFD configuration on FortiGate is correct?

Easy
127

A FortiGate administrator needs to verify that the firewall is correctly identifying and logging a specific application, 'Facebook', that is being used by internal users. The administrator has already configured an application control profile with logging enabled for Facebook. Which CLI command should the administrator use to view the application control logs in real-time?

Easy
128

An enterprise FortiGate has multiple VDOMs. The administrator wants to allow traffic from VDOM A to reach servers in VDOM B without traversing an external router. Which configuration is required?

Medium
129

A FortiGate administrator is troubleshooting high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which action should the administrator take to reduce the CPU usage while maintaining security?

Medium
130

A company has two internet connections: a primary fiber link (port1, 100 Mbps) and a backup DSL link (port2, 20 Mbps). They are using SD-WAN to load balance traffic based on volume, with a rule that sends 70% of traffic to port1 and 30% to port2. Recently, users report that video conferencing applications are experiencing high latency and jitter. The network team finds that the SD-WAN performance SLA for the fiber link shows 80% packet loss and high latency. The SD-WAN rule action is set to 'best quality' with a latency threshold of 150 ms. The current latency on port1 is 200 ms, and on port2 is 40 ms. What should the administrator do to ensure that video conferencing traffic uses the DSL link while the fiber link is degraded?

Easy
131

Which FortiGate command is used to view the current CPU usage of individual processes in real time?

Easy
132

Drag and drop the steps to configure a FortiGate VDOM in multi-VDOM mode into the correct order.

Medium
133

A FortiGate is configured with a WAF profile to protect a web server. The administrator notices that SQL injection attacks are still reaching the server despite the WAF being enabled. What is the MOST likely reason?

Medium
134

A FortiGate running FortiOS 7.4.1 has two VDOMs: CustomerA and CustomerB. The administrator wants CustomerA to access an HTTP server in CustomerB. Both VDOMs have appropriate policies. What additional configuration is required?

Medium
135

A FortiGate administrator is troubleshooting a ZTNA access proxy rule that is not matching traffic from a specific user group. The rule is configured with a source of 'ZTNA_Users' and a destination of the internal web server. The administrator confirms that the user is authenticated and has the correct EMS tag. Which FortiGate CLI command should the administrator use to verify that the ZTNA rule is being evaluated correctly?

Hard
136

A FortiGate administrator needs to identify which process is consuming the most memory. Which command should be used?

Easy
137

An administrator is troubleshooting a BGP session that is not establishing between two FortiGates. The administrator has verified that the neighbor IP is reachable. Which TWO commands should be used to further diagnose the issue? (Choose two.)

Medium
138

A FortiGate administrator wants to prevent users from accessing a list of known malicious domains. The list is updated daily by a third-party provider and available as a plain text file over HTTPS. Which FortiGate feature should be used to ingest and block these domains?

Easy
139

A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?

Hard
140

An organization has multiple ADOMs in FortiManager. The admin wants to share a set of firewall objects across all ADOMs. What is the best approach?

Hard
141

A FortiGate administrator wants to use FortiAnalyzer to view traffic logs from multiple VDOMs. Which TWO steps must the administrator perform on FortiAnalyzer?

Easy
142

A security administrator wants to block email spoofing attacks against their organization's domain. They configure SPF, DKIM, and DMARC records. Which protocol authenticates the domain of the email sender by verifying the email's signature against a public key published in DNS?

Medium
143

An enterprise FortiGate has multiple VDOMs. The security policy requires that all traffic between VDOMs must be inspected by a next-generation firewall profile. Which three steps are necessary to achieve this? (Choose three.)

Medium
144

Which feature on FortiGate uses machine learning to detect never-before-seen malware based on file characteristics?

Easy
145

A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?

Medium
146

A FortiGate administrator is troubleshooting an issue where users are unable to access a web server behind the FortiGate. The web server is on the DMZ network, and users are on the internal network. The firewall policy from internal to DMZ is configured to allow HTTP and HTTPS. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which two actions should the administrator take to resolve this issue? (Choose two.)

Medium
147

An administrator configures FortiSandbox inline scanning for HTTP traffic. They notice that files uploaded via HTTP are being scanned but no verdict is being returned, causing delays. What is the MOST likely cause?

Medium
148

An administrator has configured two VDOMs on a FortiGate. One VDOM is in NAT mode and the other in transparent mode. The administrator wants traffic from the transparent mode VDOM to be routed through the NAT mode VDOM. What must be configured to allow inter-VDOM routing?

Hard
149

An administrator is configuring an SD-WAN rule to route traffic to a specific destination through a preferred member, but wants to ensure that if that member fails, traffic automatically switches to another member. Which SD-WAN rule configuration setting should they use to define the order of member preference?

Easy
150

A FortiGate in transparent mode is deployed between a router and a switch. The administrator needs to apply a deep inspection profile to HTTP traffic. What is the correct configuration for the interfaces?

Hard
151

A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees the tunnel state as 'connecting' but no phase2 selectors are listed. Which step should the administrator take next to identify the issue?

Medium
152

A FortiGate is configured with an SD-WAN rule using 'spillover' algorithm. The primary member has a spillover threshold of 100 Mbps. Traffic of 80 Mbps is currently flowing through the primary member. A new session requiring 30 Mbps arrives. What will happen?

Hard
153

A FortiGate administrator is configuring a security profile group and wants to enable inline blocking of malicious files based on FortiGuard cloud threat intelligence, without sending files to FortiSandbox. The administrator has already enabled the antivirus profile and selected the 'Block' action for infected files. Which additional setting should be configured to ensure that files identified as malicious by the FortiGuard service are blocked in real time?

Medium
154

A FortiGate administrator has configured a ZTNA access proxy for an internal web application and wants to enforce device compliance before allowing access. The administrator has integrated FortiClient EMS and created ZTNA tags for compliant devices. Users with compliant devices are still being denied access. The firewall policy references the ZTNA server and the tag. What should the administrator verify first?

Medium
155

A FortiGate administrator is configuring ZTNA to provide access to an internal web application. The administrator wants to ensure that only devices with a specific security posture tag are allowed access. The ZTNA rule is configured with a policy that references a device group synced from FortiClient EMS. However, when a user attempts to access the application, the connection is denied even though the device has the correct tag. What is the most likely cause?

Hard
156

A FortiGate has multiple VDOMs. The administrator notices that traffic from VDOM-1 to VDOM-2 is allowed by inter-VDOM policies but is not being inspected by the security profiles. What is the most likely cause?

Medium
157

An administrator wants to use FortiAnalyzer to generate weekly compliance reports for all managed FortiGates. Which FortiAnalyzer feature should be used?

Easy
158

A FortiGate administrator wants to enable load balancing for equal-cost paths to the same destination. The FortiGate has two equal-cost routes via two different next-hop routers. Which feature should the admin enable to load balance traffic across both paths?

Easy
159

A network administrator is setting up an IPsec VPN between two FortiGates. The administrator wants to ensure that if the VPN tunnel goes down, the FortiGate can automatically re-establish it without manual intervention. Which IPsec feature should the administrator enable to detect peer failures and trigger tunnel renegotiation?

Easy
160

An administrator needs to configure advanced email security on FortiMail to protect against phishing and spoofing. Which THREE features should be enabled to achieve comprehensive email authentication?

Medium
161

A multinational corporation is implementing ZTNA for remote access to a critical internal application hosted on a server with IP 10.0.1.200:8443. The FortiGate is deployed at the edge with WAN IP 203.0.113.50. The administrator configures a ZTNA rule with proxy destination 10.0.1.200:8443, a firewall policy allowing traffic from the ZTNA gateway to the internal server, and a VIP for port forwarding for testing. However, remote users report that they can establish a ZTNA connection to the gateway but the application page fails to load, showing a blank page after a long delay. The FortiGate logs show no errors, and the debug output indicates that the proxy successfully forwarded the request to 10.0.1.200:8443 and received a response. The internal server team confirms the application is working correctly for on-site users. What is the most likely cause?

Hard
162

An admin needs to configure a FortiGate to send logs to FortiAnalyzer for a specific VDOM only. How can this be achieved?

Medium
163

A company is implementing a Security Fabric with multiple FortiGate devices. They want to use FortiAnalyzer for centralized logging and FortiManager for centralized management. Which of the following is a prerequisite for adding a FortiGate to the Security Fabric?

Easy
164

An administrator wants to use FortiGate to automatically block traffic if FortiEDR detects a threat on an endpoint. Which feature should the administrator configure?

Medium
165

A FortiGate administrator wants to use PKI certificates for IPsec VPN authentication instead of pre-shared keys. Which phase1 parameter must be set to 'signature' to enable certificate-based authentication?

Easy
166

A FortiGate with SD-WAN configured has a Performance SLA monitoring Google DNS (8.8.8.8). The SLA is configured with latency threshold 100 ms and jitter threshold 20 ms. The link is currently meeting both thresholds. The administrator wants to ensure that if the SLA fails, traffic moves to another link. Which SD-WAN rule strategy should be used?

Medium
167

An administrator wants to block a zero-day malware outbreak detected by FortiGuard. Which feature should be configured to automatically block the threat across all enabled FortiGate devices?

Easy
168

An administrator configures an ALG for SIP traffic but notices that some SIP calls are failing. The admin suspects the ALG is modifying SIP headers incorrectly. Which debug command can help verify the ALG's actions on SIP packets?

Hard
169

A FortiGate administrator runs the following command and sees the output: diagnose sys session filter dport 443 diagnose sys session list Output shows sessions with proto=6 and expire time decreasing. What does this indicate?

Medium
170

A FortiGate administrator wants to integrate ZTNA with FortiClient EMS to control access to an internal application based on device posture. The admin has configured a ZTNA tag in EMS for 'AntiVirus enabled' and created a ZTNA rule in FortiGate. What additional configuration is required on the FortiGate to enforce access based on the ZTNA tag?

Easy
171

An administrator is configuring FortiGate automation stitches to respond to a detected ransomware outbreak. The trigger is a high severity event from FortiSandbox. Which TWO actions can be used in an automation stitch to contain the threat?

Medium
172

A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?

Medium
173

A FortiGate administrator wants to use FortiManager automation stitches to automatically block IP addresses that trigger multiple intrusion prevention events. Which two components are required to configure an automation stitch? (Choose two.)

Medium
174

A network administrator is troubleshooting why a FortiGate does not appear to be enforcing a newly configured application control profile. The policy is applied to traffic from the internal network to the internet. The administrator runs 'diagnose sys session list' and sees that sessions are being created, but the application control profile is not listed in the session details. Which action should the administrator take to verify that the application control profile is being applied?

Medium
175

Which of the following is a valid command to check the status of all BGP neighbors on a FortiGate?

Easy
176

A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?

Medium
177

A FortiGate has two VDOMs: 'root' and 'customer'. The admin wants to route traffic from 'customer' to the internet via 'root', which has a BGP connection to an ISP. What is the required configuration?

Medium
178

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator wants VDOM-A and VDOM-B to exchange routing information dynamically without using static routes. The administrator has already created a VDOM link named 'vlink' between the two VDOMs and assigned IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. Which additional configuration is required on each VDOM to enable OSPF adjacency over the VDOM link?

Medium
179

Which THREE actions can an administrator perform using FortiManager in a Security Fabric environment? (Choose three.)

Hard
180

A FortiGate administrator wants to ensure that files in email attachments are disarmed before delivery. Which security feature should be configured in the antivirus profile?

Easy
181

An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?

Medium
182

A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?

Medium
183

An organization wants to implement email authentication to prevent spoofing and phishing attacks. They use FortiMail as their email security gateway. Which THREE mechanisms should they configure to achieve comprehensive email authentication?

Medium
184

A FortiGate administrator has deployed ZTNA with FortiClient EMS tagging. A remote user's endpoint is tagged as 'Compliant' in EMS, but the FortiGate ZTNA policy still denies the user's connection to the internal web application. The administrator confirmed the EMS connector status on the FortiGate shows 'Connected' and the tag is visible in the FortiGate's device inventory. What is the most likely cause of the access denial?

Medium
185

A network engineer needs to collect logs from multiple FortiGates and generate compliance reports. Which TWO FortiAnalyzer features should be used?

Medium
186

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own separate routing table. Which statement is correct?

Easy
187

An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?

Medium
188

What is the purpose of a route map when used with route redistribution on a FortiGate?

Easy
189

A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that only specific subnets are allowed over the tunnel and that the tunnel uses strong encryption. After configuring phase1 and phase2, the administrator notices that the tunnel is up, but traffic from a subnet that should be allowed is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. What is the most likely reason for the traffic not passing?

Hard
190

A healthcare provider is deploying ZTNA to secure access to an internal electronic health records (EHR) system. The EHR system is composed of multiple web services running on different ports behind a load balancer with IP 10.0.10.100. The load balancer listens on ports 443, 8443, and 9090. The administrator configures a single ZTNA rule with proxy destination 10.0.10.100:443, expecting that the other ports will be accessed via the same rule. However, users report that they can only access the service on port 443; connections to ports 8443 and 9090 fail. The FortiGate logs show that requests to other ports are being dropped. What should the administrator do to resolve this?

Medium
191

In a Fortinet ZTNA deployment, which component is responsible for forwarding decrypted traffic to the internal application server after the FortiGate proxy has performed SSL inspection?

Easy
192

Drag and drop the steps to configure a site-to-site IPsec VPN on a FortiGate firewall into the correct order.

Medium
193

A network administrator is configuring SD-WAN on a FortiGate. They have multiple WAN links and want to ensure that traffic for a critical application uses the link with the lowest latency. Which SD-WAN configuration component should be used to achieve this?

Medium
194

A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?

Easy
195

An administrator wants to block outbound traffic from internal hosts to known malicious domains without relying on full URL inspection or certificate inspection. The requirement is to use a lightweight DNS-based security service on FortiGate that can block botnet C2 and phishing domains. Which FortiGuard feature should the administrator enable and configure in a DNS filter profile?

Medium
196

You are troubleshooting a VPN phase 2 negotiation failure. The logs show 'no proposal chosen'. What is the MOST likely cause?

Hard
197

A FortiGate is configured with ECMP load balancing. What is the default behavior when multiple routes have equal cost?

Easy
198

During a failover test in an active-passive HA cluster, the administrator notices that the secondary unit does not take over the primary role after a link failure on the primary. The 'get system ha status' shows both units in 'standalone' mode. What is the MOST likely cause?

Medium
199

An organization wants to deploy a web application firewall (WAF) to protect a public-facing web application. They are evaluating FortiGate versus FortiWeb. Which of the following is a key advantage of using FortiWeb over FortiGate for WAF functionality?

Medium
200

A company is deploying ZTNA to protect an internal application. They want to ensure that only users with devices that have disk encryption enabled and the latest OS patches can access the application. Which THREE components must be configured to achieve this?

Hard
201

An administrator is deploying a FortiGate with multiple VDOMs in NAT/route mode. The administrator needs to configure inter-VDOM routing between VDOM-A and VDOM-B. Which two actions are required to enable traffic to flow between the two VDOMs? (Choose two.)

Medium
202

An administrator wants to use FortiGate to block outbound traffic to known malicious IP addresses based on a threat intelligence feed. They configure a threat feed connector and a firewall policy with a destination address group. However, the policy is not blocking traffic to the malicious IPs. What is the most likely cause?

Medium
203

A company wants to receive threat intelligence feeds from external sources to enhance their FortiGate's protection. Which method should be used to integrate external threat feeds into FortiGate?

Medium
204

A FortiGate administrator is configuring a ZTNA rule to protect an internal application. The administrator wants to ensure that only devices with a specific compliance tag are allowed, while all other devices are denied. The administrator has already created the ZTNA server and the FortiClient EMS tags. What is the correct way to enforce this requirement in the firewall policy?

Easy
205

An organization deploys FortiEDR to protect endpoints. Which component is responsible for collecting and sending telemetry data to the FortiEDR management console?

Medium
206

Match each FortiGate routing concept to its description.

Medium
207

A FortiGate is configured with multiple VDOMs. The administrator wants to assign a physical interface to multiple VDOMs to save physical ports. Which feature should they use?

Hard
208

A FortiGate is configured with a firewall policy that has a URL filter profile. Users report that access to a specific website is blocked, but the administrator wants to verify which URL filter category matched the request. The administrator runs 'diagnose debug application urlfilter -1' in the CLI. However, no output appears. What is the MOST likely reason for the lack of output?

Medium
209

A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?

Medium
210

A FortiGate administrator needs to configure a policy that allows traffic from VDOM A to VDOM B using inter-VDOM routing. Which configuration is required?

Medium
211

An administrator configures email authentication (SPF, DKIM, DMARC) on FortiMail. They find that legitimate emails are being marked as spam by FortiMail. The SPF check passes but DKIM fails. What could be the issue?

Hard
212

An organization is deploying FortiEDR to enhance endpoint protection. Which THREE capabilities does FortiEDR provide? (Choose three.)

Hard
213

A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?

Medium
214

Refer to the exhibit. A tunnel interface is configured with IP 10.0.1.1/30 and remote-ip 10.0.1.2/30. The phase2 defines src-subnet as 10.0.1.0/30 and dst-subnet as 10.0.2.0/30. What is the most likely problem with this configuration?

Hard
215

A FortiGate admin configures a policy package with header and footer policies in FortiManager. What is the purpose of header policies?

Medium
216

What is the purpose of a management VDOM in a multi-VDOM FortiGate?

Easy
217

A FortiGate is configured as a ZTNA access proxy for an internal application. The administrator wants to enforce device compliance using FortiClient EMS tags before allowing access. Which configuration step is required to ensure that only endpoints with a specific EMS tag can access the application?

Medium
218

A FortiGate administrator wants to see the current number of active sessions. Which command provides this information?

Easy
219

A company is deploying ZTNA to replace their legacy VPN. They want to ensure that only users with a valid certificate and compliant antivirus can access the internal application. Which TWO components are required on the FortiGate for this deployment?

Easy
220

An administrator is deploying an ADVPN with a hub and two spokes. The hub is behind a NAT device and has a static public IP, while both spokes are behind NAT with dynamic public IPs. The administrator wants the spokes to establish shortcuts directly between each other. Which configuration is required for the shortcut to form?

Hard
221

An administrator has a FortiGate with multiple VDOMs and a management VDOM enabled. The management VDOM is used for out-of-band management and logging. The administrator wants to ensure that the management VDOM can reach a syslog server on the Internet while all other VDOMs use a separate data VDOM for their Internet traffic. Which configuration is required to allow the management VDOM to use a different default route than the other VDOMs?

Hard
222

A network administrator is troubleshooting a FortiGate HA cluster in active-passive mode. The administrator notices that the secondary unit is not receiving heartbeat packets from the primary unit, and the cluster has split. The administrator runs 'diagnose sys ha status' on both units and sees that the primary unit shows the secondary as 'not connected', while the secondary unit shows the primary as 'not connected'. The administrator verifies that the heartbeat interfaces are correctly configured and physically connected. What is the MOST likely cause of the split?

Hard
223

An administrator has a FortiGate 600E running FortiOS 7.2 with multiple VDOMs enabled. The administrator wants to create a new VDOM named 'DMZ' and assign it a specific physical interface (port3) that is currently unused. After creating the VDOM, the administrator navigates to Network > Interfaces in the DMZ VDOM but cannot see port3 in the list of available interfaces to assign. What is the most likely reason for this?

Medium
224

A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?

Hard
225

In FortiManager, an administrator wants to apply a set of firewall policies to multiple FortiGates in different ADOMs. The policies must be centrally managed. What is the best approach?

Medium
226

An administrator wants to ensure that traffic between two VDOMs on the same FortiGate is properly inspected. Which THREE configurations must be in place?

Hard
227

A site-to-site IPsec VPN tunnel is failing. The administrator runs 'diagnose vpn ike config' and sees that phase 1 parameters are correct. However, phase 2 negotiation fails with 'no proposal chosen'. What is the MOST likely cause?

Medium
228

An administrator configures an SD-WAN rule to steer traffic from a specific subnet to an SD-WAN member with the lowest cost. Which load balancing algorithm should be selected in the SD-WAN rule to achieve this behavior?

Medium
229

An administrator configures FortiAnalyzer to receive logs from multiple FortiGates. They want to create a report that shows only incidents involving 'critical' severity and specific attack types. Which FortiAnalyzer feature allows the administrator to define such a custom report?

Hard
230

An administrator wants to troubleshoot why specific traffic is not matching a configured firewall policy. Which debug command should be used?

Medium
231

A FortiGate administrator wants to use Fortinac for network access control. Which of the following is the PRIMARY function of Fortinac in a network?

Easy
232

A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?

Easy
233

A FortiGate administrator is using FortiNAC to enforce network access control for wired endpoints. The administrator wants to quarantine any endpoint that fails antivirus compliance. Which action should be configured in the FortiNAC policy to achieve this?

Medium
234

An administrator is troubleshooting a scenario where FortiAnalyzer is not receiving logs from a FortiGate. The FortiGate shows 'log-fortianalyzer setting status: disconnected'. Which step should be taken first to resolve this?

Medium
235

Which routing technique allows a FortiGate to forward packets based on source IP address, destination IP address, or other criteria, in addition to the destination IP alone?

Easy
236

A FortiGate administrator configures SAML SSO with FortiGate as the Service Provider (SP) and an external IdP. Users report that they are prompted for credentials repeatedly without successful authentication. What is the most likely cause?

Medium
237

A FortiGate is configured with OSPF and BGP. The administrator wants to redistribute OSPF routes into BGP. Which TWO steps are required?

Medium
238

An administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that both phase 1 and phase 2 are up. The policy allows traffic from both sides. What should the administrator check next?

Medium
239

An admin configures Content Disarm and Reconstruction (CDR) on FortiGate to protect against malicious macros in Office documents. After applying the CDR profile to a firewall policy, users complain that documents are not being delivered. What is the most likely cause?

Hard
240

A FortiGate is configured with two SD-WAN members (wan1, wan2) and a performance SLA for each. The SD-WAN rule uses 'Maximize Bandwidth' strategy with volume-based load balancing. The administrator notices that traffic is only using wan1, even though both links have capacity. The SLA status for wan2 shows 'alive'. What could be the problem?

Hard
241

An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. The performance SLA monitors latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest jitter that also meets the SLA thresholds. Which SD-WAN strategy should be used?

Easy
242

A security administrator is configuring a FortiGate to use an external threat intelligence feed via a Threat Feed connector. The administrator wants to ensure that the firewall automatically blocks traffic to malicious IP addresses and domains from the feed. Which two actions are required to achieve this? (Choose two.)

Medium
243

An administrator runs 'diagnose debug application fnbam -1' and sees messages like 'LB_SELECT: selected server 10.0.0.2:80' but the client connection fails. The FortiGate is configured with server load balancing. What could be the issue?

Hard
244

An administrator is configuring a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that traffic between VDOMs is inspected by firewall policies. Which TWO statements about inter-VDOM routing are correct? (Choose two.)

Medium
245

An administrator wants to enforce that only devices with up-to-date antivirus software can access corporate resources via ZTNA. Which FortiClient feature should be used to enforce this requirement?

Easy
246

A company has a FortiGate with multiple VDOMs. The security team wants to use FortiManager to manage policies centrally. Which three steps are necessary to set up VDOM management via FortiManager? (Choose three.)

Hard
247

An administrator wants to enforce that only devices with corporate-owned certificates can establish an IPsec VPN tunnel. Which IPsec authentication method should be configured?

Easy
248

A network admin is deploying a FortiGate in transparent mode to inspect traffic between two Layer 2 switches. Which of the following statements about transparent mode is correct?

Medium
249

A network admin wants to use FortiClient's advanced threat protection features to detect ransomware behavior on endpoints. Which FortiClient feature should be enabled?

Medium
250

A FortiGate is configured with multiple BGP peers. One of the peers is not receiving the expected routes. The administrator runs 'get router info bgp neighbors <IP>' and sees that the 'State/PfxRcd' field is 'Active'. What does this indicate?

Medium
251

An administrator notices high CPU usage on a FortiGate. To identify which process is consuming the most CPU, which command should be used?

Medium
252

Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?

Medium
253

A FortiGate administrator is troubleshooting a scenario where users in VDOM-1 cannot reach a server in VDOM-2. Inter-VDOM routing is configured using a VDOM link. The administrator checks the session table and sees that packets are arriving on the VDOM link interface but are not being forwarded. What is the MOST likely cause?

Hard
254

An administrator is configuring an IPsec VPN on a FortiGate that will interoperate with a third-party peer. The peer requires the use of a specific encryption domain and does not support IKEv2. The administrator wants to ensure that only specific subnets are permitted through the tunnel, while all other traffic is excluded from the SA. Which configuration element on the FortiGate directly controls which traffic is selected for the IPsec tunnel?

Hard
255

A FortiGate administrator notices that after installing a new policy package from FortiManager, the firewall policies on the managed FortiGate do not match what was configured in FortiManager. What feature should the administrator use to review the exact changes before committing?

Easy
256

A network security administrator wants to use FortiGate to automatically quarantine an endpoint when FortiEDR detects malicious behavior on that endpoint. Which FortiGate feature should be used to integrate with FortiEDR for this purpose?

Easy
257

A network admin is troubleshooting why FortiGate's antivirus is not detecting a known malware sample. The sample is detected by other scanners. Which two checks should the admin perform? (Choose two.)

Medium
258

An administrator wants to ensure that only devices with up-to-date antivirus software can access a sensitive application via ZTNA. Which FortiGate feature should be used to enforce this requirement?

Easy
259

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to enable communication between VDOM-A and VDOM-B using an inter-VDOM link. The administrator creates the link and assigns IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. The administrator then adds a static route in VDOM-A to VDOM-B's network (192.168.2.0/24) via 10.0.0.2, and a static route in VDOM-B to VDOM-A's network (192.168.1.0/24) via 10.0.0.1. However, traffic still fails. What is the most likely missing configuration?

Hard
260

A FortiGate is configured with a firewall policy that applies an application control profile blocking social media. Users report that they can still access Facebook. The administrator verifies that the policy is correctly matching the traffic and that the application control profile is applied. Which CLI command should the administrator use to verify whether the application control is correctly identifying the traffic?

Medium
261

A security analyst is investigating a recent security incident and wants to use FortiGate's Security Fabric to gather threat intelligence. The analyst needs to view detailed information about a detected threat, including the source, destination, and the specific IPS signature that triggered. Which FortiGate feature provides a centralized view of threat events and allows drill-down into individual incidents?

Hard
262

A security administrator is configuring FortiSandbox integration to automatically block malicious files detected in email attachments. Which TWO actions are required to achieve this integration?

Medium
263

A FortiGate administrator needs to use FortiManager to deploy a new security policy to all firewalls in a specific ADOM. Which two steps are part of the installation process? (Choose two.)

Easy
264

A FortiGate is configured with a VIP for an internal web server. Users report that the web server is unreachable from the internet, but it is accessible from the internal network. The administrator runs 'diagnose debug flow' with filters for the public IP and sees that the traffic reaches the FortiGate but is dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?

Hard
265

What is the purpose of a prefix list in FortiGate routing?

Easy
266

You run 'diagnose vpn ike gateway list' and see the following: gateway name: HUB_GW version: IKEv2 state: UP mode: main local: 10.0.0.1:500 remote: 203.0.113.5:500 auth: psk dpd: on rekey: 86400 num_peers: 2 total_tunnels: 2 auto-discovery: enabled What does the 'auto-discovery: enabled' indicate about this VPN gateway?

Hard
267

A network administrator is troubleshooting an IPsec VPN tunnel between Site A (FortiGate) and Site B (third-party VPN peer). The tunnel fails to establish. On FortiGate, phase1 status shows 'up' but phase2 status remains 'down'. What is the MOST likely cause?

Medium
268

A ZTNA rule is configured to allow access to an internal application only if the client device has the ZTNA tag 'Compliant' and the user is authenticated via SAML. The FortiGate is acting as ZTNA proxy. A user successfully authenticates but the device is not tagged. What happens when the user tries to access the application?

Medium
269

An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. They have two WAN members: port1 (MPLS) and port2 (Internet). They create a performance SLA that monitors latency and jitter, and set the SLA target to 150 ms latency and 30 ms jitter. They apply the SLA to both members. The SD-WAN rule is set to 'Best Quality' strategy. After applying the configuration, they notice that VoIP traffic is sometimes routed over port2 even though port1 has lower latency and jitter. What is the most likely reason?

Medium
270

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

Hard
271

Which TWO features are required to implement an always-on SSL VPN tunnel with FortiGate that automatically reconnects when the user's network changes?

Hard
272

A FortiGate is configured with two VRF instances: VRF10 (for a customer) and VRF20 (for another customer). Each VRF has its own interfaces and routing table. The administrator wants to allow a specific server in VRF10 (10.10.10.5) to be reachable from a host in VRF20 (20.20.20.5) without leaking all routes between VRFs. Which FortiGate feature should be used to achieve this?

Hard
273

A security team uses FortiSandbox in a FortiGate security fabric. They want files that receive a 'Malicious' verdict to be automatically quarantined and their source endpoints isolated without manual intervention. Which combination of Fortinet components and features must be configured to achieve this automated response?

Hard
274

An organization uses FortiNAC for network access control. They want to enforce that only corporate-managed devices with up-to-date patches can access the production VLAN. Which THREE components must be integrated or configured?

Hard
275

An administrator configures BFD on a FortiGate to improve convergence time for OSPF. What is the primary purpose of BFD in this context?

Medium
276

A network administrator is deploying a FortiGate in multi-VDOM mode. The administrator wants to restrict a specific VDOM so that it can only use a maximum of 2 GB of system memory and 10% of the total CPU resources. Which FortiGate feature should the administrator use?

Easy
277

An administrator is troubleshooting a FortiGate HA cluster that is experiencing frequent failovers. The administrator wants to verify the HA status and identify potential issues. Which TWO commands should the administrator use to gather relevant information? (Choose two.)

Medium
278

An administrator has a FortiGate with two VDOMs: 'root' and 'VDOM-A'. The administrator wants to assign a physical interface to VDOM-A, but the interface is currently assigned to the root VDOM and is in use by a firewall policy. What must the administrator do before changing the interface's VDOM assignment?

Hard
279

An administrator wants to see the current number of active sessions on a FortiGate. Which command should the admin use?

Easy
280

A FortiGate administrator is planning a multi-VDOM deployment for a service provider. Which TWO statements are true about VDOM limitations and best practices?

Medium
281

A FortiGate is configured with two SD-WAN members: port1 and port2. The administrator wants to ensure that voice traffic uses port1, but if port1's latency exceeds 150 ms, voice traffic should fail over to port2. Which configuration is required to achieve this?

Hard
282

A FortiGate is configured with an explicit web proxy on port 8080. Users report that some websites load slowly while others fail to load at all. The administrator runs 'diagnose debug application wad 8' and sees messages about 'proxy worker' and 'connection failed'. Which command should the administrator use to view the current proxy sessions in real time?

Medium
283

A FortiGate is configured as a SAML service provider (SP) for ZTNA. Users authenticate via an external IdP. After authentication, users are not able to access applications even though the ZTNA proxy rule lists them. What should the administrator check FIRST?

Medium
284

An enterprise deploys a FortiGate in transparent mode to bridge two broadcast domains. The administrator needs to apply a web filter to HTTP traffic between these domains. Which configuration is required?

Medium
285

Drag and drop the steps to perform a firmware upgrade on a FortiGate device into the correct order.

Medium
286

A FortiManager administrator wants to deploy a policy package that contains shared header and footer policies across multiple devices. How should these policies be configured in FortiManager?

Medium
287

In FortiManager, what is the difference between a Global ADOM and a regular ADOM?

Easy
288

An administrator is configuring an SD-WAN rule to distribute traffic across two WAN links based on the number of active sessions. They want to ensure that new sessions are assigned to the link with the fewest current sessions. Which load balancing algorithm should they use?

Easy
289

A FortiGate administrator is troubleshooting a site-to-site IPsec tunnel that intermittently drops. The administrator runs 'diagnose vpn ike gateway list' and observes that the tunnel re-establishes every few minutes, and 'diagnose debug application ike -1' shows repeated INVALID_KE_PAYLOAD notifications. The remote peer is a third-party gateway that only supports a specific Diffie-Hellman group. What is the most likely cause of the repeated renegotiation?

Medium
290

An HA cluster of two FortiGates is experiencing split-brain. After investigation, you find that the heartbeat link is down on the primary unit. Which action will resolve the split-brain condition?

Hard
291

A FortiGate administrator is deploying ZTNA to replace SSL VPN for remote access. The requirement is that endpoint posture (antivirus status, OS patch level) must be verified before a user is allowed to reach internal web applications through the ZTNA proxy, and that posture must be re-evaluated on each new connection. Which FortiGate configuration element is required to enforce this dynamic, per-connection posture check?

Medium
292

A FortiManager administrator wants to push policy package changes to a managed FortiGate, but wants to see what changes will be applied before committing. Which FortiManager feature should the administrator use?

Medium
293

An administrator wants to create an automation stitch that responds to a high-severity IPS event by blocking the attacker IP. Which THREE components are required to build this automation stitch?

Medium
294

An administrator is troubleshooting an OSPF over IPsec VPN overlay. The OSPF neighbor state is stuck in EXSTART. The VPN tunnel is up. Which TWO issues could cause this?

Hard
295

A FortiGate administrator wants to implement ZTNA to control access to an internal application server. Users will access the application via FortiClient. Which configuration step is REQUIRED to allow FortiClient to forward traffic to the ZTNA gateway?

Medium
296

In FortiManager, what is an automation stitch?

Easy
297

An SD-WAN rule is configured to steer traffic based on SLA metrics. The administrator notices that traffic is not using the expected member interface even though the SLA is meeting thresholds. What should the administrator check FIRST?

Medium
298

An administrator wants to automatically block a file that FortiSandbox has determined to be malicious. The FortiGate is configured with an antivirus profile that includes FortiSandbox submission. Which verdict action should be set to 'block' in the antivirus profile to achieve this?

Medium
299

An administrator is configuring ZTNA inline CASB on a FortiGate to control access to a sanctioned SaaS application. The requirement is to block uploads of files containing credit card numbers while allowing normal business uploads. The administrator creates an access proxy rule and a CASB profile with a data loss prevention sensor. During testing, uploads of files with credit card numbers are still allowed. Which action should the administrator take to enforce the block?

Medium
300

A multi-tenant FortiGate uses VDOMs. The administrator notices that logins via SSH to the management VDOM succeed, but attempts to SSH to a traffic VDOM's management IP fail. The traffic VDOM has an administrative user configured. What is the most likely cause?

Medium
301

An administrator has configured an SD-WAN zone named 'virtual-wan-link' with two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'SLA1' is created and assigned to the zone. The administrator wants to ensure that SD-WAN rules use the SLA results to select the best member. Which statement correctly describes how the FortiGate uses the performance SLA results in SD-WAN rule selection?

Medium
302

An administrator is troubleshooting an HA cluster where both units show as primary after a link failure. What is the most likely cause of this split-brain scenario?

Easy
303

An administrator configures SD-WAN with multiple members. The SD-WAN rule uses the 'latency' strategy. The administrator notices that traffic is not switching to the best-performing member even when latency exceeds the threshold. What could be the issue?

Hard
304

A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?

Medium
305

An administrator is troubleshooting a scenario where traffic from VLAN 100 to a server at 10.1.2.100 is being blocked. The FortiGate has an active security policy allowing the traffic and the routing table shows a correct route. Which TWO diagnostic commands should the administrator run to identify the cause of the blockage?

Medium
306

Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?

Hard
307

An administrator deploys a FortiGate in transparent mode within a Layer 2 network. They apply a firewall policy with an antivirus profile to inspect traffic between two VLANs. What is a key characteristic of transparent mode that affects policy application?

Medium
308

A FortiGate administrator enables Dead Peer Detection (DPD) on an IPsec VPN tunnel. What is the primary purpose of DPD?

Easy
309

An administrator runs 'get router info bgp summary' and sees that the BGP session to a neighbor is in the 'Idle' state. The neighbor IP is reachable via ping. The BGP configuration uses loopback interfaces with 'update-source loopback1'. What is the MOST likely reason for the Idle state?

Hard
310

What is the function of a VRF (Virtual Routing and Forwarding) on a FortiGate?

Easy
311

A FortiGate has multiple IPsec VPNs to different branch offices. The administrator notices that one VPN tunnel is flapping (going up and down repeatedly). From the CLI, 'diagnose vpn ike gateway list' shows the gateway state as 'up' but then quickly goes to 'down'. What is the MOST likely cause?

Hard
312

An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links based on the source IP address of the traffic. Which load balancing algorithm should be used to achieve this?

Easy
313

An administrator configures two FortiGate units in an active-passive HA cluster. During a failover test, the administrator notices that the secondary unit becomes primary but the session table is empty, causing all existing connections to drop. Which configuration change should be made to preserve session information during failover?

Medium
314

A FortiGate 600E is running multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 each have an inter-VDOM link interface named 'ivl-1' and 'ivl-2' respectively, and both are assigned IP addresses in the 10.10.10.0/30 subnet. VDOM-1 has a static route to 192.168.2.0/24 via 10.10.10.2, and VDOM-2 has a static route to 192.168.1.0/24 via 10.10.10.1. A user in VDOM-1 (192.168.1.10) cannot ping a server in VDOM-2 (192.168.2.10). What is the most likely cause?

Medium
315

A company uses SSL VPN with FortiGate for remote access. Users report that after connecting, they can access internal web servers but cannot ping them. Which configuration is most likely missing?

Hard
316

What is the primary difference between using a Web Application Firewall (WAF) on FortiGate versus using FortiWeb?

Easy
317

An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The configuration uses certificates for authentication. The admin sees the following log message: 'Certificate validation failed: unable to get local issuer certificate.' What is the most likely cause?

Easy
318

An organization uses FortiManager to manage multiple FortiGates. A junior admin accidentally deleted a critical firewall policy on one device and the change was auto-installed. How can the senior admin revert the device to the previous configuration?

Medium
319

An administrator configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. After configuration, traffic from VDOM-A cannot reach VDOM-B. Which configuration step is MOST likely missing?

Medium
320

A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?

Medium
321

A FortiGate 600E is configured with multiple VDOMs in NAT mode. The administrator wants to route traffic between VDOM-1 and VDOM-2 without using physical interfaces. They create a VDOM link named 'vlink' with interfaces vlink0 and vlink1, assign vlink0 to VDOM-1 (IP 10.0.1.1/30) and vlink1 to VDOM-2 (IP 10.0.1.2/30). However, traffic from a host in VDOM-1 (192.168.1.0/24) to a server in VDOM-2 (192.168.2.0/24) fails. The administrator has added static routes in both VDOMs pointing to the respective VDOM link IPs. What is the most likely cause of the failure?

Medium
322

An organization wants to prevent zero-day attacks by using Content Disarm and Reconstruction (CDR) on email attachments. Which Fortinet product provides this capability?

Medium
323

An administrator has configured a FortiGate HA cluster with two units. The cluster uses a virtual cluster for load balancing in active-active mode. The administrator notices that traffic from one VDOM is not being load-balanced and is only handled by one unit. What is the most likely cause?

Medium
324

An administrator has deployed a ZTNA configuration on a FortiGate where remote users authenticate through FortiClient EMS. The administrator wants to ensure that only devices with an up-to-date operating system and active antivirus are granted access to an internal web application. The FortiGate is configured as the ZTNA access proxy. Which FortiGate component or configuration is required to enforce these device compliance checks?

Hard
325

An administrator is configuring a FortiGate with VDOMs. The administrator wants to ensure that each VDOM has its own independent routing table and that routes in one VDOM do not affect another. Which statement about VDOM routing is correct?

Easy
326

Which FortiManager feature allows an administrator to roll back a policy package to a previous version?

Easy
327

A company with a hub-and-spoke SD-WAN topology uses FortiGates at each site. The hub has two WAN links: MPLS (10 Mbps) and broadband (100 Mbps). The spokes connect only via MPLS. The company deploys a new real-time application that requires low latency and low jitter. The network administrator creates an SD-WAN rule for this application with 'best quality' strategy and both MPLS and broadband as members. The SLA for MPLS is configured with latency < 10 ms and jitter < 5 ms. The SLA for broadband is configured with latency < 50 ms and jitter < 20 ms. The actual measured latency on MPLS is 12 ms, and jitter is 4 ms. The broadband latency is 25 ms, jitter 10 ms. Which path will the application traffic take?

Medium
328

An administrator wants to enforce that only devices with antivirus software installed and running can access a sensitive application via ZTNA. Which ZTNA feature should be used to verify this requirement?

Easy
329

A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?

Hard
330

A company uses FortiManager to manage multiple FortiGates. The admin wants to use a global ADOM to manage certain policies across all devices while allowing local customization. Which two statements about global ADOM are true? (Choose two.)

Medium
331

A security analyst wants to use automation stitches on FortiGate to automatically block an IP address when a critical severity event is logged. Which TWO components are essential to create this automation stitch? (Choose two.)

Medium
332

A FortiGate administrator wants to check if the device is experiencing high CPU usage due to a specific process. Which command should they use to display real-time process CPU usage?

Easy
333

An administrator needs to deploy a honeypot solution to detect and deceive attackers inside the network. Which Fortinet product is BEST suited for this purpose?

Medium
334

In FortiGate's ZTNA, what is the purpose of a 'ZTNA tag'?

Easy
335

A network administrator is troubleshooting a scenario where remote users can connect via FortiClient VPN but cannot access internal resources. The FortiGate has a valid IPsec VPN configuration. Which THREE checks should the administrator perform to resolve the issue?

Medium
336

A network security administrator is deploying a FortiSandbox appliance in a FortiGate environment. The administrator wants to ensure that when a zero-day malware sample is detonated, the FortiGate immediately blocks the file hash and the C2 callback. Which FortiSandbox integration method should the administrator configure on the FortiGate to achieve this?

Medium
337

You want to use policy-based routing (PBR) to send traffic from a specific subnet to a different next-hop than the default route. Which configuration is required?

Medium
338

A FortiGate administrator wants to use FortiManager to manage multiple FortiGates in different geographic regions. To isolate configuration changes, the administrator creates separate ADOMs for each region. Which type of ADOM should be used to allow some common objects (like address groups) to be shared across all regions?

Medium
339

A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?

Hard
340

In a hub-and-spoke VPN, spokes cannot communicate with each other directly. The administrator wants to allow direct spoke-to-spoke traffic without routing through the hub. Which technology should be configured?

Medium
341

An administrator has a FortiGate 600E running multiple VDOMs in NAT mode. The security team wants to inspect inter-VDOM traffic between VDOM-A and VDOM-B with a firewall policy that applies UTM profiles. The administrator has already created a VDOM link named vlink1 with interfaces vlink1-A in VDOM-A and vlink1-B in VDOM-B. What must the administrator do to ensure that inter-VDOM traffic is inspected by a security policy?

Medium
342

An administrator configures an automation stitch in FortiManager to execute a CLI script on a FortiGate when a specific event is triggered. The automation stitch is enabled but does not run when the event occurs. What is the most likely cause?

Hard
343

When troubleshooting an IPsec VPN phase 1 negotiation failure, which debug command should the administrator run to see detailed IKE negotiation messages?

Medium
344

A FortiGate administrator is configuring a multi-VDOM deployment. The administrator wants to use a single physical interface for multiple VDOMs. Which TWO methods allow this?

Medium
345

An administrator configured FortiGate to forward suspected malicious files to FortiSandbox. They set the action to 'block' for malicious verdicts. Some files are being blocked, but others with a 'clean' verdict are allowed. However, they notice that some files that should have been sent to FortiSandbox are not being forwarded. Which reason is MOST likely?

Hard
346

Based on the exhibit, what can be concluded about the session?

Hard
347

An administrator is configuring a FortiGate with multiple VDOMs in NAT/route mode. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. Which TWO statements about VDOM links are correct? (Choose two.)

Medium
348

A FortiGate administrator is configuring an IPsec VPN tunnel to a remote site that is behind a NAT device. The administrator notices that the tunnel establishes, but traffic intermittently fails. Which setting should be adjusted to improve reliability?

Medium
349

An administrator manages a FortiGate with VDOMs 'prod' and 'dev' on a single HA pair. The administrator wants 'prod' to fail over independently from 'dev' so that maintenance on the dev environment does not trigger a failover of prod. Which FortiGate feature should be configured?

Hard
350

A FortiGate administrator is setting up a ZTNA rule to allow access to an internal application only for users who are members of the 'Finance' group in FortiClient EMS. The administrator has already configured the ZTNA server and access proxy. Which additional configuration is required on the FortiGate to enforce this group membership?

Easy
351

A security engineer wants to implement advanced threat protection for email using FortiMail. Which THREE features should be enabled to provide comprehensive protection against sophisticated email threats? (Choose three.)

Hard
352

A FortiGate is deployed in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator creates an inter-VDOM link named IVL1 with interface ivl-1-0 in VDOM-1 and ivl-1-1 in VDOM-2. Static routes are configured in both VDOMs to route traffic across the link. However, traffic from VDOM-1 to VDOM-2 is dropped. What is the most likely reason?

Hard
353

During a ZTNA deployment, an administrator notices that traffic from a specific internal application is being routed through the ZTNA gateway but is not reaching the destination server. The FortiGate policy allows the traffic, and the client has a valid ZTNA connection. What is the most likely cause of the issue?

Hard
354

A FortiGate is configured as a ZTNA proxy. The administrator wants to ensure that only devices with a specific ZTNA tag assigned by FortiClient EMS are allowed to access the application. Which two configuration steps are required? (Choose two.)

Medium
355

A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing internal applications. The administrator wants to ensure that only authenticated and compliant devices can access the applications, and that all traffic is inspected. Which two actions are required to achieve this? (Choose two.)

Hard
356

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and observes that the 'ipsengine' process is consuming a large amount of CPU. The administrator suspects that a specific IPS signature is causing the issue. Which command should the administrator use to identify which IPS signature is triggering the high CPU usage?

Hard
357

An administrator is investigating a security incident where a workstation is communicating with a known command and control (C2) server. The FortiGate has IPS enabled but did not block the traffic. Which TWO configuration issues could explain why the IPS did not detect the C2 communication? (Choose two.)

Medium
358

An administrator configures a route map on a FortiGate to redistribute connected routes into OSPF. The route map sets a metric of 100. After applying, the redistributed routes appear with metric 20. What is the most likely reason?

Medium
359

A network administrator is troubleshooting an IPsec VPN tunnel that is not coming up. The configuration uses IKEv2 with pre-shared keys. The administrator runs 'diagnose vpn ike log-filter' and sees no logs. What is the most likely cause?

Medium
360

A FortiGate is configured with VRF. Which statement about VRF is true?

Medium
361

A security administrator is configuring a FortiGate to use an external threat intelligence feed to block malicious IP addresses. The administrator wants the FortiGate to automatically update the list of malicious IPs from a threat feed and use it in firewall policies. Which FortiGate feature should be used?

Medium
362

An administrator configures inter-VDOM routing between VDOMs A and B using a VDOM link. The administrator can ping from VDOM A to an interface in VDOM B, but traffic from VDOM B to VDOM A times out. What is the most likely cause?

Medium
363

An administrator is troubleshooting an SD-WAN deployment where traffic is not being forwarded according to the configured SD-WAN rules. The FortiGate has two WAN interfaces, port1 and port2, both members of an SD-WAN zone. A performance SLA is configured and both members are within SLA. The administrator suspects that the SD-WAN rules are not being evaluated correctly. Which two statements about SD-WAN rule evaluation are correct? (Choose two.)

Hard
364

An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?

Medium
365

You are troubleshooting BFD on a FortiGate SD-WAN deployment. BFD is configured on two WAN interfaces (wan1, wan2) with a minimum transmit interval of 100 ms and a multiplier of 3. The network experiences occasional jitter causing packet loss. After a brief outage, the BFD session does not recover. Which setting should be adjusted to improve BFD resilience without significantly increasing failover time?

Hard
366

A network administrator is configuring VDOMs on a FortiGate and wants to separate management traffic from production data traffic. What is the best practice when using a management VDOM?

Easy
367

A FortiGate administrator wants to use FortiManager automation stitches to automatically block an IP address when a specific threat is detected. Which components must be configured within the automation stitch?

Medium
368

An administrator configures an automation stitch on FortiGate to automatically block an IP address when a specific IPS signature triggers. What must be configured as the trigger and action?

Medium
369

A FortiGate administrator is configuring an IPsec VPN with IKEv2. The remote peer is behind a NAT device and has a dynamic public IP. The administrator wants the FortiGate to act as the responder and allow the remote peer to initiate the tunnel, while ensuring that only the remote peer's unique ID (FQDN) is accepted. Which configuration on the FortiGate is required to achieve this?

Medium
370

What is the purpose of a header policy in a FortiManager policy package?

Easy
371

A FortiGate in an HA cluster is experiencing intermittent session synchronization failures. The administrator runs 'diagnose sys ha dump sync-status' and sees that sessions are not being synchronized properly. Which TWO potential causes should the administrator investigate?

Medium
372

An administrator has deployed a FortiGate at a branch with two WAN links: port1 (primary) and port2 (backup). They create an SD-WAN zone and a performance SLA named 'ISP-Health' that monitors 8.8.8.8 using ping. The SLA is configured with link-cost-factor latency and a threshold of 50 ms. After a week, they notice that the primary link is still being used for all traffic even though its latency frequently exceeds 150 ms. The backup link has 20 ms latency. What is the most likely reason the SD-WAN rule is not failing over?

Medium
373

Which FortiGate feature allows the creation of multiple virtual routing tables within a single VDOM?

Easy
374

An administrator wants to isolate tenant traffic in a single FortiGate by creating separate virtual firewalls with independent routing tables, administrators, and policies. Which feature should the administrator use?

Easy
375

A FortiGate administrator is configuring an IPsec VPN to a remote peer behind a device that performs NAT. The administrator notices that the tunnel establishes but rekeys fail after the Phase 1 lifetime expires. Which setting should the administrator enable on the FortiGate to allow the IKE negotiation to survive NAT and pass through the NAT device reliably?

Easy
376

You are troubleshooting an SD-WAN rule where traffic is not matching the expected SLA. The FortiGate shows 'SLA mismatch' in logs. What is the MOST likely cause?

Medium
377

An administrator needs to verify that a FortiGate is correctly matching a firewall policy for traffic from 192.168.1.0/24 to 10.0.0.0/8. Which command provides a list of policies that match a given source and destination?

Easy
378

A FortiGate 600E is running multiple VDOMs in NAT mode. The administrator wants to assign a VLAN subinterface to VDOM-A while the parent physical interface remains in the root VDOM. Which configuration step is required to accomplish this?

Medium
379

During a ZTNA implementation, the administrator configures a ZTNA rule for an internal application but users cannot connect. The FortiGate policy is correct and the application is reachable from the FortiGate. What is the most likely misconfiguration?

Hard
380

What is the difference between a global ADOM and a regular ADOM in FortiManager?

Easy
381

A company wants to use FortiMail to implement email authentication to prevent spoofing. Which THREE mechanisms should be configured in FortiMail's Authentication Profile?

Medium
382

Based on the debug flow output, what is the reason the packet is dropped?

Hard
383

A FortiGate is configured with ECMP load balancing for equal-cost routes. The administrator wants to ensure that all traffic from a specific source IP uses the same next hop. Which ECMP load balancing method should be selected?

Medium
384

An administrator is configuring a FortiGate to detect and block traffic to known malicious domains using DNS filtering. The administrator wants to ensure that DNS queries for malicious domains are blocked and that users are redirected to a block page. Which DNS filter action should be configured?

Medium
385

An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal web application. The current network uses FortiGate as the firewall. Which component is required to enforce ZTNA policies on the FortiGate?

Easy
386

During a security incident, the SOC team receives an alert from FortiSIEM about a user accessing a known malicious IP. The team wants to automatically block the IP on the FortiGate. Which FortiGate feature can be used to create an automated response based on a threat intelligence feed?

Hard
387

A FortiGate has two VDOMs: Root and CustomerA. The administrator wants to manage the CustomerA VDOM from FortiManager. What must be configured on FortiManager to allow management of the CustomerA VDOM?

Medium
388

An HA cluster of two FortiGates is experiencing split-brain. Which command should the administrator use to check the current HA status and identify which unit is the primary?

Easy
389

An administrator wants to configure a multi-peer IPsec VPN where one FortiGate (hub) connects to multiple remote FortiGates (spokes) using a single phase 1 interface with dynamic IP addresses. Which configuration is required on the hub?

Easy
390

Which FortiMail advanced feature allows the administrator to rewrite URLs in email bodies to redirect users to a safe scanning service when they click on a link?

Medium
391

A FortiGate is configured with BGP and OSPF. The administrator wants to ensure that routes learned via BGP are redistributed into OSPF, but only specific prefixes. Which three components are needed? (Select THREE.)

Hard
392

An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links. The administrator wants to distribute traffic based on the source IP address to ensure that each source uses a consistent path. Which load balancing algorithm should be used?

Easy
393

A FortiGate admin notices that HTTPS traffic to a web server is not being scanned by the antivirus profile applied to the firewall policy. The admin confirms the policy is correct and antivirus is enabled. What is the MOST likely reason the traffic is not being scanned?

Medium
394

During a failover test in an HA cluster, the administrator observes that the secondary unit becomes primary but does not have the latest configuration. What is the most likely cause?

Medium
395

Which of the following is a required step when enabling VDOMs on a FortiGate for the first time?

Easy
396

What is the purpose of configuring BFD (Bidirectional Forwarding Detection) on a FortiGate?

Easy
397

A FortiGate administrator is troubleshooting a policy that is supposed to allow HTTP traffic from an internal subnet to a web server. Users report that they cannot access the web server. The administrator runs 'diagnose debug flow' and sees that the traffic is being denied by policy 0. What is the most likely cause?

Easy
398

A FortiGate is configured with three VDOMs: root, Sales, and Engineering. The administrator wants to ensure that the Sales VDOM can access the internet through the root VDOM, but the Engineering VDOM must not have any internet access. All VDOMs are currently in NAT mode. Which configuration is required to achieve this?

Medium
399

A FortiGate administrator is configuring a firewall policy to inspect traffic for advanced threats. The administrator wants to ensure that the policy uses both antivirus and IPS inspection, and that the traffic is inspected in a way that minimizes latency while still detecting threats. Which two actions should the administrator take? (Choose two.)

Medium
400

A FortiGate is configured with ECMP load balancing for multiple equal-cost routes. The administrator wants to ensure that all packets belonging to the same session go out the same interface. Which ECMP load balancing method should be used?

Hard
401

An organization wants to implement Zero Trust Network Access (ZTNA) to secure access to an internal application. The application is hosted on a server with IP 10.1.1.100. Which component acts as the intermediary between users and the application in FortiGate ZTNA?

Easy
402

A FortiGate with SD-WAN has two members: MPLS (port1) and Broadband (port2). The performance SLA is configured to monitor latency and packet loss. The administrator notices that after a brief outage on the MPLS link, traffic fails over to Broadband but does not fail back when MPLS recovers. What is the likely cause?

Medium
403

What is the primary function of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus profile?

Easy
404

What is the purpose of Dead Peer Detection (DPD) in an IPsec VPN?

Easy
405

An administrator needs to check the current CPU and memory usage of a FortiGate to determine if resource exhaustion is causing network delays. Which CLI command provides a real-time, top-like view of processes and their resource consumption?

Easy
406

A network administrator wants to ensure that files downloaded from the internet are analyzed by FortiSandbox before being delivered to the client. The FortiGate is configured with a FortiSandbox connection and an antivirus profile. Which setting must be enabled in the antivirus profile to submit files to FortiSandbox?

Medium
407

An administrator has configured BGP on a FortiGate with two upstream ISPs. They notice that traffic to a specific prefix is not load-balanced as expected; all traffic goes through ISP1 even though both paths are available. 'get router info bgp network' shows the prefix with two next hops. What is the MOST likely cause?

Hard
408

An administrator has configured a FortiGate with an SD-WAN zone named 'virtual-wan-link' containing two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'CriticalSLA' monitors a server at 8.8.8.8 using ICMP probes every 5 seconds, with failure thresholds: latency 200 ms, jitter 50 ms, packet loss 5%. The SLA status for port1 is 'alive' and for port2 is 'dead'. An SD-WAN rule is configured to use the 'lowest-cost' algorithm with the SLA target 'CriticalSLA'. The administrator notices that all traffic is being routed through port1, even though port2 has a lower cost metric. What is the most likely reason for this behavior?

Medium
409

What is the purpose of using a prefix list in route redistribution?

Easy
410

A FortiGate administrator is configuring an IPsec VPN with IKEv2 between two sites. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the phase 2 selectors are restricted to specific subnets. Which two configuration elements are required to meet these goals? (Choose two.)

Hard
411

A FortiGate administrator is troubleshooting a connectivity issue where users cannot access a web server behind the FortiGate from the internet. The administrator suspects that the virtual IP (VIP) configuration is incorrect. Which two commands should the administrator use to verify the VIP configuration and its associated firewall policy? (Choose two.)

Medium
412

An administrator needs to configure an SD-WAN rule that routes traffic from the guest VLAN to the Internet using the most cost-effective link. The SD-WAN zone contains three members: port1 (MPLS, cost 10), port2 (Broadband, cost 5), and port3 (LTE, cost 20). All members meet the performance SLA. Which load balancing algorithm should be used to ensure traffic uses the lowest-cost link?

Easy
413

An administrator configures a firewall policy with an application control profile to block social media. The administrator observes that some social media traffic is still passing through. The traffic is HTTPS. What additional configuration is REQUIRED for application control to effectively block HTTPS-based social media?

Hard
414

A FortiGate is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the process 'ipsengine' is using the most CPU. What is the most likely cause?

Easy
415

An administrator needs to monitor FortiGate session count and CPU usage over time using FortiAnalyzer. Which log type should be configured for this?

Easy
416

A FortiGate is configured with ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing credit card numbers. Which ZTNA inline CASB feature should be used?

Hard
417

An HA cluster (active-passive) is configured. The administrator wants to perform a failover test without causing service disruption. Which command should be used?

Medium
418

A FortiGate administrator is configuring an IPsec VPN with IKEv2 and wants to ensure that the tunnel uses perfect forward secrecy (PFS). Which phase2 configuration is required?

Easy
419

A network administrator is configuring SD-WAN on a FortiGate. The organization has two internet links: MPLS (primary) and broadband (backup). The administrator wants all traffic to use the MPLS link unless it fails, in which case traffic should fail over to the broadband link. Which SD-WAN configuration best achieves this requirement?

Easy
420

An enterprise uses multiple VDOMs on a FortiGate. The administrator needs to route traffic between VDOM-A and VDOM-B using a firewall policy. What is the correct configuration step?

Medium
421

A FortiGate administrator runs 'diagnose debug application sslvpn -1' and sees repeated messages: 'SSL VPN tunnel error: no response from client'. What is the most likely cause?

Medium
422

Which of the following is the primary purpose of BFD (Bidirectional Forwarding Detection) on a FortiGate?

Easy
423

An administrator configures BFD on a BGP session between two FortiGates. After enabling BFD, the BGP session flaps intermittently. What is the most likely cause?

Hard
424

An administrator sees the following output from 'get router info routing-table': S 0.0.0.0/0 [10/0] via 192.168.1.1, port1 S 0.0.0.0/0 [10/0] via 192.168.2.1, port2 They have configured ECMP load balancing. However, traffic to a specific destination IP is always using port1. What is the likely reason?

Medium
425

Which feature in FortiOS enables a FortiGate to act as a proxy for client-initiated connections to internal applications without requiring a VPN client, by verifying device posture and user identity?

Easy
426

A network admin needs to apply a common set of firewall rules at the beginning of every policy package for all VDOMs managed by FortiManager. The rules should be automatically inserted and not editable within each VDOM. What should be configured?

Medium
427

An administrator needs to enable automation stitches to automatically block a malicious IP address detected by FortiSandbox. Which two components are required? (Choose two.)

Medium
428

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

Hard
429

A FortiGate administrator is deploying ZTNA with a FortiClient EMS that tags endpoints as 'compliant' or 'non-compliant'. The administrator wants the FortiGate to grant access only to endpoints that FortiClient EMS has tagged as compliant, while still allowing non-compliant endpoints to reach a remediation portal. Which two configuration elements on the FortiGate must be aligned to enforce this?

Hard
430

A security administrator is configuring a FortiGate to block outbound traffic to known command-and-control (C2) servers. The administrator wants to use a dynamic, cloud-based threat intelligence service that is continuously updated by Fortinet. Which FortiGuard service should be enabled to block traffic based on the latest C2 IP addresses and domains?

Medium
431

A FortiGate administrator is configuring an ADVPN with a hub-and-spoke topology. The administrator wants to ensure that spoke-to-spoke traffic can be dynamically established without traversing the hub for every packet. The administrator also wants to ensure that the shortcut tunnels are only established when necessary and are torn down when no longer used. Which two statements about ADVPN shortcut tunnels on FortiGate are correct? (Choose two.)

Hard
432

Which TWO actions are appropriate when troubleshooting a slow network connection through a FortiGate?

Medium
433

Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per SD-WAN member?

Easy
434

An administrator is integrating a FortiExtender with a FortiGate. The FortiExtender is connected to port5 and configured with a cellular WAN connection. What must be configured on the FortiGate to allow the FortiExtender to provide WAN connectivity as an SD-WAN member?

Hard
435

A customer reports intermittent connectivity issues between two internal subnets separated by a FortiGate firewall. The traffic is allowed by the policy, but users experience timeouts during peak hours. Which troubleshooting step should you take first?

Medium
436

Which FortiGate IPS feature allows administrators to create rules that detect network traffic patterns deviating from normal protocol behavior?

Easy
437

A company uses FortiMail for email security. They want to prevent email spoofing by verifying that incoming emails originate from authorized servers. Which email authentication method should be configured on FortiMail to check the sending server's IP against a published SPF record?

Medium
438

A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route for 192.168.100.0/24 into OSPF. After configuring 'config router ospf' with 'redistribute static' enabled, the route appears in the OSPF database but is not being advertised to other areas. What is the most likely cause?

Hard
439

A FortiGate administrator configures a ZTNA access proxy rule to allow access to an internal application only if the user's device has the tag 'Compliant'. The tag is assigned by FortiClient EMS. However, a user with a compliant device is still blocked. The admin sees in the ZTNA logs that the tag is not being received. What should the administrator check FIRST?

Medium
440

You run the following command on a FortiGate: 'diagnose vpn ike gateway list' and see that the DPD status for a VPN peer is 'dead'. What does this indicate?

Medium
441

A FortiGate is configured with a VIP (virtual IP) for an internal web server. Users report that the web server is unreachable from the internet, but it works from the internal network. The administrator runs 'diagnose sniffer packet any "host 203.0.113.10 and port 80" 4' and sees incoming packets on the wan1 interface but no outgoing packets on the internal interface. What is the MOST likely cause?

Hard
442

A network security team is evaluating options for web application security. They need to protect a critical web application from SQL injection and cross-site scripting (XSS) attacks, and they require granular control over HTTP request parameters. Which THREE factors should influence their decision between using FortiGate's WAF profiles versus deploying a dedicated FortiWeb appliance?

Hard
443

An administrator runs 'diagnose ips anomaly http' and sees many entries with 'type=SQLi' and 'score=0'. What does a score of 0 indicate?

Hard
444

An administrator is configuring FortiMail to improve email security. Which three of the following features are part of FortiMail's advanced threat protection? (Choose three.)

Hard
445

A FortiGate administrator is configuring ZTNA inline CASB to control access to a SaaS application. The administrator wants to block uploads of files containing sensitive data while allowing other operations. Which ZTNA inline CASB configuration is required to achieve this?

Hard
446

An administrator needs to configure VRF to separate traffic for two departments. Which TWO components must be configured for each VRF?

Medium
447

Which FortiAnalyzer feature allows an administrator to create a sequence of automated response actions triggered by a specific log event?

Easy
448

A FortiGate administrator wants to use threat intelligence feeds to block known malicious IP addresses. Which TWO steps are required to accomplish this? (Choose two.)

Medium
449

An administrator configures two VDOMs as shown in the exhibit. They create an inter-VDOM link between VDOM1 and VDOM2. They then add a firewall policy in VDOM1 allowing traffic from port1 to the inter-VDOM link, and a policy in VDOM2 allowing traffic from the inter-VDOM link to port2. However, traffic from 192.168.1.10 to 10.10.10.50 fails. What is the most likely cause?

Medium
450

An admin runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

Hard
451

A FortiGate administrator is using the built-in FortiGuard web filter to block malicious websites. Users report that they can still access a site that is categorized as 'Malware' by FortiGuard. The administrator verifies that the web filter profile is applied to the policy and that the category is set to block. What is the most likely reason for this issue?

Medium
452

An administrator configures a WAF profile on FortiGate to protect a web application. However, the administrator notices that SQL injection attacks are not being blocked. What should the administrator check first?

Medium
453

Which of the following best describes the function of FortiDeceptor in an enterprise network?

Easy
454

A FortiGate administrator is configuring SSL VPN for remote users. The administrator wants to ensure that users can only access specific internal resources based on their user group. Which SSL VPN configuration mode should be used to provide granular access control?

Easy
455

A FortiGate is deployed with two ISPs and SD-WAN. The organization uses OSPF to exchange routes with a remote branch. The administrator notices that the FortiGate is not installing OSPF-learned routes into the routing table. The OSPF configuration is verified to be correct, and neighbors are established. Which configuration could be causing the issue?

Hard
456

An administrator is configuring a FortiGate to block outbound traffic to known malicious IP addresses. They want the block list to be updated automatically from a commercial threat intelligence service that provides a REST API. Which FortiGate feature should be used?

Medium
457

An administrator is troubleshooting an SD-WAN rule that is not matching traffic as expected. The rule is configured with a source address of 'all', destination '10.0.0.0/24', and service 'HTTP'. The rule is placed after a rule that matches all traffic to '10.0.0.0/24' with service 'ALL'. The administrator notices that HTTP traffic to 10.0.0.0/24 is being handled by the first rule. What is the most likely cause?

Hard
458

An administrator wants to enforce that only devices with the latest antivirus signatures and a corporate disk encryption solution can access a sensitive application via ZTNA. Which two FortiClient EMS components must be configured? (Choose two.)

Easy
459

Drag and drop the steps to configure a FortiGate as a DHCP server into the correct order.

Medium
460

Which Fortinet product is designed specifically to detect and deceive attackers by creating decoy systems and luring them away from real assets?

Easy
461

An administrator configures a prefix list to filter routes received from a BGP neighbor. The prefix list permits 192.168.0.0/16 le 24. Which routes are permitted?

Medium
462

A FortiGate administrator is configuring a ZTNA rule to allow access to an internal web application only for users who authenticate with multi-factor authentication (MFA). The administrator has configured the ZTNA rule to require the 'MFA' tag from FortiClient EMS. However, users who have MFA enabled are still being denied access. What is the most likely reason?

Easy
463

An administrator wants to ensure that FortiGate validates the identity of the remote VPN peer using a certificate during IKEv2 phase 1. Which authentication method should the administrator select in the IPsec phase 1 configuration?

Easy
464

An administrator needs to ensure that all firewall policies in a FortiGate VDOM have a common set of inspection profiles added at the end of the policy list. Which FortiManager feature best achieves this?

Medium
465

A network administrator needs to configure SD-WAN on a FortiGate to distribute traffic across two WAN links based on session count. Which load balancing algorithm should be selected in the SD-WAN rule?

Easy
466

An administrator is configuring ZTNA inline CASB for a SaaS application. The goal is to block upload of files containing credit card numbers. Which configuration components are required?

Hard
467

A FortiGate is managed by FortiManager. The administrator creates a new policy package for VDOM 'Sales' and installs it. Later, they find that the previous configuration has been overwritten. What should the administrator do to avoid this in the future?

Medium
468

A network admin needs to configure a FortiGate to load balance traffic across two ISP links using SD-WAN. The requirement is to use both links simultaneously for different sessions based on source-destination IP hash. Which two settings are required? (Select TWO.)

Medium
469

A FortiGate administrator is troubleshooting an IPsec VPN where Phase 1 completes but Phase 2 fails to establish. The administrator reviews the Phase 2 configuration and notices that the local and remote subnets do not match between the two peers. Which action should the administrator take to resolve the Phase 2 failure?

Medium
470

An organization uses FortiWeb to protect its web applications. The security team wants to block requests that contain a specific custom pattern in the URL. Which feature should be used?

Medium
471

A FortiGate is configured with multiple VDOMs. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B. The administrator creates an inter-VDOM link and assigns IP addresses to both ends. Which additional configuration is required to allow traffic to pass between the VDOMs?

Medium
472

What is the primary purpose of Content Disarm and Reconstruction (CDR) in advanced antivirus protection?

Easy
473

A BGP peering between two FortiGates is not establishing. The administrator runs 'get router info bgp neighbor' and sees that the neighbor state is 'Idle' and the BGP configuration appears correct. What should the administrator check next?

Hard
474

During a failover test in an HA cluster, the primary FortiGate fails over to the secondary. After failover, some existing TCP sessions are dropped. What is the MOST likely reason?

Medium
475

A FortiGate is configured with a VIP (virtual IP) to publish an internal web server to the internet. External users report that they cannot access the web server, but internal users can access it using its private IP. The administrator runs 'diagnose debug flow' and sees that traffic from external users is being dropped with the message 'iprope_in_check() check failed, drop'. What is the most likely cause?

Hard
476

An organization wants to implement a solution that can detect and automatically respond to threats across multiple Fortinet security products. Which product should they use?

Medium
477

An administrator has configured FortiSandbox integration with FortiGate. Files are being submitted, but the firewall is not blocking subsequent downloads of files that FortiSandbox later identifies as malicious. The administrator verifies that the FortiSandbox license is valid and the connection is up. Which configuration is most likely missing?

Hard
478

What is the primary purpose of FortiGuard Outbreak Prevention service?

Easy
479

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is up but traffic is not passing. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA has been established. However, 'diagnose vpn tunnel list' shows no IPsec SA entries. What is the most likely cause?

Medium
480

An administrator configures a hub-and-spoke ADVPN with FortiGate at the hub and multiple remote sites. After setup, spokes establish shortcuts directly. However, traffic between two spokes consistently goes through the hub even though shortcuts should exist. Running 'diagnose npu np6 ipsec peercache' shows no shortcut entries. What is the MOST likely reason?

Hard
481

An organization wants to prevent users from downloading malicious files from the internet. Which FortiGate security profile should be applied to the outbound firewall policy to block files based on their hash if they have been identified as malicious by FortiSandbox?

Easy
482

A FortiGate is configured with two VRF instances: VRF10 (for the finance department) and VRF20 (for the engineering department). Each VRF has its own routing table and interfaces. The administrator needs to allow a server in VRF10 (10.10.10.10) to communicate with a server in VRF20 (10.20.20.20). The administrator has already configured the necessary firewall policies to allow the traffic. However, pings from 10.10.10.10 to 10.20.20.20 fail. What is the most likely cause?

Hard
483

An organization uses FortiClient EMS to enforce compliance on endpoints. They want to ensure that only devices with updated antivirus definitions can access the corporate VPN. Which FortiClient configuration should be applied?

Easy
484

A FortiGate administrator wants to stop outbound DNS queries to a known malicious domain that is not present in any static blocklist. The administrator has already licensed FortiGuard DNS Filtering and enabled DNS filtering on the firewall policy. Which FortiGuard service must the FortiGate resolve the domain against so that the query is blocked based on the latest threat intelligence?

Medium
485

A network administrator is troubleshooting a scenario where FortiView in FortiAnalyzer shows no traffic data for a specific FortiGate, but logs are being received. Which two possible causes should the administrator investigate? (Choose two.)

Hard
486

A FortiGate administrator is troubleshooting an issue where IPsec VPN traffic is not being forwarded correctly in a multi-VDOM environment. Which TWO factors should the administrator verify?

Medium
487

An administrator is configuring an SD-WAN rule to prefer a specific overlay tunnel for VoIP traffic. The rule uses the 'SLA' strategy with a performance SLA that measures jitter and latency. After applying the rule, the administrator notices that VoIP traffic is still being routed over a different member that does not meet the SLA. What is the most likely cause?

Medium
488

A FortiGate administrator is troubleshooting why a custom IPS signature is not triggering on traffic matching the pattern. Which TWO checks should be performed?

Hard
489

A multinational company uses FortiGate devices as VPN gateways to connect its headquarters (HQ) and branch offices via IPsec VPN tunnels. The company is migrating its remote access solution from IPsec VPN to SSL VPN using FortiClient. Currently, 500 remote users connect via IPsec VPN with pre-shared keys and XAuth authentication. The migration must be seamless with minimal downtime, and users must continue to authenticate using their existing Active Directory credentials. The SSL VPN portal must provide access to internal web applications and some legacy TCP-based applications that do not support HTTP. The security team requires that all traffic between remote users and the internal network be encrypted and that the SSL VPN use a certificate from a public CA to avoid certificate warnings on client devices. The IT team wants to use FortiToken for two-factor authentication (2FA) for all VPN users. Which of the following is the most appropriate course of action to meet all requirements?

Easy
490

A FortiGate is configured with multiple VDOMs. The administrator needs to provide a network engineer with read-only access to all VDOMs, but the engineer should not be able to make any configuration changes. Which administrative profile configuration should the administrator use?

Medium
491

A FortiGate admin sees the following log: 'Action=blocked, Service=HTTP, Application=Outbreak, File=invoice.doc, ThreatScore=95'. What is the MOST likely explanation for this block?

Hard
492

An administrator needs to back up the configuration of a FortiGate managed by FortiManager before making major changes. Which feature in FortiManager should the administrator use?

Easy
493

Which Fortinet product is designed to deploy decoy systems to lure attackers and detect lateral movement within the network?

Easy
494

An administrator runs 'diagnose sys session list' and sees sessions with 'proto=6 proto_state=02' and a long duration. The administrator is troubleshooting why sessions are not being terminated after a policy change that should block the traffic. What does 'proto_state=02' indicate?

Hard
495

An administrator wants to create an automation stitch that sends a webhook notification when an IPS attack is detected. Which trigger and action should be used?

Medium
496

A FortiGate 600E is running in multi-VDOM mode and is managed by FortiManager. The administrator needs to assign CPU and memory resource limits to a specific VDOM so that it cannot consume more than 30% of the system's resources. Which FortiGate feature should the administrator configure?

Medium
497

You run 'diagnose sys session filter dport 179' on a FortiGate and see many sessions with proto=6 and proto_state=01. What does this indicate about the BGP sessions?

Hard
498

Which FortiGate feature is used to detect link failures within milliseconds, allowing rapid convergence for routing protocols like OSPF and BGP?

Easy
499

An administrator notices that a FortiGate's CPU is consistently high, and the performance dashboard shows the 'ipsengine' process consuming most CPU. The administrator suspects a specific traffic pattern is overwhelming the IPS engine. Which CLI command should be used to identify the top sessions by bandwidth that may be triggering the IPS engine?

Medium
500

Refer to the exhibit. A user reports that accessing a legitimate HTTPS website is blocked. The FortiGate logs show that the connection was denied by the antivirus profile. What is the most likely cause?

Medium
501

An administrator is configuring FortiClient EMS to enforce compliance for ZTNA. Which TWO settings are required on FortiGate to use compliance-based ZTNA tags?

Medium
502

A FortiGate administrator is configuring a ZTNA rule that uses a proxy-based policy to inspect traffic to a web application. The administrator wants to ensure that only users who have a valid certificate installed on their endpoint are allowed access. The certificate is issued by the corporate PKI and is stored in the user's certificate store. Which ZTNA configuration element should the administrator use to enforce this requirement?

Hard
503

Which FortiGate security feature removes potentially malicious active content from files (e.g., macros, scripts) before delivering them to end users?

Easy
504

Which routing protocol is commonly used in SD-WAN deployments to exchange routes between FortiGate and the provider edge router in an MPLS network?

Easy
505

What is the role of FortiGuard Outbreak Prevention in FortiGate's security suite?

Easy
506

A FortiGate admin configures a firewall policy with an antivirus profile in flow-based inspection mode. The admin notices that some large files are being scanned but others are allowed without scanning. What is the most likely cause?

Hard
507

A FortiGate is configured with an IPsec VPN tunnel to a remote peer. The tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. The administrator then runs 'diagnose debug flow' and sees that traffic is being dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause of the drop?

Hard
508

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator wants to assign a physical interface to a non-management VDOM. The interface currently belongs to the root VDOM and has an IP address. What must the administrator do first?

Medium
509

An administrator configures an automation stitch to respond to a high severity event. The trigger is 'event' and the action is 'CLI script'. What must be defined for the action to execute properly?

Medium
510

A FortiGate administrator is investigating a slow network issue. The 'diagnose sys session stat' shows a high number of sessions. Which THREE commands can help identify the source of the high session count?

Hard
511

A FortiGate is configured with a VIP (virtual IP) for an internal web server at 10.0.0.10, mapping to public IP 203.0.113.5. External users report that they cannot access the web server, but internal users can access it using the private IP. The administrator runs 'diagnose debug flow filter addr 203.0.113.5' and 'diagnose debug flow show function-name enable' and sees the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 203.0.113.5:443->198.51.100.10:54321) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-10.0.0.10 via port2"'. No further output appears. What is the MOST likely cause of the issue?

Hard
512

Which feature allows a FortiGate to participate in multiple routing tables simultaneously, enabling network segmentation and overlapping IP address spaces?

Easy
513

An administrator needs to view real-time traffic logs and top applications for a specific VDOM on FortiAnalyzer. Which tool should be used?

Easy
514

A company uses an advanced antivirus profile with machine learning engine enabled. After a recent outbreak, several files that were previously undetected are now flagged. How does the outbreak prevention feature help in this situation?

Hard
515

An administrator is troubleshooting why a FortiGate is dropping traffic from a specific source IP (10.1.1.100). The administrator wants to see real-time per-packet details including the reason for drops. Which CLI command should the administrator use?

Medium
516

A FortiGate 600E is deployed with multiple VDOMs in NAT/route mode. The administrator assigns VLAN 100 to VDOM-A on port1 and VLAN 200 to VDOM-B on port1, then configures the VLAN interfaces as management interfaces for each VDOM. Users in VDOM-A report intermittent connectivity to servers in VDOM-B, while pings between the VLAN interface IPs fail. What is the most likely cause?

Medium
517

An organization wants to use FortiManager to manage multiple FortiGate devices. The administrator needs to ensure that each device group has separate policy and object configurations. Which FortiManager feature should be configured?

Medium
518

What is the purpose of a management VDOM on a FortiGate?

Easy
519

A FortiGate administrator is configuring an IPsec VPN with multiple peers for redundancy. The administrator wants to ensure that if the primary peer becomes unreachable, the tunnel fails over to the secondary peer automatically. Which configuration is required to achieve this?

Medium
520

A company's FortiGate is configured with multiple IPsec VPN tunnels to branch offices. One tunnel keeps dropping and re-establishing every few minutes. The logs show 'IPsec SA negotiation failed' with error 'proposal mismatch'. What is the most likely cause?

Medium
521

An administrator sees the following error when trying to commit changes from FortiManager to a FortiGate: 'Policy check failed: Policy ID 5 uses a zone that does not exist on the device.' What is the most likely cause?

Medium
522

An administrator wants to secure email traffic by ensuring that incoming emails are verified against the sender's domain SPF record. Which email authentication method provides this verification?

Easy
523

An administrator is troubleshooting SD-WAN and runs the following CLI command: 'execute sdwan-health-check status' The output shows that one SD-WAN member has a status of 'dead'. What does this indicate?

Medium
524

An administrator is configuring FortiAnalyzer to receive logs from FortiGates in a multi-VDOM environment. The admin wants to ensure that logs from each VDOM are separated into their own datasets. What must be configured?

Hard
525

Which FortiManager feature allows administrators to view the exact configuration changes that would be applied to a managed FortiGate before committing them?

Easy
526

A security administrator is deploying FortiDeceptor in a data center network. They want to detect an attacker who is performing internal reconnaissance by scanning the subnet for live hosts. Which FortiDeceptor component should the administrator deploy to generate a decoy IP address that responds to such scans and alerts on any interaction?

Medium
527

An administrator is configuring SSL VPN on FortiGate and wants to allow users to access internal applications via a web portal without installing any client software. Which SSL VPN mode should be used?

Easy
528

A network administrator is troubleshooting an SD-WAN setup where a specific application is not using the intended overlay tunnel. The SD-WAN rule is configured with a destination of 'all' and a source of 'all', and the strategy is set to 'manual' with the overlay tunnel as the preferred member. However, traffic is still going out via the underlay. What is the most likely reason?

Medium
529

A FortiGate admin notices that sessions to a particular server are not being logged in FortiAnalyzer. The firewall policy has logging enabled. What is the MOST likely reason?

Medium
530

An administrator needs to generate a report showing top applications by bandwidth usage across all VDOMs for the last 30 days. Which FortiAnalyzer feature should be used?

Medium
531

An administrator wants to see the current sessions for a specific source IP address 192.168.1.10. Which CLI command should be used?

Easy
532

A FortiGate administrator is configuring an antivirus profile to protect against unknown malware. The administrator wants to use machine learning to detect malicious files based on their behavior and characteristics without relying solely on signatures. Which antivirus feature should be enabled to meet this requirement?

Easy
533

An administrator deploys ZTNA with FortiGate as the access proxy for internal web applications. Users authenticate through FortiClient EMS, and device posture checks must be enforced before access is granted. A user with a compliant laptop can reach the application, but when the same user connects from a personal device that fails the posture check, the connection is still allowed. The administrator verifies the ZTNA rule is enabled and the EMS connector is up. Which configuration element is most likely missing to enforce device posture?

Medium
534

Which feature in FortiMail provides an additional layer of protection by analyzing the behavior of email attachments in a sandbox environment?

Easy
535

A security administrator wants to generate a weekly report in FortiAnalyzer that shows the top threats detected by the FortiGate. Which feature should the administrator use to create this report?

Medium
536

An administrator is configuring an SD-WAN rule that uses the 'volume' load balancing algorithm. The rule includes two members: port1 with a volume ratio of 3, and port2 with a volume ratio of 1. Which two statements correctly describe how the FortiGate will distribute sessions? (Choose two.)

Medium
537

A FortiGate administrator is setting up a ZTNA environment where FortiClient EMS is used to tag endpoints. The administrator wants to create a firewall policy that allows access to a web application only for users whose endpoints have the tag 'Compliant'. Which configuration step is required to use the tag in the firewall policy?

Easy
538

An administrator wants to integrate a FortiExtender into an existing SD-WAN deployment. Which TWO steps are required for proper integration?

Medium
539

What is the purpose of a management VDOM in a multi-VDOM FortiGate deployment?

Easy
540

A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees that the IKE gateway is stuck in the 'connecting' state. The administrator confirms that the pre-shared key matches on both peers. Which action should the administrator take next to identify the cause?

Medium
541

An administrator has an SD-WAN deployment with two members, port1 (primary, low latency) and port2 (secondary, high latency). A performance SLA is configured using a ping probe to 8.8.8.8 with a 100 ms latency threshold. The SLA status for port1 is 'alive' and for port2 is 'dead'. The administrator creates an SD-WAN rule with the 'SLA' strategy that includes both members. They expect traffic to use port1 and, if it fails, port2. However, after applying the rule, all traffic is still going out port1 and never uses port2. What is the cause of this behavior?

Medium
542

A FortiGate administrator is troubleshooting an IPsec VPN that uses IKEv2 and certificate authentication. The tunnel fails to establish, and the administrator sees that the phase 1 negotiation reaches the point of exchanging certificates but then fails. The administrator wants to verify the certificate-related configuration. Which two actions should the administrator take to resolve the issue? (Choose two.)

Hard
543

Which THREE conditions must be met for an IPsec VPN to successfully establish phase2?

Medium
544

A company uses FortiGate ZTNA to provide remote access to an internal web application. The application requires client certificates for authentication. The administrator has configured the ZTNA rule to use certificate authentication. However, users report that they are prompted for credentials repeatedly. What is the most likely cause?

Medium
545

What is the function of a route map in FortiGate routing?

Easy
546

An administrator is configuring a FortiGate to detect and block command and control (C2) traffic using FortiGuard's Indicator of Compromise (IoC) service. The administrator wants to ensure that the firewall checks DNS queries and HTTP requests against the IoC database. Which feature should be enabled on the FortiGate to accomplish this?

Medium
547

A FortiGate is configured with an SSL inspection profile that uses a deep-inspection mode. Users complain that a banking website fails to load, but HTTP sites work. The administrator confirms the site uses TLS 1.3 with Encrypted Client Hello (ECH) and certificate pinning. Which action should the administrator take to restore access while maintaining visibility for other traffic?

Hard
548

An administrator configures FortiGate as a SAML identity provider (IdP) for a cloud application. The application (SP) initiates the login. Users are redirected to the FortiGate login page and authenticate successfully, but then receive an error from the SP. What is a common cause?

Medium
549

An administrator configures a custom IPS signature to detect traffic to a specific malicious domain. Which syntax is correct for a custom IPS signature in FortiGate?

Hard
550

An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The Phase 1 status shows 'init' and the debug output indicates 'no suitable proposal found'. The remote peer is a third-party VPN device. Which of the following is the MOST likely cause?

Hard
551

In a multi-VDOM deployment, an administrator needs to route traffic between VDOM-A and VDOM-B. The administrator creates a VDOM link between the two VDOMs. What additional configuration is required on each VDOM to enable inter-VDOM traffic?

Medium
552

An administrator has deployed a FortiGate in an SD-WAN hub-and-spoke topology. Spoke sites use IPsec tunnels to the hub, and the hub advertises a default route to the spokes. The administrator wants traffic from any spoke to another spoke to flow through the hub without requiring additional tunnels between spokes. Which SD-WAN feature should be configured on the hub to achieve this?

Medium
553

What is the purpose of a global ADOM in FortiManager?

Easy
554

A FortiGate is deployed in multi-VDOM mode. The administrator has created VDOM-A and VDOM-B, and configured an inter-VDOM link between them. Users in VDOM-A need to access a web server in VDOM-B. The administrator has added a static route in VDOM-A for the server's subnet pointing to the VDOM link interface, and a return route in VDOM-B. Which TWO additional configurations are required to allow the traffic? (Choose two.)

Hard
555

In a multi-VDOM deployment, inter-VDOM routing is configured using VDOM links. After configuring the VDOM links and adding static routes, traffic between VDOMs is not working. The administrator verifies that the VDOM link interfaces are up and have correct IP addresses. What is the most likely missing configuration?

Hard
556

An administrator wants to verify which SD-WAN member is currently being used for a specific traffic flow. Which command should they use on the FortiGate?

Easy
557

An administrator is investigating a security incident and needs to determine which firewall policy allowed a specific malicious traffic flow. The traffic is no longer active. Which FortiAnalyzer log type should the admin query?

Hard
558

An administrator is configuring a FortiGate in multi-VDOM mode. The administrator needs to ensure that the 'Management' VDOM can be accessed via HTTPS and SSH from the internal network, while other VDOMs should not have management access enabled on their interfaces. Which TWO actions must the administrator perform? (Choose two.)

Medium
559

A FortiGate administrator is planning to deploy VDOMs to separate customer traffic. The administrator wants to use FortiManager for centralized management. Which TWO prerequisites must be met before the VDOMs can be managed from FortiManager?

Easy
560

An administrator wants to monitor CPU usage of specific processes on a FortiGate. Which command should be used?

Easy
561

A FortiGate with two WAN interfaces configured in an SD-WAN setup uses the 'lowest-cost' load balancing algorithm. The performance SLA monitors latency and jitter. If wan1 has a cost of 10 and wan2 has a cost of 20, but wan1 is experiencing 50% packet loss, what will happen to traffic?

Hard
562

What is the function of FortiAnalyzer in a Fortinet Security Fabric?

Easy
563

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The VPN tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. Which two commands should the administrator use to further troubleshoot why traffic is not passing through the tunnel? (Choose two.)

Hard
564

A FortiGate has two WAN interfaces (port1, port2) as SD-WAN members. The performance SLA monitor is configured for both with a latency threshold of 50 ms. The measured latency on port1 is 45 ms and on port2 is 55 ms. An SD-WAN rule uses 'lowest-cost' algorithm. Which interface will be selected for new sessions?

Hard
565

A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route (192.168.100.0/24) into OSPF area 0. The route is configured as a static route on the FortiGate. Which configuration step is essential to ensure the static route is redistributed into OSPF?

Hard
566

A company uses FortiManager to manage multiple FortiGate firewalls. After making changes to a policy package, the administrator runs an install preview and sees a warning: 'Policy ID 10 will be deleted on device XYZ'. What is the most likely reason for this warning?

Medium
567

A FortiGate administrator configures inter-VDOM routing. Traffic from VDOM-A to VDOM-B is blocked. The administrator checks the policy in VDOM-A allowing traffic to the VDOM link interface. What else must be verified?

Medium
568

An administrator runs 'diagnose debug application ipsmonitor -1' and sees repeated messages: 'IPS engine restarting'. What is the MOST likely cause of this behavior?

Medium
569

An administrator is configuring an SD-WAN rule to route VoIP traffic (identified by application 'VoIP') over the best available link. The SD-WAN zone 'virtual-wan-link' contains three members: port1 (cost 10), port2 (cost 20), and port3 (cost 30). A performance SLA named 'VoIP-SLA' is applied to the rule, monitoring latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest latency that meets the SLA. Which SD-WAN algorithm should be used?

Hard
570

A FortiGate administrator is investigating a security incident and needs to identify which user initiated a specific outbound connection to a malicious IP address. The company uses FSSO for authentication. Which THREE pieces of information from FortiAnalyzer logs would be MOST useful? (Choose three.)

Medium
571

An administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA state is 'UP' but the IPsec SA state is 'DOWN'. The remote peer is a FortiGate. What is the most likely cause of this issue?

Hard
572

A security analyst is reviewing logs from a FortiGate that uses FortiGuard IPS. The analyst notices that a signature for a recent Apache Struts vulnerability is not triggering even though the vulnerable service is exposed. The FortiGate is running the latest IPS engine and signature database. Which action should the analyst take to verify whether the signature is enabled and properly applied to the traffic?

Hard
573

A network administrator is configuring SD-WAN rules with load balancing. They want to distribute HTTP traffic evenly across two WAN links based on the number of sessions. Which TWO settings should they use? (Choose two.)

Medium
574

A FortiGate administrator is configuring an IPsec VPN with IKEv2. The administrator wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) for phase 2. Which parameter must be configured in the phase 2 proposal?

Medium
575

A FortiGate has an SD-WAN rule with two members: port1 and port2. The rule uses the 'lowest-cost' algorithm. The administrator configures a performance SLA that monitors latency to a remote server. The SLA is applied to both members. After some time, port1's latency exceeds the SLA threshold and its status becomes 'dead'. What happens to new sessions that match the SD-WAN rule?

Hard
576

In a multi-VDOM deployment, what is the purpose of inter-VDOM routing?

Easy
577

During a BGP troubleshooting session, an administrator sees that the BGP neighbor state is 'Active'. Which three conditions could cause this state? (Choose THREE.)

Hard
578

An administrator wants to ensure that all traffic from a specific LAN subnet (192.168.10.0/24) to the internet uses a particular WAN interface (wan1) in an SD-WAN setup, while other traffic uses wan2. What is the correct configuration to achieve this?

Medium
579

An administrator has configured a FortiGate with two VRF instances: VRF10 and VRF20. They need to allow a server in VRF10 (10.10.10.0/24) to communicate with a server in VRF20 (10.20.20.0/24). The administrator creates a firewall policy with source interface VRF10 and destination interface VRF20, but traffic is not passing. What is the most likely cause?

Hard
580

An administrator configures FortiManager automation stitches to respond to high CPU usage on a FortiGate. The stitch should trigger a script to run diagnostics. Which THREE components are required in an automation stitch?

Hard
581

A FortiGate administrator wants to verify whether a specific session is being offloaded to the NP6 processor. Which CLI command should the administrator use?

Easy
582

Which FortiGate feature allows multiple independent routing tables on a single device, enabling traffic separation for different departments or customers?

Easy
583

A network administrator is configuring SD-WAN on a FortiGate and wants to ensure that VoIP traffic uses the link with the lowest latency while bulk download traffic uses the link with the highest bandwidth. Which TWO configuration steps are required?

Medium
584

A FortiGate is receiving BGP routes from a neighbor but not advertising them to other peers. The administrator runs 'get router info bgp network' and sees the routes are in the BGP table but not advertised. What is the most likely cause?

Medium
585

An administrator is deploying ZTNA for a legacy application that uses a fixed IP address and port. Which ZTNA component is responsible for securely proxying traffic from the user to the application without exposing the application's actual network location?

Medium
586

A FortiGate has two WAN interfaces configured as SD-WAN members. The administrator wants traffic to specific destination IP addresses to use a particular member. Which SD-WAN configuration object should be used to achieve this?

Medium
587

Drag and drop the steps to configure a FortiGate to use an external authentication server (e.g., RADIUS) for admin login into the correct order.

Medium
588

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator wants to identify which processes are consuming the most CPU. Which command should be used?

Easy
589

Which THREE statements are true about FortiGate SD-WAN health-check configuration?

Medium
590

You receive an alert that FortiAnalyzer log disk usage is at 95%. Which action should you take to immediately free up space without losing important logs?

Easy
591

Which FortiGate security feature can reconstruct files to remove potentially malicious content while preserving the file's usability?

Easy
592

An administrator is building an ADVPN with a single hub and many spokes. Spokes are behind NAT devices and receive dynamic public IP addresses. The administrator wants shortcuts to form directly between spokes without routing traffic through the hub. Which combination of features must be configured on the hub and spokes to allow shortcut negotiation to succeed in this environment?

Hard
593

A network engineer is deploying a FortiGate in transparent mode at a branch office. The goal is to insert the firewall without changing the existing IP subnet scheme. Which statement about transparent mode is TRUE?

Easy
594

An administrator is configuring FortiMail to be more secure against advanced email threats. Which THREE features should they enable to protect against email-based phishing attacks?

Easy
595

A security analyst is investigating alerts from FortiGate's IPS. They notice that an attack was detected but not blocked, even though the IPS profile is set to block. The log shows the action as 'detected'. What is the most likely reason for this behavior?

Medium
596

An administrator configures OSPF on a FortiGate with multiple areas. After configuration, the FortiGate does not become an ABR. What is the most likely reason?

Hard
597

Which load balancing algorithm in SD-WAN sends new sessions to the member interface with the least number of active sessions?

Easy
598

An administrator wants to verify that a BGP route is being advertised to a neighbor. Which command displays the routes that FortiGate is advertising to a specific BGP neighbor?

Easy
599

Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per interface?

Easy
600

A network administrator notices that several endpoints are infected with ransomware despite having FortiGate ATP enabled. The logs show that the files were downloaded over HTTPS, and the antivirus profile did not detect them. What is the most likely reason?

Medium
601

A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?

Medium
602

An administrator is configuring a FortiGate in transparent mode for a data center segment. Which of the following is true about transparent mode operation in an enterprise environment?

Medium
603

A network administrator notices that FortiGate is not blocking a known malicious file that was submitted to FortiSandbox and received a 'malicious' verdict. The firewall policy includes a FortiSandbox inline scan profile. What is the MOST likely cause?

Medium
604

An administrator is configuring a FortiGate to use the external threat feed feature to block traffic from known malicious IP addresses. They want to ensure that the feed is automatically updated and that the firewall blocks traffic based on the feed. Which two actions must the administrator perform? (Choose two.)

Hard
605

What is the primary function of FortiDeceptor in a network security architecture?

Easy
606

An administrator is configuring a FortiGate as a SAML Identity Provider (IdP) for a third-party service provider. Which of the following is REQUIRED for the FortiGate IdP configuration?

Medium
607

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?

Medium
608

A FortiGate is configured with a site-to-site IPsec VPN to a remote office. Users at the remote office report that they cannot access resources at the main office. The administrator checks the VPN status and sees that the tunnel is up. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)

Hard
609

An administrator configures ZTNA with FortiClient EMS. The goal is to restrict access to an internal application based on device posture. The administrator configures a ZTNA tag for 'Compliant' that checks antivirus and OS patch status. Which TWO additional steps are required on the FortiGate to enforce access based on this tag?

Hard
610

A FortiGate 600F is running in multi-VDOM mode with VDOMs named 'root', 'finance', and 'guest'. The administrator notices that a firewall policy created in the 'finance' VDOM does not appear when logging into the 'guest' VDOM and wants to confirm that policies, address objects, and routing tables are kept completely separate per VDOM. Which FortiGate feature provides this separation by default?

Medium
611

A FortiGate administrator is implementing Zero Trust Network Access using ZTNA tags from FortiClient EMS to control access to internal applications. The administrator must ensure that devices losing compliance are denied access and that only managed endpoints can reach the applications. Which two configuration actions are required to meet these goals? (Choose two.)

Hard
612

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which two actions should the administrator take to further diagnose and potentially resolve the issue? (Choose two.)

Hard
613

A FortiGate administrator uses FortiAnalyzer for log analysis and wants to identify all sessions that were blocked by a specific firewall policy ID 10. Which log filter should be applied?

Medium
614

Which SD-WAN load balancing algorithm distributes new sessions based on the number of active sessions on each link?

Easy
615

Drag and drop the steps to configure a FortiGate as a DNS server (DNS proxy) into the correct order.

Medium
616

An admin wants to ensure that office documents (e.g., Word, Excel) downloaded from the internet are safe before users open them. Which feature should be used to remove potentially malicious macros and active content?

Medium
617

You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?

Medium
618

A FortiGate administrator is implementing Zero Trust Network Access (ZTNA) for remote users accessing an internal web application. The administrator wants to ensure that only users who have authenticated and whose devices meet posture requirements can reach the application, and that the application itself is never directly exposed to the internet. Which two FortiGate configuration steps are required to achieve this? (Choose two.)

Medium
619

An administrator wants to use FortiManager to manage multiple FortiGates, each in a separate customer environment. The administrator needs to isolate configuration changes per customer and ensure each customer's admin can only see their own devices. What FortiManager feature should be used?

Medium
620

A FortiGate with FortiExtender is using LTE as a backup WAN link. When the primary link fails, the LTE link does not take over. What could be the cause?

Hard
621

A FortiGate administrator is configuring a ZTNA rule to protect an internal web server. The administrator wants to ensure that only users who authenticate via SAML and whose devices have the latest antivirus signature are allowed access. Which FortiGate feature must be used to enforce this?

Medium
622

What is the purpose of FortiDeceptor in an enterprise security architecture?

Easy
623

A FortiGate administrator is configuring a web filter profile to block access to known malicious websites. The administrator wants to ensure that the firewall blocks sites based on FortiGuard category 'Malicious Websites' and also logs the blocked attempts. Which action should the administrator take?

Medium
624

An administrator configures SD-WAN with two members (wan1, wan2) and a performance SLA for ICMP to 1.1.1.1. The SD-WAN rule is set to 'Best Quality' with 'latency' metric. The admin notices that traffic sometimes switches to the other link even when the current link has acceptable latency. Which action can reduce unnecessary flapping?

Medium
625

An admin receives an email from FortiMail regarding a message that was rejected due to SPF failure. What does this indicate about the email?

Medium
626

An administrator is troubleshooting a FortiGate that is dropping traffic from a specific VLAN. The administrator runs 'diagnose debug flow' with a filter for the VLAN's subnet and sees the trace terminate with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?

Hard
627

What is the primary benefit of using FortiClient with ATP features in conjunction with FortiGate?

Easy
628

An administrator wants to detect lateral movement and early stages of an attack using decoy systems that mimic production assets. Which Fortinet product should they deploy?

Medium
629

A company uses FortiWeb to protect its web application. They want to block SQL injection attempts. Which FortiWeb feature should be configured to inspect HTTP requests for malicious SQL patterns?

Hard
630

An administrator is configuring FortiDeceptor to detect threats within the network. Which TWO statements about FortiDeceptor are correct?

Medium
631

A FortiGate administrator is troubleshooting a scenario where traffic between two VDOMs is not working. The admin has configured inter-VDOM routing. Which TWO steps should the administrator verify? (Choose two.)

Medium
632

A FortiGate is configured with OSPF multi-area. The administrator wants to ensure that routes from area 0 are redistributed into area 1. Which OSPF configuration is required?

Easy
633

A FortiGate is configured with SD-WAN and multiple members. The administrator notices that traffic to a critical application is consistently routed over a low-quality link, even though a better link is available. The SD-WAN rule uses the 'Best Quality' strategy with a performance SLA. What is the most likely reason?

Medium
634

In a Zero Trust Network Access architecture, which component acts as the policy enforcement point for access decisions?

Easy
635

A company wants to ensure that only company-managed laptops with up-to-date antivirus can access the internal file server remotely. Which Fortinet solution integrates with FortiGate to enforce device compliance before granting ZTNA access?

Easy
636

An administrator is deploying a FortiGate in transparent mode to seamlessly integrate into an existing network. The administrator needs to manage the FortiGate remotely over the network. Which configuration is required?

Medium
637

A company has deployed FortiClient with advanced threat protection (ATP) features. Which TWO capabilities does FortiClient ATP provide beyond basic antivirus?

Medium
638

An administrator is setting up a new FortiGate with multiple VDOMs. The administrator wants to ensure that each VDOM has its own set of administrators and that administrators of one VDOM cannot view or modify settings in another VDOM. Which feature should the administrator configure to achieve this?

Easy
639

An admin wants to block malicious files detected by FortiSandbox at the FortiGate level. Which configuration is required on the FortiGate to automatically block files based on FortiSandbox verdict?

Medium
640

In FortiManager, what is the purpose of an automation stitch?

Hard
641

Which FortiClient feature is specifically designed to prevent the execution of unknown malware by analyzing behavior in real-time?

Easy
642

An administrator wants to protect against zero-day malware that has not yet been discovered by signature-based detection. Which TWO technologies can help mitigate such threats?

Medium
643

A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?

Hard
644

A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?

Hard
645

A FortiGate administrator is configuring ZTNA to protect an internal application and wants to ensure that only users who authenticate with a valid client certificate and whose devices pass posture checks can connect. The administrator has configured FortiClient EMS integration and a ZTNA access proxy rule. During testing, users without client certificates are still able to reach the application after providing username and password. Which setting should the administrator verify to enforce certificate-based authentication?

Medium
646

An administrator wants to use FortiManager to push a new firewall policy to a managed FortiGate. Before installing, the administrator wants to review what changes will be applied. Which FortiManager feature should be used?

Easy
647

An administrator is troubleshooting a FortiGate that is experiencing intermittent packet loss for traffic passing through an IPsec VPN tunnel. The administrator wants to capture packets on the VPN interface to analyze the issue. Which command should the administrator use to capture packets on the IPsec tunnel interface named 'vpn1'?

Hard
648

An administrator runs the following CLI output: 'diagnose sys session filter dport 443' and sees 'proto=6 proto_state=01 duration=3600 expire=3599'. Which statement BEST describes the session?

Hard
649

An administrator has configured an SD-WAN rule with the 'lowest-cost' strategy. The rule includes two members: port1 and port2. The administrator notices that all traffic is being sent over port1, even though port2 has a lower latency. Which factor is most likely causing this behavior?

Medium
650

An administrator has a FortiGate 600E running multiple VDOMs. The administrator wants to ensure that when a VDOM is deleted, all associated firewall policies, addresses, and routes are also removed to avoid orphaned objects. Which action should the administrator take?

Medium
651

A FortiGate is configured with two WAN interfaces in an SD-WAN zone. The administrator wants to ensure that Voice over IP (VoIP) traffic uses the link with the lowest latency, while all other traffic uses the link with the highest available bandwidth. The performance SLA 'VoIP_SLA' monitors latency to a VoIP provider. Which SD-WAN configuration should the administrator implement to meet these requirements?

Medium
652

A FortiGate administrator is implementing ZTNA to control access to internal web applications. The administrator wants to ensure that only devices with a valid FortiClient EMS tag can access the applications. Which ZTNA component must be configured on the FortiGate to enforce this?

Hard
653

An administrator has a FortiGate with multiple VDOMs in NAT mode. The administrator wants to configure a global policy that applies to all VDOMs to block traffic from a known malicious IP block. Which statement is correct about global policies?

Medium
654

A FortiGate administrator is deploying a multi-VDOM setup for a service provider. The provider wants each customer VDOM to have its own administrative access, yet the overall device management (including firmware upgrades) should be centralized from the management VDOM. Which TWO statements are true regarding administrative VDOMs?

Medium
655

A FortiGate is deployed in multi-VDOM mode with two VDOMs: VDOM-1 and VDOM-2. The administrator needs to enable communication between these VDOMs using a VDOM link. Which TWO statements about VDOM link configuration are correct? (Choose two.)

Hard
656

What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?

Easy
657

A network admin runs 'diagnose sys top' on a FortiGate and sees that the process 'httpsd' is consistently using 95% CPU. Which of the following actions is MOST appropriate to troubleshoot this issue?

Medium
658

A FortiGate administrator wants to implement Content Disarm and Reconstruction (CDR) for email attachments. Which security profile must be configured to enable CDR?

Medium
659

An admin configures a FortiManager ADOM for a customer with multiple FortiGates. The admin wants to use meta fields to group firewalls by location. After defining a meta field 'Location' and assigning values to devices, where can the admin use the meta field for policy targeting?

Hard
660

An administrator wants to monitor real-time CPU usage per process on a FortiGate. Which command should be used?

Easy
661

A FortiGate administrator is troubleshooting an IKEv2 VPN tunnel that fails to establish. The remote peer logs show 'no acceptable proposal' error. Which TWO possible causes should the administrator check?

Medium
662

An administrator is configuring SD-WAN and wants to ensure that voice traffic uses the lowest latency link. Which two configurations are required to achieve this? (Choose TWO.)

Medium
663

An administrator wants to create a separate virtual firewall instance on a FortiGate to isolate a DMZ environment. The DMZ must have its own routing table, firewall policies, and administrators. Which FortiGate feature should be used?

Easy
664

A FortiGate has two equal-cost paths to a destination network. ECMP is enabled. The administrator notices that all traffic uses the first path. What is the most likely cause?

Hard
665

An IPS administrator wants to detect a new custom attack that sends malformed HTTP headers. The attack pattern is a specific sequence of bytes that is not covered by existing signatures. What is the BEST way to detect this attack on FortiGate?

Medium
666

A FortiGate with SD-WAN enabled uses two members: MPLS (10 ms latency) and Internet (40 ms latency). The SD-WAN rule uses 'Best Quality' strategy with latency as the metric. Traffic to a critical application (10.1.1.0/24) is currently using the MPLS link. The MPLS link's latency increases to 60 ms due to a routing issue. How will FortiGate handle new sessions to 10.1.1.0/24?

Medium
667

An administrator is planning a multi-VDOM deployment with a management VDOM. Which TWO statements about management VDOMs are correct? (Choose two.)

Medium
668

An administrator configures a FortiGate in transparent mode for a VDOM. After switching to transparent mode, the administrator notices that the default route disappears and traffic fails. What must be configured to restore routing?

Medium
669

A FortiGate administrator is configuring a route-based IPsec VPN to a cloud provider. The provider requires that only traffic for the 10.20.0.0/16 network be sent through the tunnel, and that the FortiGate present a specific local subnet of 192.168.10.0/24 as its source. The administrator wants to avoid policy-based VPN configuration. Which configuration approach correctly defines the traffic selectors for this route-based tunnel?

Easy
670

A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator has created a VDOM link between VDOM-1 and VDOM-2 and assigned IP addresses to both ends. A server in VDOM-1 (10.1.1.10/24) needs to reach a server in VDOM-2 (10.2.2.10/24). The administrator has added a static route in VDOM-1 for 10.2.2.0/24 pointing to the VDOM-2 link interface IP, and a static route in VDOM-2 for 10.1.1.0/24 pointing to the VDOM-1 link interface IP. However, traffic is not passing. Which additional configuration is required on the FortiGate to allow the traffic to flow?

Medium
671

A FortiGate is configured as a ZTNA proxy for a web application. Users report that after authenticating, they receive a '502 Bad Gateway' error. What is the most likely cause?

Easy
672

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. The administrator then runs 'diagnose debug flow filter addr 10.1.1.1' (the remote subnet) and 'diagnose debug flow show function-name enable', and observes the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 10.1.1.1:80->192.168.1.100:12345) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-192.168.1.1 via port2"'. No further output appears. What is the MOST likely cause of the issue?

Hard
673

An email security administrator wants to prevent attackers from spoofing the company's domain. Which email authentication mechanism should be configured to allow receiving servers to verify that emails claiming to be from the domain are sent from authorized mail servers?

Medium
674

An administrator has configured an SD-WAN zone named 'virtual-wan' containing two members: port1 and port2. They want to apply different SD-WAN rules based on the destination IP address. Which FortiGate configuration object should they use to define the destination IP address for matching traffic in an SD-WAN rule?

Medium
675

A FortiGate administrator configures a custom IPS signature with the pattern 'attack' in the HTTP request URI. After applying the signature, no alerts are generated even though the traffic matches. What is the MOST likely cause?

Hard
676

An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)

Medium
677

An administrator receives an error when trying to create a ZTNA proxy rule: 'The ZTNA proxy rule requires a valid application mapping.' What does this indicate?

Medium
678

A company is implementing Zero Trust Network Access using Fortinet's ZTNA solution. They have deployed a FortiGate as the ZTNA gateway and are using FortiClient as the ZTNA agent. Users report that they can initiate ZTNA connections but the connections drop after a few minutes. The FortiGate logs show that the ZTNA session is being terminated due to a endpoint compliance check failure. Which action should the administrator take to resolve this issue?

Medium
679

A FortiGate cluster (A-P) has a session that is not synchronizing to the secondary unit. The administrator runs 'diagnose sys ha session-sync status' and sees that the session count is different between primary and secondary. Which is the most likely cause?

Hard
680

A FortiGate administrator has configured a firewall policy with a web filter profile that uses a FortiGuard category action to block 'Malware' websites. Users report that they can still access some known malicious sites that are categorized as 'Malware'. The administrator verifies that the FortiGuard service is reachable and the license is valid. What is the most likely cause?

Medium
681

A FortiGate administrator wants to quickly identify which process is consuming the most CPU on the device. Which CLI command should be used?

Easy
682

A FortiGate in an HA cluster with VDOMs enabled experiences a failover. After the failover, traffic that was passing before is now being dropped. The configuration is synchronized between the primary and secondary units. What is the most likely reason?

Hard
683

An administrator configures a VDOM link between VDOMs A and B. In VDOM A, the VDOM link interface is assigned IP 10.10.10.1/24, and in VDOM B, it is assigned 10.10.10.2/24. A firewall policy on VDOM A allows traffic from a subnet in VDOM A to a subnet in VDOM B. However, traffic fails. The admin checks the routing table in VDOM A and sees a route to the destination subnet via 10.10.10.2. What is the most likely cause?

Medium
684

An administrator configures a VDOM on a FortiGate and assigns two interfaces (port1, port2) to it. The administrator wants to route traffic between two different subnets within the same VDOM. Which configuration is required?

Medium
685

An administrator is configuring a FortiGate with multiple VDOMs. The administrator needs to allow a VDOM to use a shared physical interface with another VDOM. Which feature should be used?

Medium
686

Which of the following is a requirement for FortiGate to act as a SAML Identity Provider (IdP) for ZTNA?

Easy
687

A FortiGate administrator is deploying ZTNA for remote users who connect through FortiClient. The administrator wants to enforce device compliance based on the FortiClient EMS tags. The FortiGate is already integrated with FortiClient EMS. Which configuration step is required to use EMS tags in a ZTNA policy?

Medium
688

An administrator is configuring a FortiGate to inspect SMTP traffic for spam and viruses. The traffic must be decrypted to inspect the content. Which THREE elements are required for this configuration? (Choose three.)

Medium
689

An administrator is troubleshooting BGP with SD-WAN. They have configured BGP on the FortiGate and the SD-WAN rule uses 'best quality' strategy. However, failover does not happen when a WAN link goes down. The BGP session is still up. What is the most likely reason?

Medium
690

An NSE7 administrator is configuring a FortiGate to use the built-in intrusion prevention system (IPS) to detect and block exploits targeting a custom web application. The administrator wants to ensure that the IPS engine inspects all HTTP traffic, including encrypted sessions, without impacting performance. Which FortiGate feature should be enabled to allow IPS inspection of SSL/TLS traffic?

Medium
691

A FortiGate running FortiOS 7.4 is configured with a firewall policy that references an IPS sensor. The sensor uses a custom signature to detect a recently discovered exploit. Users report that the exploit traffic is not being blocked even though the signature is enabled. The administrator confirms the traffic matches the signature and that the policy is in flow-based inspection mode. Which action should the administrator take to ensure the IPS sensor can block the exploit?

Medium
692

A FortiGate administrator is implementing ZTNA in reverse-proxy mode to protect an internal web application. Remote users authenticate through FortiClient with EMS tags, and the administrator wants to enforce that only users with a valid certificate and a compliant endpoint can access the application. After configuring the ZTNA server and access proxy, the administrator notices that users without the certificate are still able to reach the application. What is the most likely cause?

Medium
693

An administrator is configuring a FortiGate with multiple VDOMs. The administrator wants to ensure that the VDOMs can use overlapping IP addresses on their respective interfaces. Which setting must be enabled to allow this?

Medium
694

A FortiGate administrator wants to use SAML SSO to authenticate VPN users. The FortiGate will act as the service provider (SP) and an external identity provider (IdP) will be used. Which of the following must be configured on the FortiGate to enable SAML authentication for SSL VPN?

Medium
695

Which Fortinet product provides endpoint detection and response (EDR) capabilities, including automated threat containment?

Easy
696

A network administrator is configuring inter-VDOM routing between two VDOMs: VDOM-A and VDOM-B. The administrator creates a inter-VDOM link and adds routes pointing to the link. However, traffic from VDOM-A to VDOM-B fails. What is the most likely missing configuration?

Medium
697

A company is deploying FortiClient ATP to protect endpoints. They want to block ransomware behavior in real time. Which FortiClient feature should be enabled?

Medium
698

A FortiGate is configured with SD-WAN using load balancing algorithm 'source-dest-ip'. What is the primary characteristic of this algorithm?

Easy
699

In FortiManager, what is the purpose of header and footer policies in a policy package?

Medium
700

An administrator needs to apply different routing policies for traffic based on source IP address, overriding the normal routing table. Which feature should be configured?

Medium
701

A network administrator is deploying FortiGate to protect against unknown malware. They want to use machine learning to detect and block malicious files without relying on signatures. Which antivirus scanning technique should be enabled to achieve this?

Easy
702

A FortiGate is configured with two SD-WAN members: port1 (WAN1) and port2 (WAN2). An SD-WAN rule routes traffic from the internal subnet 10.0.1.0/24 to the internet using the 'volume' load-balancing algorithm. The rule is configured with a volume ratio of 70:30 for port1:port2. After some time, the administrator notices that port1 is handling approximately 90% of the traffic volume, while port2 handles only 10%. What is the most likely cause of this imbalance?

Medium
703

An administrator runs 'diagnose debug application sslvpn -1' and sees repeated 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate'. The SSL-VPN is configured to require client certificates. What is the cause?

Hard
704

Which two commands display the current session count on a FortiGate?

Easy
705

A FortiGate administrator is configuring ZTNA to provide secure access to an internal application. The application is hosted on a server with IP 10.0.1.100 and port 8080. The administrator creates a ZTNA rule on the FortiGate as an access proxy. What is the correct configuration for the ZTNA rule's 'Application Access' entry?

Medium
706

An administrator has a FortiGate with VDOMs 'VDOM-A' and 'VDOM-B' connected by an inter-VDOM link. Users in VDOM-A can reach a web server in VDOM-B, but return traffic from the server to clients is being dropped. The administrator has already created policies in both directions. Which action should the administrator take to resolve the dropped return traffic?

Hard
707

A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. The tunnel is established but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees 'no matching policy for this IPsec SA'. What is the most likely cause?

Medium
708

A network administrator is deploying a FortiGate in transparent mode to replace an existing layer 2 switch. Which statement about transparent mode is true?

Easy
709

A FortiGate administrator wants to ensure that only devices with an up-to-date antivirus and OS patch level can access a sensitive application published via ZTNA. Which ZTNA component should the administrator configure to enforce this requirement?

Easy
710

A FortiGate administrator is troubleshooting a ZTNA deployment. Users report that they can access the ZTNA application, but the EMS tags are not being enforced. The administrator verifies that the FortiGate is connected to FortiClient EMS and that the EMS tags exist. What is the most likely cause?

Medium
711

A FortiGate administrator has configured an antivirus profile with sandbox inspection and applied it to a firewall policy. Users report that downloads of executable files are delayed significantly, but eventually complete. The administrator wants to reduce the delay while still blocking malicious files before they reach the endpoint. Which change should the administrator make?

Hard
712

A FortiManager administrator wants to push a policy package that includes both global header/footer policies and VDOM-specific policies. Which statement about header/footer policies is correct?

Medium
713

An administrator wants to add custom fields to device objects in FortiManager to track location and contact info. Which feature should be used?

Medium
714

A FortiGate is configured with two WAN members in an SD-WAN zone. The performance SLA monitors latency to a probe server. The rule uses 'best quality' strategy. After some time, one member fails the SLA. Which action does the FortiGate take for existing sessions that were using that member?

Hard
715

An administrator is troubleshooting an issue where a FortiGate is not forwarding traffic between two internal subnets. The administrator runs 'diagnose debug flow' and sees that packets are entering the FortiGate but are dropped with the message 'reverse path check fail, drop'. What is the MOST likely cause?

Hard
716

When troubleshooting an IPsec VPN phase 1 failure, you run 'diagnose vpn ike config' and see that the remote gateway IP address is incorrect. Which command is used to correct the peer IP configuration?

Medium
717

A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?

Easy
718

A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?

Medium

Frequently asked questions

What does the scenario questions domain cover on the NSE7 exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 718 scenario questions questions in the NSE7 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.