wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

rf-forti1

Total questions: 81

Worksheet time: 41mins

Name
Class
Date
1.

An administrator wants to configure dead peer detection (DPD) on an IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic. Which DPD mode on FortiGate meets this requirement?

a)

Enabled

b)

On Idle

c)

Disabled

d)

On Demand

2.

Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true?

a)

If SD-WAN is enabled, you control the load-balancing algorithm with the parameter load-balance-mode.

b)

If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.

c)

If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.

d)

If SD-WAN is disabled, you configure the load-balancing algorithm in config system settings.

3.

You created a web filter profile named restrict_media-profile with a category usage quota. When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down. What is the reason?

a)

The firewall policy is in no-inspection mode instead of deep-inspection.

b)

The inspection mode in the firewall policy does not match the web filter profile feature set.

c)

The web filter profile is already referenced in another firewall policy.

d)

The naming convention used in the web filter profile is restricting it in the firewall policy.

4.

Refer to the exhibit. As an administrator, you created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit. What could be the possible reason of the diagnose output shown in the exhibit? (Choose one answer)

a)

There is no firewall policy configured with an IPS security profile.

b)

FortiGate entered into IPS fail open state.

c)

Administrator entered the command diagnose test application ipsmonitor 5.

d)

Administrator entered the command diagnose test application ipsmonitor 99.

5.

Refer to the exhibit. The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection. For which two reasons are these web categories exempted?

a)

FortiGate temporary certificates can be denied by sites using HTTP Strict Transport Security, so such sites are exempted.

b)

These websites are in an allowlist of reputable domain names maintained by FortiGuard.

c)

Resource utilization is optimized because these sites are in the trusted domain list on FortiGate.

d)

Legal regulation aims to prioritize user privacy and protect sensitive information for these websites.

6.

Refer to the exhibit. The NOC team connects to the FortiGate GUI with the NOC_Access admin profile and requests that GUI sessions do not disconnect too early during inactivity. What must the administrator configure to meet this request?

a)

Move NOC_Access to the top of the list to ensure all profile settings take effect.

b)

Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.

c)

Ensure all NOC_Access users are assigned the super_admin role to guarantee access.

d)

Increase the admintimeout value under config system accprofile NOC_Access.

7.

Refer to the exhibit. Based on the partial configuration shown, what are two possible outcomes when FortiGate enters conserve mode?

a)

Administrators cannot change the configuration.

b)

FortiGate skips quarantine actions.

c)

Administrators must restart FortiGate to allow new sessions.

d)

FortiGate drops new sessions requiring inspection.

8.

What is the primary FortiGate election process when the HA override setting is enabled?

a)

Connected monitored ports > Priority > HA uptime > FortiGate serial number

b)

Connected monitored ports > Priority > System uptime > FortiGate serial number

c)

Connected monitored ports > HA uptime > Priority > FortiGate serial number

d)

Connected monitored ports > System uptime > Priority > FortiGate serial number

9.

An administrator wants to configure an IPS sensor to block traffic that triggers a signature a set number of times during a specific time period. How can the administrator achieve the objective?

a)

Use IPS group signatures, set rate-mode 60.

b)

Use IPS packet logging option with periodical filter option.

c)

Use IPS filter, rate-mode periodical option.

d)

Use IPS signatures, rate-mode periodical option.

10.

A FortiGate firewall policy is configured with active authentication, but the user cannot authenticate when accessing a website. Which protocol must FortiGate allow even though the user cannot authenticate?

a)

LDAP

b)

TACACS+

c)

Kerberos

d)

DNS

11.

Refer to the exhibit, which shows a partial configuration from the remote authentication server. Why does the FortiGate administrator need this configuration?

a)

To authenticate only the Training user group

b)

To set up a RADIUS server secret

c)

To authenticate and match the Training OU on the RADIUS server

d)

To authenticate any FortiGate user groups

12.

Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?

a)

The Underlay zone is the zone by default.

b)

The Underlay zone contains no member.

c)

port2 and port3 are not assigned to a zone.

d)

The virtual‑wan‑link and overlay zones can be deleted.

13.

Which three statements explain a flow‑based antivirus profile?

a)

FortiGate buffers the whole file but transmits to the client at the same time.

b)

Flow‑based inspection uses a hybrid of the scanning modes available in proxy‑based inspection.

c)

If a virus is detected, the last packet is delivered to the client.

d)

Flow‑based inspection optimizes performance compared to proxy‑based inspection.

e)

The IPS engine handles the process as a standalone.

14.

Refer to the exhibit. An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow. This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times. Why are there no logs generated under security logs for ABC.Com?

a)

The ABC.Com Type is set as Application instead of Filter.

b)

The ABC.Com is configured under application profile, which must be configured as a web filter profile.

c)

The ABC.Com Action is set to Allow.

d)

The ABC.Com is hitting the category Excessive‑Bandwidth.

15.

Which two statements describe characteristics of automation stitches?

a)

Actions involve only devices included in the Security Fabric.

b)

An automation stitch can have multiple triggers.

c)

Multiple actions can run in parallel.

d)

Triggers can involve external connectors.

16.

Which three statements about SD‑WAN performance SLAs are true?

a)

They rely on session loss and jitter.

b)

They can be measured actively or passively.

c)

They are applied in a SD‑WAN rule lowest cost strategy.

d)

They monitor the state of the FortiGate device.

e)

All the SLA targets can be configured.

17.

Which two statements are true about an HA cluster?

a)

An HA cluster cannot have both in‑band and out‑of‑band management interfaces at the same time.

b)

Link failover triggers a failover if the administrator sets the interface down on the primary device.

c)

When sniffing the heartbeat interface, the administrator must see the IP address 169.254.0.2.

d)

HA incremental synchronization includes FIB entries and IPsec SAs.

18.

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate?

a)

The selected SSL inspection profile has certificate inspection enabled.

b)

The website is exempted from SSL inspection.

c)

The EICAR test file exceeds the protocol options oversize limit.

d)

The browser does not trust the FortiGate self‑signed CA certificate.

19.

You have configured the following commands on a FortiGate. What would be the impact of this configuration on FortiGate?

a)

FortiGate will enable strict RPF on all its interfaces and port1 will be enable for asymmetric routing.

b)

FortiGate will enable strict RPF on all its interfaces and port1 will be exempted from RPF checks.

c)

Port1 will be enabled with flexible RPF, and all other interfaces will be enabled for strict RPF.

d)

The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces.

20.

Refer to the exhibit of the SSL inspection profile. What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

a)

FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.

b)

FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.

c)

FortiGate will close the connection if the SNI does not match the CN or SAN fields.

d)

FortiGate will close the connection if the SNI does not match the CN and SAN fields.

21.

A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?

a)

The DC agent sends login event data directly to FortiGate.

b)

The user logs into the Windows domain.

c)

The collector agent forwards login event data to FortiGate.

d)

FortiGate determines user identity based on the IP address in the FSSO list.

22.

A network administrator is reviewing firewall policies in both Interface Pair View and By Sequence View. The policies appear in a different order in each view. Why is the policy order different in these two views?

a)

Policies in Interface Pair View are prioritized by security levels, while By Sequence View strictly follows the administrator’s manual ordering.

b)

By Sequence View groups policies based on rule priority, while Interface Pair View always follows the order of traffic logs.

c)

The firewall dynamically reorders policies in Interface Pair View based on recent traffic patterns, but By Sequence View remains static.

d)

Interface Pair View sorts policies based on matching interfaces, while By Sequence View shows the actual processing order of rules.

23.

An administrator notices that some users are unable to establish SSL VPN connections, while others can connect without issues. What should the administrator check first?

a)

Ensure that the affected users are using the correct port number.

b)

Ensure that user traffic is hitting the firewall policy.

c)

Ensure that forced tunneling is enabled to reroute all traffic through the SSL VPN.

d)

Ensure that the HTTPS service is enabled on SSL VPN tunnel interface.

24.

Refer to the exhibit. An administrator has created a new firewall address to use as the destination for a static route. Why is the administrator not able to select the new address in the Destination field of the new static route?

a)

In the new static route, the administrator must select Named Address.

b)

In the new firewall address, the FQDN address must first be resolved.

c)

In the new static route, the administrator must first set the interface to port2.

d)

In the new firewall address, Routing configuration must be enabled.

25.

FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected physical interfaces on FortiGate are true? Select two.

a)

Both interfaces must have the interface role assigned.

b)

Both interfaces must have directly connected routes on the routing table.

c)

Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.

d)

Both interfaces must have IP addresses assigned.

26.

When configuring a FortiGate in a multi-WAN setup, why would an administrator enable session preservation on an interface?

a)

To allow the FortiGate to dynamically change interfaces for all active sessions when a WAN link fails

b)

To make sure all sessions without source NAT enabled always use the primary WAN link

c)

To improve security by forcing users to authenticate again when the WAN link changes

d)

To ensure that existing SSL VPN connections remain on the same interface even if route changes occur

27.

Refer to the exhibit. FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles. Which action must the administrator perform to consolidate the two policies into one?

a)

Create an Aggregate interface that includes port1 and port2 to create a single firewall policy.

b)

Select port1 and port2 subnets in a single firewall policy.

c)

Replace port1 and port2 with any interface in a single firewall policy.

d)

Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy.

28.

You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate setting should you check to resolve this issue?

a)

FortiGuard category ratings

b)

Application and Filter Overrides

c)

Network Protocol Enforcement

d)

Replacement Messages for UDP-based Applications

29.

When configuring firewall policies, which of the following is true regarding the policy ID? Select two.

a)

It is mandatory to provide a policy ID while creating a firewall policy regardless of GUI or CLI.

b)

A firewall policy ID identifies the order of policy execution in firewall policies.

c)

You can create a policy in CLI with policy ID 0.

d)

A policy ID cannot be edited once a policy is created.

30.

Which two statements are correct when FortiGate enters conserve mode? Select two.

a)

FortiGate continues to run critical security actions, such as quarantine.

b)

FortiGate refuses to accept configuration changes.

c)

FortiGate halts complete system operation and requires a reboot to regain available resources.

d)

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.

31.

A remote user reports slow SSL VPN performance and frequent disconnections. The user is located in an area with poor internet connectivity. What setting should the administrator adjust to improve the user's experience?

a)

Enable split tunneling to reduce VPN traffic.

b)

Change the SSL VPN port to a non-standard port.

c)

Increase the session timeout for inactive sessions.

d)

Configure the DTLS timeout to accommodate high-latency connections.

32.

An administrator wants to analyze and manage digital certificates to prevent browser warnings when users connect to the SSL VPN portal. Which two statements describe how to correctly do this? Select two

a)

The administrator can rely on the default FortiGate self-signed certificate to prevent all security warnings in the browser.

b)

The administrator must disable HTTPS administrative access entirely to avoid certificate warnings.

c)

The administrator can use a publicly trusted certificate from a known certificate authority (CA) to stop browser warnings.

d)

The administrator can import the FortiGate self-signed certificate into each user's browser as a trusted certificate.

33.

An administrator suspects that the Collector Agent is not forwarding login events to FortiGate. What is the most effective troubleshooting step?

a)

Verify if DC agent is enabled on the FortiGate

b)

Restart the domain controller to refresh authentication services

c)

Verify if FortiGate is set to use LDAP authentication instead of FSSO

d)

Check if TCP port 8000 is open between the collector agent and FortiGate

34.

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up?

a)

On BR1-FGT, set Seconds to 43200.

b)

On HQ-NGFW, enable Diffie-Hellman Group 2.

c)

On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.

d)

On HQ-NGFW, set Encryption to AES256.

35.

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet. Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? Select two.

a)

In the system settings, set Multiple Interface Policies to enable.

b)

In the IP pool configuration, set endip to 100.65.0.112.

c)

In the firewall policy, set match-vip to enable using CLI.

d)

In the IP pool configuration, set type to overload.

36.

Refer to the exhibits. An administrator has observed the performance status outputs on an HA cluster for 55 seconds. Which FortiGate is the primary?

a)

HQ-NGFW-2 with the parameter memory-failover-threshold setting

b)

HQ-NGFW-2 with the parameter priority setting

c)

HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting

d)

HQ-NGFW-1 with the parameter override setting

37.

Which statement correctly describes NetAPI polling mode for the FSSO collector agent?

a)

The collector agent uses a Windows API to query DCs for user logins.

b)

NetAPI polling can increase bandwidth usage in large networks.

c)

The NetSessionEnum function is used to track user logouts.

d)

The collector agent must search Windows application event logs.

38.

You have configured the FortiGate device for FSSO. A user is successful in log-in to Windows, but their access to the internet is denied. What should the administrator check first?

a)

Whether the user is assigned to the correct AD group.

b)

The FortiGate firewall policy settings for SSL decryption.

c)

The FortiGate FSSO active users list for user’s IP address.

d)

The Windows event viewer for failed login attempts.

39.

What are three key routing principles in SD-WAN?

a)

By default, SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination.

b)

SD-WAN rules have precedence over any other type of routes.

c)

Regular policy routes have precedence over SD-WAN rules.

d)

By default, SD-WAN rules are skipped if only one route to the destination is available.

e)

By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

40.

Refer to the exhibits. An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access facebook.com, they are redirected to a FortiGuard web filtering block page. Based on the exhibits, which configuration change must the administrator make to allow Facebook while blocking all other social networking sites?

a)

Change the Feature set of Web Filter Profile as Proxy-based.

b)

Change the type as Simple in the Static URL Filter section.

c)

Set the Action as Exempt for www.facebook.com in the Static URL Filter.

d)

Set the Social Networking action as warning in the FortiGuard Category Based Filter.

41.

Refer to the exhibit. You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS. While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS. What could be the cause?

a)

Web filter is not enabled on the firewall policy to complement the antivirus profile.

b)

The feature set in the antivirus profile is not set to Flow-based.

c)

The SSL inspection mode in the firewall policy is not deep content inspection.

d)

The action on the firewall policy is not set to deny.

42.

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)?

a)

100.65.0.101

b)

100.65.0.49

c)

100.65.0.99

d)

100.65.0.149

43.

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver?

a)

Disable match-vip in the Allow_access policy.

b)

Configure a One-to-One IP pool object in a new policy.

c)

Set the Destination address as Webserver in the Deny policy.

d)

Set the Destination address as Deny_IP in the Allow_access policy.

44.

Refer to the exhibits. The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device. Based on the system performance output, what are the two possible outcomes?

a)

FortiGate has entered conserve mode.

b)

Administrators can access FortiGate only through the console port.

c)

Administrators can change the configuration.

d)

FortiGate drops new sessions.

45.

Refer to the exhibits. Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibit. What would be the expected outcome in the HA cluster?

a)

HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.

b)

HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.

c)

HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority.

d)

The HA cluster will become out of sync because the override setting must match on all HA members.

46.

Refer to the exhibits. An administrator wants to add HQ-ISFW-2 in the Security Fabric. HQ-ISFW-2 is in the same subnet as HQ-ISFW. After configuring the Security Fabric settings on HQ-ISFW-2, the status stays Pending. What can be the two possible reasons?

a)

Upstream FortiGate IP must be set to 10.0.11.254.

b)

SAML Single Sign-On must be set to Manual.

c)

HQ-ISFW-2 must be authorized on HQ-ISFW.

d)

Management IP must be set to 10.0.13.254.

47.

Refer to the exhibit. The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category. What are two solutions for satisfying the requirement?

a)

Configure a static URL filter entry for download.com with Type set to Wildcard and Action set to Block.

b)

Configure a web override rating for download.com and select Malicious Websites as the subcategory.

c)

Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.

d)

Set the Freeware and Software Downloads category Action to Warning.

48.

You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem?

a)

Use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 or 4500).

b)

Turn on fragmentation to fix large certificate negotiation problems.

c)

Configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP ports.

d)

Use the protocol IKEv2.

49.

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. You cannot access any of the Google applications, but you are able to access www.fortinet.com. Which two actions would you take to resolve the issue?

a)

Add “Google*.com” to the URL category in the security profile.

b)

Change the inspection mode to Flow-based.

c)

Set the action for Google in the Application and Filter Overrides section to Allow.

d)

Move up Google in the Application and Filter Overrides section to set its priority to 1.

e)

Set SSL inspection to deep-content inspection.

50.

Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. Which two factors can you observe from these configurations?

a)

YouTube search is allowed based on the Google Application and Filter override settings.

b)

Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings.

c)

Facebook access is blocked based on the category filter settings.

d)

YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings.

51.

Refer to the exhibit, which contains a RADIUS server configuration. An administrator added a configuration for a new RADIUS server. While configuring, the administrator enabled Include in every user group. What is the impact of enabling Include in every user group in a RADIUS configuration?

a)

This option places the RADIUS server, and all users who can authenticate against that server, into every FortiGate user group.

b)

This option places the RADIUS server, and all users who can authenticate against that server, into every RADIUS group.

c)

This option places all users into every RADIUS user group, including groups used for the LDAP server on FortiGate.

d)

This option places all FortiGate users and groups required to authenticate into the RADIUS server, which, in this case, is FortiAuthenticator.

52.

Refer to the exhibits. An administrator creates a new address object on the root FortiGate (HQ-NGFW-1) in the Security Fabric. After synchronization, this object is not available on the downstream FortiGate (HQ-ISFW). What must the administrator do to synchronize the address object?

a)

Change the csf setting on HQ-ISFW (downstream) to set configuration-sync local.

b)

Change the csf setting on HQ-ISFW (downstream) to set saml-configuration-sync default.

c)

Change the csf setting on HQ-NGFW-1 (root) to set fabric-object-unification default

d)

Change the csf setting on both devices to set downstream-access enable.

53.

Which three strategies are valid SD-WAN rule strategies for member selection?

a)

Lowest Cost (SLA) without load balancing

b)

Manual with load balancing

c)

Lowest Quality (SLA) with load balancing

d)

Lowest Cost (SLA) with load balancing

e)

Best Quality with load balancing

54.

What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device?

a)

Heartbeat interfaces have virtual IP addresses that are manually assigned

b)

Heartbeat IP addresses are used to distinguish between cluster members

c)

The heartbeat interface of the primary device in the cluster is always assigned IP address 169.254.0.1169.254.0.1

d)

A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster

55.

Refer to the exhibit showing a debug flow output. Which two conclusions can you make from the debug flow output?

a)

The default gateway is configured on port2

b)

The RPF check fails

c)

The debug flow is for UDP traffic

d)

The matching firewall policy denies the traffic

56.

When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate. Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate?

a)

Allow

b)

Trust & Allow

c)

Allow & Warning

d)

Block

e)

Block & Warning

57.

You want to ensure that an SSL VPN user's authenticated session does not remain active after they disconnect from the VPN. Which configuration will ensure this?

a)

Configure the firewall authentication session timeout to be lower than the SSL VPN session timeout

b)

Manually clear active firewall authentication sessions after a user disconnects

c)

Increase the SSL VPN idle timeout to reduce the chance of early disconnections

d)

Enable settings to force the firewall authentication session to end when the SSL VPN session ends

58.

Refer to the exhibit, which shows a firewall policy to enable active authentication. When attempting to access an external website using an active authentication method, the user is not presented with a login prompt. What is the most likely reason for this situation?

a)

The Service DNS is required in the firewall policy

b)

The Remote-users group must be set up correctly in the FSSO configuration

c)

No matching user account exists for this user

d)

The Remote-users group is not added to the Destination

59.

Refer to the exhibit. Why did the FortiGate device drop the packet?

a)

It matched the default implicit firewall policy

b)

It matched an explicitly configured firewall policy with the action DENY

c)

It cannot reach the next-hop IP

d)

It failed the RPF check

60.

Refer to the exhibit, which shows a routing table. An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only. What are the two criteria that the administrator can use to achieve this objective?

a)

The new static route must have the distance set to 9

b)

The existing static route through port3 must have the distance set to 11

c)

The new static route must have the priority set to 3

d)

The new static route must have the metric set to 1

61.

Refer to the exhibit. Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?

a)

None of the inspected protocols are active in this profile

b)

FortiGate, with less than 22\, GB RAM, does not support the Antivirus scan feature

c)

Antivirus scan is disabled under System -> Feature visibility

d)

The Feature Set for the profile is Flow-based but it must be Proxy-based

62.

An administrator has configured a dial-up IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about this scenario are correct?

a)

The administrator must enable a dynamic routing protocol on the dialup interface

b)

The administrator must use a policy route instead of a static route for add-route to work properly

c)

The administrator must ensure phase 2 is successfully established

d)

The administrator must define the remote network correctly in the phase 2 selectors

63.

An administrator configured a FortiGate device to act as a collector for agentless polling mode. What must the administrator add to the FortiGate device to retrieve AD user group information?

a)

TACACS server

b)

LDAP server

c)

RADIUS server

d)

Keycloak server

64.

What are two features of FortiGate FSSO agentless polling mode?

a)

FortiGate directs the collector agent to use a remote LDAP server

b)

FortiGate uses the SMB protocol to read the event viewer logs from the DCs

c)

FortiGate does not support workstation check

d)

FortiGate uses the AD server as the collector agent

65.

A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting many HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?

a)

The matching firewall policy is set to proxy inspection mode

b)

The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions

c)

The full SSL inspection feature does not have a valid license

d)

The browser does not trust the certificate used by FortiGate for SSL inspection

66.

A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tunnel when both tunnels are up; the secondary tunnel must be used only if the primary tunnel goes down. FortiGate should be able to detect a dead tunnel to speed up tunnel failover. Which two key configuration changes must the administrator make on FortiGate to meet the requirements?

a)

In the phase1-interface, enable npu-offload to detect a dead tunnel.

b)

Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.

c)

Enable Dead Peer Detection.

d)

Use the VPN wizard to create an IPsec template for a redundant IPsec VPN tunnel.

67.

An administrator wants to form an HA cluster using the FGCP protocol. Which two requirements must the administrator ensure both members fulfill?

a)

They must have the same HA group ID.

b)

They must have the heartbeat interfaces in the same subnet.

c)

They must have the same number of configured VDOMs.

d)

They must have the same hard drive configuration.

68.

FortiGate is integrated with FortiAnalyzer and FortiManager. When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

a)

Policy ID

b)

Log ID

c)

Universally Unique Identifier

d)

Sequence ID

69.

Refer to the exhibit. The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name. FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows. What could be the reason?

a)

SD-WAN rule names do not appear immediately; the administrator must refresh the page.

b)

There is no application control profile applied to the firewall policy.

c)

FortiGate load balanced the traffic according to the implicit SD-WAN rule.

d)

Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled.

70.

An administrator manages a FortiGate model that supports NTurbo. How does NTurbo acceleration enhance antivirus performance?

a)

For proxy-based inspection, NTurbo offloads traffic to the content processor.

b)

For flow-based inspection, NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces.

c)

For proxy-based inspection, NTurbo buffers the whole file and then sends it to the antivirus engine.

d)

For flow-based inspection, NTurbo creates two inspection sessions on the FortiGate device.

71.

Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Login.Failed signature to the IPS Sensor profile?

a)

The signature setting includes a group of other signatures.

b)

FortiGate stores a local copy of the packet that matches the signature.

c)

FortiGate allows this low-severity signature packet and creates a log.

d)

The signature setting uses a custom rating threshold.

72.

Refer to the exhibits. A diagram of a FortiGate device connected to the network VIP object and firewall policy configurations are shown. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. If the host 100.65.1.111 sends a TCP SYN packet on port 443 to 100.65.0.200, what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination?

a)

10.0.11.254, 10.0.15.50, and 4443, respectively

b)

100.65.1.111, 10.0.11.50, and 443, respectively

c)

10.0.11.254, 100.65.0.200, and 443, respectively

d)

100.65.1.111, 10.0.11.50, and 4443, respectively

73.

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate device. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.11.50?

a)

100.65.0.101

b)

100.65.0.200

c)

100.65.0.102

d)

10.0.11.254

74.

Based on the routing table shown in the exhibit, which two statements are true?

a)

A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.

b)

A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.

c)

A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.

d)

A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.

75.

An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?

a)

It uses DNS over TLS.

b)

It uses DNS over HTTPS.

c)

It uses UDP 8888.

d)

It uses UDP 53.

76.

What are two features of collector agent advanced mode?

a)

Advanced mode supports nested or inherited groups.

b)

In advanced mode, security profiles can be applied only to user groups, not individual users.

c)

In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.

d)

Advanced mode uses the Windows convention—NetBIos: Domain\Username.

77.

How can the administrator view the log messages shown in the exhibit? (Choose two.)

a)

Filtering by Policy UUID and Application Name in the log entry

b)

By right clicking the Implicit deny policy

c)

Through FortiGate CLI command diagnose log test

d)

Through Security event log page

78.

An administrator wants to address shadow IT visibility challenges and prevent users from sending sensitive tiles outside the organization without proper approval. Which FortiSASE method should the administrator implement to achieve these goals?

a)

Secure SD-WAN access (SSD-WAN)

b)

Secure private access (SPA)

c)

Secure SaaS access (SSA)

d)

Secure Internet access (SIA)

79.

Refer to the exhibit. You are configuring FortiAnalyzer on FortiGate. Which step must you take to connect FortiAnalyzer to FortiGate?

a)

Verify the FortiAnalyzer serial number.

b)

Authorize FortiGate on FortiAnalyzer.

c)

Enable disk logging on FortiGate.

d)

Configure UDP port 514 on FortiGate.

80.

You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS for FortiGate CNF policy enforcement for EC2 instance traffic. Which path does the EC2 traffic take from the EC2 instance to the internet?

a)

EC2 instance → internet gateway (IGW) → gateway load balancer (GWLB) → FortiGate CNF → internet

b)

EC2 instance → GWLB endpoint (GWLBe) → FortiGate CNF → IGW → internet

c)

EC2 instance → FortiGate CNF → GWLB → GWLBe → IGW → internet

d)

EC2 instance → GWLBe → FortiGate CNF → GWLBe → IGW → internet

81.

You are onboarding an agentless, secure web gateway (SWG) endpoint for secure internet access (SIA). What will happen to the user's nonweb traffic?

a)

All the nonweb traffic will bypass FortiSASE.

b)

The endpoint will use split tunneling to redirect nonweb traffic to FortiSASE.

c)

FortiSASE will use Firewall-as-a-Service (FWaaS) to redirect nonweb traffic.

d)

FortiSASE will use SWG to redirect nonweb traffic to FortiExtender.