FCP-FGT-AD-7-6 practice questions
Fortinet · FCP_FGT_AD-7.6 · 200 questions
Original practice questions for the FCP - FortiGate 7.6 Administrator (FCP_FGT_AD-7.6) exam, covering deployment and system configuration, firewall policies and authentication, content inspection, routing, and VPN on FortiOS 7.6.0 — framed in the network operations of a regional electric utility's field and substation infrastructure.
This course contains the use of artificial intelligence.
About the FCP_FGT_AD-7.6 exam
- Time allowed
- 1 hour 30 minutes
- Questions
- 50 multiple-choice
- Format
- Proctored; delivered through the Fortinet Training Institute
Exam details published by the vendor, checked 26 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Browse by Domain
Study specific topics at your own pace.
Deployment and System Configuration · 47 questions
- A regional electric utility is placing a new FortiGate at the edge of its grid-operations control-center network. The device must route between internal subnets, act as the default gateway for utility servers, and translate addresses for outbound traffic to remote substations. Which operating mode should the deployment team configure on the FortiGate?
- A substation has protection-relay traffic and status-monitoring traffic arriving over a single physical uplink cable to the FortiGate, and the utility's network team wants each traffic type on its own logical interface so separate firewall policies and IP subnets can apply, without running additional cabling. Which interface type should they create on top of the existing physical port?
- Field-service technicians bring laptops to a switching station and connect to a dedicated FortiGate interface for temporary network access. The utility wants those laptops to automatically receive an IP address, default gateway, and DNS server from the FortiGate itself, with no separate server on site. What should the network team configure on that interface?
- The grid-operations NOC's security team is hardening the FortiGate interface that faces the wide-area link to remote substations. They want administrators to still be able to reach the interface for management, but only over encrypted protocols, with legacy plaintext management protocols disabled. Which administrative access combination best fits that goal?
- A junior operator has just joined the grid-operations NOC team and needs to log in to the FortiGate to view interface status and generate reports, but should not be able to modify firewall policies or system settings. What is the correct way to provision this operator's account?
- The utility's security policy states that a particular administrator account should only ever be able to log in to the FortiGate from workstations inside the NOC's management subnet, even if the correct password is entered from anywhere else. Which FortiGate feature enforces this on the account itself?
- The utility is deploying two identical FortiGates as a redundant pair protecting the control-center perimeter, and wants both units to be capable of actively forwarding traffic at the same time to make use of both units' processing capacity, rather than leaving one unit completely idle until a failure occurs. Which FGCP cluster mode meets this requirement?
- A utility is inserting a FortiGate into an existing back-office network between the core switch and the billing servers, but the network team has been told they cannot renumber any device or change the default gateway on the billing servers during the migration window. Which operating mode lets the FortiGate be added inline for inspection without changing any existing IP addressing?
- The link between the NOC's core switch and the perimeter FortiGate is becoming a bandwidth bottleneck, and the utility also wants the connection to survive the failure of a single cable or switch port without an outage. Two additional physical ports are available on both devices. What should the network team configure to meet both goals?
- The utility's internet service provider assigns the FortiGate's WAN interface a public IP address automatically and can change that address at any time, rather than allowing the utility to fix a permanent address on that link. How should the network team configure IP addressing on that WAN interface?
- The utility's internet-facing FortiGate interface must remain reachable for basic connectivity testing by the ISP's monitoring system, but the security team wants to prevent that interface from responding to any request that could be used to log in or make configuration changes. Which administrative access setting best achieves this on the internet-facing interface?
- After a phishing attempt targeted several NOC staff, the utility's CISO wants FortiGate administrator logins to require something beyond just a correct password before granting access, so a stolen password alone is not enough to log in. Which account-level feature should the team enable to meet this requirement?
- The utility's SOC notices a burst of failed login attempts against a NOC administrator account, all originating from inside the account's already-permitted management subnet and consistent with an automated password-guessing attempt. Trusted hosts already restrict the account to that subnet, and the attempts are still failing on the password itself. Which account-level control most directly slows or stops this kind of repeated-guessing attempt?
- In the utility's FGCP cluster protecting the control-center perimeter, the two FortiGate units continuously exchange configuration synchronization and status information over a link dedicated to that purpose, separate from the interfaces carrying substation and back-office traffic. What is this dedicated link used for?
- A utility network engineer initially deployed a FortiGate in transparent mode to bridge two segments of the back-office network, but now needs the unit to also perform source NAT for outbound traffic and to route between several newly added subnets. What must the engineer do to support this new requirement?
- A small utility back-office closet has four physical FortiGate ports connected to four unmanaged switches serving printers and workstations that all belong to the same trust level, and the network team wants these four ports to behave as one interface without needing a firewall policy between them, while still preserving other physical ports for zone separation elsewhere. What should they configure?
- The utility has three separate substation uplink interfaces on the FortiGate, and the security team wants to write one set of firewall policies that treats all three as a single named group of interfaces for policy matching, rather than writing three nearly identical policies for each individual interface. Which FortiGate construct is designed for grouping interfaces this way for policy purposes?
- The utility centralizes its DHCP server at the NOC, but a remote substation's device segment sits on the far side of a FortiGate interface and cannot reach that central server with its normal broadcast-based DHCP requests. The utility does not want to deploy a local DHCP server at the substation. What should be configured on the substation-facing interface?
- An automation team at the NOC uses scripted CLI sessions to push configuration changes to the FortiGate on its internal management interface, and never uses the web GUI on that interface. The security team wants to reduce the interface's attack surface to only what the automation actually uses. Which change accomplishes that?
- During a security assessment, the utility discovers that every technician on the NOC team logs in to the FortiGate using one shared superadmin account, since it was the only account created at deployment time. What is the main problem with continuing this practice, and what should replace it?
- A field technician, working temporarily from a hotel network while traveling, tries to log in to the FortiGate using their personal administrator account and the correct password, but the login is rejected. The account's trusted hosts are configured to only the NOC management subnet. What is the most likely reason the login failed?
- In the utility's FGCP cluster, the primary unit has a monitored WAN interface configured for link health monitoring. That specific physical link to the ISP goes down, while every other interface on the primary unit remains healthy. What is the expected FGCP behavior?
- A network engineer bundles two physical ports on the FortiGate with two ports on the NOC's core switch into an aggregate interface, but after cabling both links the interface still shows only one member port as active and traffic never balances across both. What is the most likely cause?
- In the utility's FGCP cluster, the original primary unit fails and the secondary unit takes over as primary. A few hours later, the original unit is repaired and rejoins the cluster with its higher configured priority restored. The utility wants the cluster to keep the current secondary-turned-primary unit in charge, rather than automatically switching primary roles back the moment the repaired unit returns. What HA setting controls this behavior?
- The grid-operations NOC wants every substation FortiGate to automatically pull the newest antivirus and IPS signature packages from Fortinet on a recurring schedule, without an engineer manually loading files onto each device. Which FortiGuard capability accomplishes this?
- A substation FortiGate's IPS and application-control signature packages stopped updating even though the unit has internet reachability to FortiGuard. What is the most likely cause the NOC should check first?
- Before scheduling a firmware upgrade on an unstaffed substation FortiGate, an engineer needs to confirm the device won't be pushed to a version it can't safely reach in a single jump. What should the engineer consult?
- Before applying a batch of policy and interface changes to a remote switching-station FortiGate, an engineer wants a safety net that lets them undo everything in minutes if the change goes wrong. What should they do first?
- A compliance auditor asks the NOC to confirm that configuration backups for control-center FortiGates cannot be read by anyone who happens to find the exported file on a USB drive left in a drawer. What should the NOC verify is enabled on those backups?
- A grid-operations security team wants six months of firewall log history available for a post-incident investigation, but the substation FortiGate has limited local disk space. Which logging approach best fits this requirement?
- A NOC analyst configures a substation FortiGate to send log entries to a central syslog server, but wants routine allowed-traffic events excluded so the server only receives security-relevant activity. What should the analyst adjust?
- The NOC's network monitoring platform needs to poll a substation FortiGate's CPU, memory, and interface counters every few minutes without being able to change any configuration on the device. Which feature fits this requirement?
- In addition to periodic polling, the NOC wants a substation FortiGate to proactively notify the monitoring platform the moment an interface goes down, rather than waiting for the next scheduled poll. What SNMP mechanism supports this?
- A regional utility runs both its grid-operations network and a physically separate corporate back-office network through the same physical FortiGate appliance at the control center, and wants each network's firewall configuration and routing table to be fully independent of the other. What FortiOS feature is designed for this?
- An engineer enabling the Security Fabric on a control-center FortiGate that has multiple VDOMs configured needs to decide which VDOM should host the fabric root role. What consideration should guide that decision?
- A NOC director wants a single consolidated view showing how the control-center FortiGate, downstream FortiGates at major substations, and their connected Fortinet devices relate to one another, along with an overall security posture score. What Fortinet capability provides this?
- In a Fortinet Security Fabric spanning the control-center FortiGate and several substation FortiGates, what role does the control-center device play as the fabric root?
- Before upgrading firmware on a switching-station FortiGate, an engineer wants to know whether any features currently in use will behave differently or be deprecated in the target version. Where should the engineer look?
- After successfully completing a change window on a substation FortiGate, an engineer wants to make sure the newly applied configuration itself is captured as a recovery point, not just the pre-change state. What should the engineer do once the change is confirmed stable?
- A substation FortiGate is configured to log only to its own local disk, with no external log destination. What operational risk does this configuration carry that is specific to a remote, unstaffed site?
- A NOC engineer notices that a substation FortiGate's hardware failed and needs an RMA replacement, and separately wonders whether that failure affects the unit's FortiGuard content subscription. What is the correct relationship between hardware support (RMA) entitlement and FortiGuard content subscription entitlement?
- An engineer is about to push a firmware upgrade to a remote switching-station FortiGate over a slow WAN link. Which precaution most directly reduces the risk of an unrecoverable outage if the upgrade fails partway through?
- A utility places its field-crew VPN termination in one VDOM and its corporate billing network in a separate VDOM on the same physical FortiGate. If a field-crew VPN policy is misconfigured, what is the expected effect on the corporate billing VDOM's firewall policies?
- The NOC wants the Security Fabric to be aware of resources beyond just other FortiGate devices, for example, information from a connected third-party or Fortinet ecosystem service that enriches the fabric's visibility. What general mechanism supports this kind of integration?
- A field engineer reports that a substation FortiGate can browse general internet sites fine but is failing to retrieve FortiGuard signature updates, and initially assumes a network outage. What check would most quickly distinguish a licensing problem from an actual connectivity problem?
- A NOC security reviewer flags that a substation FortiGate is using SNMPv1 community strings for monitoring and recommends moving to SNMPv3. What is the main security improvement SNMPv3 provides over SNMPv1/v2c community strings?
- Immediately after a firmware upgrade completes on a remote substation FortiGate, what is the most important verification step before considering the maintenance window closed?
Firewall Policies and Authentication · 47 questions
- A utility NOC engineer creates a firewall policy permitting field-service laptops on the Field-VPN interface to reach the outage-management server on Corp-LAN over HTTPS, with a schedule object scoped to weekday business hours. A field technician reports the connection is refused when working an after-hours storm restoration call, even though the technician's laptop, destination address, and service all match the policy exactly. Why is the policy not matching this after-hours session?
- The security team at a regional utility adds a new, tightly scoped policy allowing only maintenance traffic from a single substation RTU host to a specific historian server, but places it below an existing broad policy that already permits all substation-to-corporate traffic on the same interface pair. After activation, traffic still matches the broad policy instead of the new narrow one. What is the correct explanation for this behavior in FortiOS 7.6?
- A utility's field-operations network includes three subnets used by different crew types: overhead-line trucks, substation maintenance vans, and metering technicians. The security engineer wants every crew subnet to share one identical firewall policy permitting access to the work-order dispatch server, and wants to add or remove a crew subnet later without editing the policy itself. Which approach best achieves this in FortiOS 7.6?
- A third-party protection-relay vendor provides remote support to a substation device from a cloud-hosted jump host whose public IP address changes periodically because the vendor uses a dynamic-DNS provider. The utility wants a firewall policy that keeps working automatically as the vendor's IP changes, without a scheduled task to update the policy. Which address-object type is designed for this in FortiOS 7.6?
- A work-order dispatch application at a utility's back-office site listens on TCP port 8443 instead of the standard HTTPS port, and no built-in FortiOS service object matches it. A field crew's laptops need a policy that permits only that exact application traffic, nothing broader. What should the engineer configure to match this traffic precisely?
- A field crew's laptops need to reach the work-order dispatch server over three separate custom TCP services the application uses for data sync, file transfer, and status polling. The security engineer wants a single firewall policy line, and wants to add a fourth service later without touching the policy. What should the service field reference?
- A utility schedules a one-night cutover maintenance window during which a vendor's support laptop needs firewall access to a substation relay that is normally blocked. The change window is a single calendar date and time range, never to repeat. Which FortiOS schedule object type fits this requirement, as opposed to the type normally used for standing business-hours access?
- A newly deployed FortiGate at a small substation has exactly one explicit firewall policy configured, permitting the local RTU to reach the NOC historian server over one specific service. A different device on the same substation subnet, not covered by that policy, attempts to reach an unrelated corporate server. What happens to that second device's traffic?
- A security auditor at the utility wants visibility into every connection attempt that field devices make toward the corporate back-office network that isn't explicitly permitted by any policy, to spot reconnaissance or misconfigured devices. Reviewing the FortiGate's traffic logs, the auditor finds no entries at all for denied sessions, even though explicit policies are correctly logging their own traffic. What is the most likely reason?
- A utility's SOC wants full session-level visibility into traffic between the corporate billing network and the field-operations network, including successful, uneventful sessions with no security profile hits, for a compliance audit trail. An engineer reviews an existing policy and finds its logging option set to log security events only. What does the engineer need to change to meet the SOC's requirement?
- A network engineer notices that a high-volume policy carrying routine telemetry between two internal utility segments has its logging option set to disable logging entirely, to keep log storage manageable. During a later incident investigation, the SOC needs to reconstruct exactly which internal hosts communicated across that policy during a specific hour, but the traffic log has no relevant entries. What is the best explanation, and the trade-off it represents?
- Field-service laptops on a utility's Field-VPN segment need outbound access to a cloud-hosted mapping service, but the utility wants those laptops to appear on the internet as the FortiGate's public WAN interface address rather than their internal private addresses. Which policy-level setting accomplishes this in a standard, non-central-NAT firewall policy?
- A utility is redesigning its NAT strategy across dozens of firewall policies that each need slightly different source-NAT behavior for field, substation, and back-office traffic. The network architect wants NAT rules managed as their own centralized rule set, separate from and independently ordered from the firewall policies that permit the traffic. Which FortiOS 7.6 NAT model matches this requirement, as opposed to configuring NAT directly on each firewall policy?
- A utility's back-office network has far more internal hosts needing outbound internet access than it has spare public IP addresses. The network engineer wants many internal hosts to share a small handful of public addresses simultaneously, distinguishing their sessions by source port rather than by a dedicated address per host. Which FortiOS IP pool type is designed for this?
- A substation's data-historian gateway needs a stable, individually identifiable public IP address for every outbound session it initiates, because a downstream cloud analytics partner allowlists connections by source IP and expects exactly one gateway per address, never a shared one. Which IP pool type fits this requirement?
- A utility shares one small overload IP pool across many back-office hosts for outbound access, and the SOC needs to trace a suspicious outbound connection reported by the analytics partner back to the specific internal host that generated it, using only the shared external address and port at the time of the connection. Which IP pool feature makes this kind of per-host attribution practical at scale?
- A vendor's field-diagnostic application on a utility crew's laptop requires that its outbound source port never change across the life of a session, because the receiving cloud service correlates requests by the exact source port the client first used. The laptop's traffic already passes through an overload IP pool shared with other crew laptops. What NAT adjustment addresses the application's requirement, and what does it cost?
- A utility exposes a substation's engineering-access web console to a small set of external vendor IP addresses for remote diagnostics, without giving the vendor a route into the substation's internal address space directly. External requests arrive at one of the FortiGate's public WAN addresses and must be redirected to the console's actual private address behind the firewall. Which FortiOS construct is designed to perform this kind of external-to-internal address translation for inbound traffic?
- A utility wants external vendor access to a substation console's management interface, which listens only on internal TCP port 8080, but wants vendors to connect using the more familiar external port 443 on the FortiGate's public address, rather than remembering a nonstandard port. Which VIP configuration accomplishes translating both the address and the port in a single object?
- A network engineer configures a virtual IP mapping a public WAN address to a substation console's private address, expecting that creating the VIP object alone is enough to let the vendor's traffic reach the console. After saving the VIP, vendor connection attempts still fail with no matching traffic appearing in any explicit policy's log. What additional step does FortiOS require before this VIP actually forwards traffic?
- After a utility redesigns its WAN routing so that return traffic from the corporate billing network to a field crew's VPN session now takes a different path back through a second FortiGate interface than the path the session originally went out on, the crew's application connections begin silently failing partway through. What FortiOS mechanism explains why asymmetric routing like this breaks stateful sessions?
- A utility engineer tightens a firewall policy to block a category of traffic between the field network and the corporate billing network that used to be allowed, expecting the change to take effect immediately. Several existing field-device sessions that were already open before the change continue passing traffic for some time afterward, even though the same traffic is now correctly blocked for brand-new connection attempts. Why do the existing sessions keep working after the policy change?
- A utility engineer finds that outbound sessions from the field-crew subnet are being denied, even though a central SNAT policy exists that matches the subnet and specifies the correct overload pool. Reordering the central SNAT policy list makes no difference to the denies. What does this indicate about how central SNAT relates to the firewall policy's accept-or-deny decision?
- A utility configures a VIP so an internal back-office subnet can reach a substation console using the substation's public-facing address, even though both networks sit behind the same FortiGate, a hairpin scenario where the traffic enters and exits through interfaces the firewall must handle carefully. The VIP and an appropriate inbound policy are both configured, but internal back-office hosts still cannot reach the console this way, while genuinely external vendor traffic to the same VIP works correctly. What is a likely missing piece specific to this internal hairpin case?
- A regional utility's NOC wants engineers to prove their identity before a firewall policy allows them onto the internet from the control-center LAN, rather than just letting any device on that subnet browse freely. What does adding firewall authentication to that policy actually change?
- A utility's control-center FortiGate needs firewall-authenticated access for only three short-term contractors doing a one-week substation audit, with no existing directory service reachable from that segment. Which authentication approach best fits this situation?
- A utility's NOC configures a FortiGate to authenticate field technicians against a central RADIUS server before granting VPN access into the substation network. What must the FortiGate and the RADIUS server share for this authentication exchange to succeed?
- A utility wants its FortiGate to authenticate corporate back-office staff against the existing Active Directory service used for billing and dispatch systems, without creating separate accounts. Which concept describes how the FortiGate locates and reads a user's entry in that directory during LDAP authentication?
- A utility's FortiGate has two firewall policies for the same source subnet: one referencing a 'Substation-Vendors' user group with limited access, and one referencing a 'NOC-Engineers' user group with broader access. A vendor logs in but was never added to either group. What happens to their traffic?
- A field contractor working on billing-system integration was mistakenly added to the utility's 'Substation-Vendors' group instead of the 'Back-Office-Contractors' group. What is the most direct consequence for that contractor's firewall-authenticated sessions?
- A utility's security team is documenting authentication methods for their FortiGate deployment and needs to distinguish active from passive authentication. Which statement correctly describes that distinction?
- Visitors to a utility's control-center building connect to a guest wireless network and are shown a branded web page requiring them to accept an acceptable-use disclaimer before internet access is granted. Which authentication mechanism is this?
- A NOC operator logs into their domain-joined workstation each morning and, without ever seeing a login prompt on the FortiGate, is immediately granted the access their user group is entitled to when browsing out to vendor documentation sites. Which authentication approach produces this experience?
- A utility wants its guest wireless captive portal to display a legal disclaimer and require a checkbox acceptance, but explicitly does not want to issue individual guest usernames and passwords. Is this achievable with a FortiGate captive portal?
- A utility deploys FSSO so that corporate back-office staff are transparently identified when their domain-joined workstations generate traffic through the FortiGate. Conceptually, how does the FortiGate typically learn which username is associated with a given workstation's IP address in this deployment?
- A contractor brings a personal, non-domain-joined laptop onto the utility's corporate network segment where FSSO is used to identify back-office staff. What happens to that contractor's identity from the FortiGate's perspective?
- A utility wants to strengthen authentication for a small set of high-privilege NOC accounts by requiring something beyond just a password. What does adding two-factor authentication accomplish?
- A vendor technician remotely connects over VPN to perform scheduled substation maintenance. The utility requires the vendor to supply both a password and a push-approved code from a mobile authenticator app before the session is established. What security property does this combination primarily provide compared to password-only VPN access?
- A utility issues a temporary local user account on the FortiGate for a two-day facility inspection by an outside auditor, with the account set to expire automatically at the end of the visit. What is the main operational benefit of using an expiring guest-style account here rather than a standard, permanent local account?
- A utility distinguishes between a 'Guest' access tier for unmanaged, walk-in visitors and a 'Contractor' group for vetted third parties with an ongoing work order. Why does this distinction matter for how firewall policies are written?
- A utility is evaluating certificate-based user authentication as an alternative to password-based login for a set of engineering laptops accessing the control-center network. Conceptually, what does this approach rely on instead of a shared password?
- A vendor's laptop presents a client certificate during an authentication attempt to the utility's FortiGate, but the certificate was issued by a certificate authority the FortiGate does not trust. What is the most likely outcome?
- A NOC operator authenticates once in the morning and then steps away from their workstation for an extended lunch, leaving the session idle. Why would the utility configure an authentication timeout on that firewall policy?
- A utility's FortiGate is configured to authenticate NOC staff against a RADIUS server first, with a local user group configured as a fallback. During a network outage, the RADIUS server becomes unreachable. What should happen for a NOC operator attempting to authenticate during the outage, assuming their account also exists locally?
- A utility's firewall policy references a user group called 'NOC-Engineers' rather than listing each engineer's individual username. What operational advantage does referencing the group provide over listing individuals directly in the policy?
- A utility configures LDAP authentication so that the FortiGate not only verifies a back-office employee's password against the corporate directory, but also checks which LDAP group the employee belongs to, in order to decide which firewall policy applies. What is this second check, beyond password verification, generally called?
- A utility offers NOC operators a choice between a FortiToken Mobile push notification they approve with a tap, or manually typing a rotating numeric code from the same app, as their second authentication factor. What is the key practical difference between these two options?
Content Inspection · 59 questions
- A regional utility's NOC administrator wants FortiGate to buffer entire downloaded files from the corporate billing segment so antivirus can inspect the complete payload and present a custom block page when malware is found, rather than simply resetting the session mid-transfer. Which inspection mode should the policy use to get that behavior?
- A network engineer is designing the firewall policy for the link between a remote substation and the utility's NOC, where throughput and low latency matter more than the richest possible content-inspection feature set. The engineer selects flow-based inspection for that policy. What is the main architectural reason flow-based inspection fits this requirement?
- An OT vendor's application on the grid-operations network uses certificate pinning and breaks whenever its TLS session is decrypted. The NOC team applies certificate inspection instead of deep inspection to that traffic so they can still log destinations by category. What is FortiGate actually able to determine under certificate inspection?
- The utility's security team needs FortiGate to detect malware embedded inside HTTPS downloads on the corporate billing segment, not just identify which domains are being visited. Which SSL inspection approach is required to make that content visible to the antivirus engine?
- After the utility enables a deep-inspection SSL profile on the policy covering NOC administrator workstations, several staff report that their browsers now show certificate warnings on ordinary HTTPS sites. What is the most likely cause, and what should the team do about it?
- The OT vendor's substation application keeps failing under deep inspection because it pins the destination server's exact certificate and rejects any substitute FortiGate presents. The NOC team wants to keep deep inspection active for all other traffic on that policy while letting this one application through untouched. What is the appropriate mechanism?
- A utility security analyst is comparing how antivirus scanning behaves in a flow-based firewall policy versus a proxy-based one for the field-technician VPN segment. Which statement correctly describes flow-based antivirus scanning?
- The back-office work-order dispatch segment uses proxy-based inspection with antivirus enabled, and a field engineer downloads a firmware image far larger than the antivirus profile's configured oversize-file threshold. What is the expected behavior for that download?
- A utility administrator notices that a particular replacement-message behavior available on one firewall policy is not available on another policy carrying an otherwise identical antivirus profile. What most likely explains the difference?
- The billing back-office segment only needs FortiGate to enforce category-based web filtering on HTTPS traffic (blocking known-bad domains) and does not require the firewall to detect malware hidden inside encrypted downloads. Which SSL inspection choice satisfies this requirement with the least decryption overhead?
- A NOC engineer proposes turning off SSL inspection entirely for the whole corporate segment just to stop certificate warnings on the OT vendor's pinned application, instead of adding that one application to the SSL exemption list. What is the main drawback of the engineer's proposed approach?
- When deep inspection is active on the FortiGate protecting the NOC, how does the FortiGate present a certificate to an internal workstation browsing to an external HTTPS site?
- A deep-inspection profile has been running smoothly for over a year on the NOC's outbound policy, with the signing CA certificate already trusted on every workstation. One morning, every workstation on that policy simultaneously starts showing certificate warnings on every HTTPS site, with no configuration change made overnight. What is the most likely cause?
- A utility network architect is choosing an inspection mode for a high-throughput fiber link between two substations that mostly carries routine telemetry and management traffic, where CPU and memory headroom on the FortiGate are limited and full-object buffering is not a priority. Which mode best fits this constraint?
- The utility's compliance team wants FortiGate to block access to a specific URL path on an otherwise-permitted HTTPS site (for example, blocking only a particular page on a general-purpose SaaS site) rather than blocking the whole domain. Which SSL inspection setting is required to make path-level filtering possible?
- A utility security engineer configures antivirus on a proxy-based policy so that when a file download is confirmed infected, FortiGate withholds the file from the requester and presents a substitute notification page rather than merely dropping the connection. Which behavior does this depend on that flow-based inspection does not provide in the same way?
- Rather than manually listing every FQDN belonging to third-party software-update and SaaS vendors the NOC relies on, an administrator wants FortiGate to exempt whole categories of well-known, low-risk destinations from SSL deep inspection. What FortiGate capability supports this without hand-building a custom address list for every vendor?
- The utility's security team is finalizing separate firewall policies for two different traffic types crossing the same FortiGate: general corporate web browsing on the billing segment, and the OT vendor's certificate-pinned application on the substation segment. Which pairing of inspection choices best matches each traffic type's needs?
- The utility's antivirus profile on the corporate billing segment is fully configured and applied to the policy, yet malware embedded inside an HTTPS download from an external site is not being detected. Investigation shows the policy's SSL/SSH inspection profile is set to certificate inspection. What is the most likely explanation for the missed detection?
- Reviewing the utility's overall content-inspection design, an auditor asks why the billing segment uses deep inspection with full antivirus and web filtering, the substation segment uses certificate inspection with an SSL exemption for the OT vendor's pinned application, and the NOC administrator segment uses deep inspection plus a distributed trusted CA certificate. What principle best explains why these three segments are configured differently rather than sharing one SSL/SSH inspection profile?
- Meridian Electric Cooperative's NOC workstation policy applies a web filter profile containing a static URL filter list with a Block entry for one site, while the FortiGuard category that same site belongs to is configured with a Monitor action. When a NOC analyst browses to that site, what happens, and why?
- An administrator adds Meridian Electric Cooperative's OT vendor support portal to the static URL filter list with the Exempt action so field engineers can always reach it. What is the practical effect of choosing Exempt instead of Allow for that entry?
- Meridian Electric Cooperative wants field-service technicians to see a notice before opening a category of sites that is discouraged but sometimes operationally necessary, rather than blocking it outright. Which FortiGuard category action fits this requirement?
- Meridian Electric Cooperative doesn't want to fully block a streaming-video category on back-office workstations, but wants usage capped so it doesn't consume WAN bandwidth all day. Which web filter category action is designed for exactly this?
- Meridian Electric Cooperative wants FortiGate to force safe search on a search engine that back-office staff use over HTTPS, using the web filter profile's safe search option rather than a DNS-based rewrite. What does FortiOS need in place for that enforcement to actually take effect on the HTTPS traffic?
- An administrator at Meridian Electric Cooperative wants to guarantee that one specific vendor domain is always treated a certain way, independent of how FortiGuard's cloud rating service currently classifies it. Which web filter mechanism should the administrator use for that guarantee?
- Meridian Electric Cooperative wants to stop NOC workstations from reaching a risky category of destinations no matter what application or port a user tries to reach them with. Why is a DNS filter profile particularly well suited to that goal, compared to relying on web filtering alone?
- Meridian Electric Cooperative's web filter profile blocks a specific category, and the destination sites are all HTTPS. Which statement correctly distinguishes what FortiGate can enforce on that HTTPS traffic without SSL deep inspection versus with it enabled?
- A field technician's laptop at Meridian Electric Cooperative runs a messaging application configured to use a nonstandard TCP port instead of its usual default. Why is application control still able to identify and act on that traffic, unlike a rule that matched purely on destination port?
- Meridian Electric Cooperative wants to block essentially every application in the Peer-to-Peer category on back-office workstations, but allow one specific internal file-transfer application even though it happens to fall into that same category. How does an application control profile support this?
- Without SSL deep inspection enabled, what is a realistic expectation for application control's ability to identify applications running inside fully encrypted HTTPS sessions?
- Meridian Electric Cooperative wants to restrict which video categories back-office staff can watch on a major video-sharing site. That site is served entirely over HTTPS. What does the video filter profile require in order to make category- or channel-level decisions on that traffic?
- Meridian Electric Cooperative has a FortiGuard category that field technicians occasionally need for legitimate vendor research, but the security team wants access tied to a specific, identifiable person rather than allowed for anyone who happens to click past a notice. Which web filter category action fits this requirement?
- Before deciding whether to block a newly observed web category on substation-facing workstations, a Meridian Electric Cooperative administrator wants to see how often that category is actually being visited without interrupting anyone's browsing yet. Which category action fits this exploratory step?
- NOC administrators notice that FortiGuard category-based web filter actions have stopped taking effect on Meridian Electric Cooperative's FortiGate, even though the web filter profile configuration hasn't changed. Which underlying condition would most directly explain this symptom?
- An administrator at Meridian Electric Cooperative needs a static URL filter entry that matches an entire family of subdomains used by one vendor, not just a single exact address. What capability of the static URL filter list makes this possible?
- Meridian Electric Cooperative uses a proprietary OT vendor protocol on the field-service segment that Fortinet's application signature database does not recognize. The administrator wants a deliberate, configured decision for this kind of unrecognized traffic rather than an accidental default. Where in an application control profile is that decision made?
- When Meridian Electric Cooperative's DNS filter profile blocks a category, browser-based traffic to a blocked domain typically shows the technician a FortiGuard block/landing page, while a non-browser OT client attempting to reach that same blocked domain simply fails to connect with no page shown. What explains this difference?
- Meridian Electric Cooperative's NOC wants to block objectionable video content for staff browsing over HTTPS, in addition to their existing Web Filter profile. How should the administrator configure this in FortiOS 7.6, and what does it require to act on the HTTPS sessions?
- Meridian Electric Cooperative needs one specific page on a shared corporate SaaS domain permitted while blocking every other page on that same domain for back-office users. Why is a DNS filter profile the wrong tool for this specific requirement, even though it could block the whole domain easily?
- A network engineer at a regional electric utility builds and tunes an IPS sensor for the substation segment, but does not touch any existing firewall policy. What happens to traffic entering that segment?
- A field engineer keeps seeing IPS alerts fire and block a legitimate operational polling protocol traveling between the NOC and a substation switching station. The sensor protecting that link covers a broad set of signatures. Which change addresses the false positive with the least collateral impact on the rest of the substation's protection?
- A security engineer is evaluating an IPS signature described as "rate-based" for detecting a flood-style scan attempt against the utility's back-office web application. Which best describes how a rate-based signature differs from a standard signature match?
- Meridian Electric Cooperative is enabling IPS on a substation link for the first time and wants to see which signatures would actually fire against real traffic before any of them are allowed to interrupt substation communications. Which rollout approach fits how FortiGate IPS is designed to be tuned in?
- Which best describes what a file filter profile does within a firewall policy protecting the utility's back-office file-transfer traffic?
- A work-order dispatch system at the utility only accepts image attachments, but an operator renames an executable file to end in ".jpg" hoping to slip it past a simple content check. How does a properly configured file filter profile generally handle this attempt?
- The utility wants to reduce the risk of operational data, such as substation configuration exports, leaving the network through the back-office email gateway. Which capability is purpose-built for identifying that kind of sensitive content within the traffic stream?
- When rolling out a new DLP filter to protect the flow of operational data from the grid-operations network toward the internet-facing back-office segment, which action choice lets the security team observe matches before committing to enforcement?
- After attaching IPS, file filter, and DLP profiles to the policy protecting the substation link, an engineer wants to confirm the profiles are actually evaluating traffic rather than just being present in the policy configuration. What is a reliable way to verify this?
- An IPS signature entry lists attributes such as severity and target operating system. What is the general purpose of these attributes when an administrator is building a sensor for the utility's back-office servers?
- A utility technician emails a password-protected .zip archive containing several files toward the internet-facing gateway. In general terms, why might a file filter profile fail to enforce its file-type rule on the files stored inside that archive?
- The utility wants to catch unusually large exports of operational data leaving the grid-operations segment even without knowing the exact content pattern in advance. Which DLP filter match criterion best supports that goal?
- Two IPS actions available for a matched signature are "block" and "reset." In general terms, what distinguishes "reset" from a plain "block" when a match occurs on TCP traffic?
- An administrator created a DLP profile and confirmed its filters are configured correctly, but traffic matching the sensitive pattern still passes untouched through the firewall policy protecting the back-office email gateway. What is the most likely cause?
- When an administrator adds a predefined IPS signature to a sensor without changing its action, what generally happens?
- For a DLP profile designed to prevent operational data from leaving the grid-operations segment toward the internet, which firewall policy is the correct place to attach it?
- A firewall policy protecting an outbound path from the back-office segment has both a file filter profile and a DLP profile attached. A file being transferred matches a block rule in the file filter profile. What happens to that specific transfer, at minimum?
- A work-order dispatch upload was blocked by the FortiGate protecting the back-office segment, but the operator doesn't know which security profile caused it. What is the most direct way for an engineer to determine which profile — IPS, file filter, or DLP — took the action?
- A utility security team is documenting the roles of IPS, file filter, and DLP profiles for their FortiGate deployment. Which statement correctly distinguishes the three from each other?
Routing · 24 questions
- A grid-operations engineer is configuring a new static route on the control-center FortiGate so traffic for a remote substation's management subnet goes out over the primary fibre uplink. Besides the destination subnet, which pair of parameters must the static route specify to actually forward traffic toward that substation?
- The NOC's FortiGate holds a static route for 10.20.0.0/16 out the primary fibre link to the regional aggregation site, and a second static route for 10.20.4.0/24 out the cellular backup modem, covering one specific substation inside that larger block. A workstation at the NOC sends a packet to 10.20.4.50. Which route does the FortiGate use to forward it?
- A network administrator at the utility's NOC is reviewing two static routes to the same remote substation subnet: one via the fibre interface with administrative distance 10, and one via the cellular backup interface also with administrative distance 10 but a higher priority value. How does the FortiGate use these two values differently when deciding which route to install?
- A regional utility's NOC FortiGate has specific static routes for every known substation and back-office subnet, plus a 0.0.0.0/0.0.0.0 static route pointing out the WAN interface toward the utility's upstream ISP. What role does that 0.0.0.0/0.0.0.0 entry play in the routing table?
- The utility has summarized several small substation subnets into a single /20 static route advertised toward its upstream provider. One of the smaller subnets inside that /20 is not actually in use yet. What is the purpose of adding a blackhole static route for that specific unused subnet on the FortiGate?
- The NOC FortiGate has two static routes to the same regional data-center subnet: one out primary fibre and one out a secondary fibre link from a different provider, both left at the default administrative distance and the default priority. What does the FortiGate do with traffic to that data-center subnet as a result?
- A field-services team wants all traffic sourced from the technician-laptop subnet, regardless of destination, to exit through the cellular backup link instead of the primary fibre uplink, even though the main routing table still prefers fibre for every destination. Which FortiGate routing feature is designed for this kind of source-based forwarding override?
- After the NOC team adds a policy route sending technician-VPN return traffic out a different interface than the one packets arrived on, some sessions start failing even though the policy route and firewall policy both look correct. What FortiGate mechanism is most likely dropping this traffic?
- The NOC wants the FortiGate to automatically detect when the primary fibre link to a remote substation stops passing traffic — not just when the physical interface goes down — and fail over to the cellular backup route before operators notice an outage. Which FortiGate capability is designed for this kind of active, above-layer-1 reachability check?
- While a technician's VPN session to a substation is actively transferring data over the primary fibre route, an administrator adds a new, more specific static route that would send that same destination over the cellular backup link instead. What happens to the technician's already-established session?
- An administrator configures two static routes to the same remote substation: one out the primary fibre interface with priority 0, and one out the cellular backup interface with priority 10, both at the same administrative distance. Under normal conditions, with both links up, which route forwards traffic to the substation?
- A FortiGate at a substation has a manually configured static route to the NOC's back-office subnet with administrative distance 10, and also learns a route to the same subnet dynamically with a higher administrative distance from a routing protocol. Assuming both routes have the same prefix length, which route does the FortiGate install as active in its routing table?
- The utility's routing table contains a static default route (0.0.0.0/0.0.0.0), a static route for 172.16.0.0/16 covering the whole substation network, and a static route for 172.16.8.0/22 covering one regional cluster of substations. A packet is destined for 172.16.8.100. Which route does the FortiGate select?
- The utility summarizes its entire remote-substation address space as a single route advertised toward its WAN transport provider so the provider's routers don't need dozens of individual entries. If one substation subnet inside that summary is temporarily decommissioned, why would an engineer add a blackhole route for just that subnet on the FortiGate, rather than leaving it unhandled?
- With ECMP active across the NOC's two fibre uplinks to a regional aggregation point, engineers notice that a single large file transfer only ever uses one of the two links, even though many separate sessions are spread across both. Why does ECMP behave this way for that one transfer?
- A substation's primary fibre static route has a configured link health monitor that pings a target on the far side of the NOC's aggregation router. The fibre physically stays up, but the aggregation router itself stops responding to the probe. What is the expected effect on the routing table?
- An administrator configures a policy route that forces all traffic from the back-office billing subnet out through a specific WAN interface and gateway, but that WAN interface is currently down. What happens to traffic matching the policy route while the interface is down?
- Two static routes exist for the same substation subnet: one via fibre at administrative distance 10 and priority 5, and one via cellular at administrative distance 20 and priority 1. Which route is active in the routing table under normal conditions?
- A utility's NOC uses dual WAN links to two different upstream providers, with policy routes sending traffic to certain destinations out one link while replies to other, unrelated sessions legitimately return over the other link based on the routing table each provider maintains. What is the general concern this design raises for the FortiGate's default anti-spoofing behavior?
- An engineer adds a new static route on the substation FortiGate and leaves the administrative distance field at its default value, without learning any competing route to the same destination from a dynamic routing protocol. What administrative distance does that static route receive by default?
- A substation has two egress paths to the NOC: a fibre link and a cellular modem, both terminated on the same FortiGate and both currently healthy. The utility wants outbound telemetry traffic automatically split across both links based on real-time latency and jitter measurements, rather than always preferring one link unless it fails outright. Which approach fits this requirement?
- ECMP is configured across three equal-cost fibre paths from the NOC to a shared regional hub, but monitoring shows one path consistently carries far more traffic than the other two, even though hundreds of independent sessions exist. What is the most likely explanation, assuming all three routes are correctly configured at equal distance and priority?
- An engineer deletes the only static route to a remote substation subnet entirely — not replacing it with a different route, just removing it — while a technician has an active session to a device in that subnet. What is the most accurate expectation for that already-established session?
- Summarizing everything a FortiGate considers when multiple candidate paths exist to the same substation subnet, in which order does it actually apply longest-prefix match, administrative distance, and priority to decide the active route?
VPN · 23 questions
- A utility's NOC engineer is building a new site-to-site IPsec tunnel to a remote substation FortiGate. During IKE phase 1, the two devices must agree on how to protect the negotiation itself before any user traffic can be defined. Which set of parameters is negotiated in phase 1?
- During phase 2 of an IPsec negotiation between the utility's NOC FortiGate and a substation peer, the administrators must agree on which specific traffic will be encrypted and how the data-plane security association is protected. What does phase 2 primarily negotiate?
- A utility wants to add a new substation to its hub-and-spoke IPsec design and later run a dynamic routing protocol over the tunnel to automatically advertise reachable subnets. Which IPsec configuration approach best supports this goal?
- An OT maintenance vendor needs a permanent site-to-site IPsec tunnel into a utility's substation network so its engineers can remotely service protective relays. The vendor's edge device has a dynamic, unpredictable public IP address, while the utility's NOC FortiGate has a fixed IP. How should the NOC FortiGate be configured for phase 1?
- A utility is choosing how the NOC FortiGate will authenticate to a new substation FortiGate for a site-to-site IPsec tunnel. Compared with a pre-shared key, what is the main operational advantage of using certificate-based authentication for this pair of peers?
- A field-service technician connects to the utility's network from a truck using remote-access VPN to reach a work-order dispatch application, while all other internet traffic from the laptop should continue to go out the technician's own mobile hotspot instead of through the utility's network. Which VPN concept controls this behavior?
- A utility's NOC FortiGate has a route-based IPsec tunnel to a substation that is up and passing traffic. The security team notes that the tunnel interface alone does not restrict which hosts on the NOC side can reach which hosts on the substation side. What must still be configured for traffic to be properly controlled once it reaches the tunnel interface?
- A NOC engineer is troubleshooting a new site-to-site IPsec tunnel to a substation that never comes up at all. Checking the logs, phase 1 never completes and no security association is ever established. Which category of misconfiguration is the most likely cause?
- Phase 1 comes up cleanly between the NOC FortiGate and a substation peer, but phase 2 never establishes and no traffic passes across the tunnel. Which area should the engineer investigate first?
- A utility is designing IPsec connectivity from its NOC to twelve remote substations, and wants every substation to be able to reach every other substation directly for peer-to-peer protective relay coordination, without routing traffic through the NOC. Which IPsec VPN topology fits this requirement?
- A utility has forty substations but wants to limit the number of tunnels each substation FortiGate must maintain, while still giving the NOC central visibility and control over inter-substation traffic. Which topology trades off full mesh connectivity for that centralized control?
- The NOC's IPsec hub connects to twenty substations, and the utility wants three critical substations to keep talking to each other even if the NOC hub temporarily goes offline for maintenance, while the remaining seventeen substations can tolerate depending entirely on the hub. Which topology description matches this design?
- The utility wants an IPsec tunnel between the NOC and a substation to tear down automatically if the peer stops responding, rather than staying up as a stale, unusable security association that field technicians assume is still working. Which IPsec feature accomplishes this?
- Field technicians connecting to the utility's dispatch application over SSL VPN report that the tunnel mode client works fine, but their laptops sometimes need to reach dispatch through a plain web browser from a shared kiosk in a truck depot where no client software can be installed. Which SSL VPN access mode fits the kiosk scenario?
- A utility deploys remote-access VPN for field technicians using the FortiClient application, giving them a full virtual network adapter that lets applications behave as if the laptop is physically on the utility's internal network. Which SSL VPN access mode is being used?
- A utility security architect is reviewing remote-access VPN policy and wants field laptops to reach only the dispatch and billing subnets over the tunnel, sending all other traffic, including general internet browsing, out the laptop's own local connection. Which split tunneling configuration accomplishes this?
- A utility uses full-tunnel remote-access VPN so that all traffic from a technician's laptop, including general web browsing, is inspected by the NOC's FortiGate before reaching the internet. What operational cost does this design accept compared to split tunneling?
- A field technician's SSL VPN session repeatedly fails right after the technician enters valid credentials, while other technicians using the same portal connect successfully. The FortiGate's event log shows the authentication step succeeding, but the session tears down immediately afterward. Which layer of the problem should the engineer investigate next?
- A utility's NOC FortiGate has phase 1 configured with an 86400-second key lifetime for its tunnel to a substation, while the substation's older FortiGate still has phase 1 set to 28800 seconds. Both sides use matching encryption and authentication proposals. What is the most likely outcome?
- A substation FortiGate has two internet-facing WAN links for redundancy, and the utility wants the site-to-site IPsec tunnel to the NOC to automatically fail over to the backup WAN link if the primary link goes down, without an engineer having to reconfigure the tunnel by hand. Beyond the IPsec tunnel itself, what must also be addressed for this failover to actually work end to end?
- A NOC engineer sees an IPsec tunnel to a substation come up successfully (phase 1 and phase 2 both establish), but no traffic actually reaches hosts on the substation LAN even though the tunnel status shows as up. What is the most likely explanation to check first?
- An OT vendor's site-to-site IPsec tunnel to a substation was working for months, but after the vendor rotated their edge device's certificate, the tunnel stopped establishing phase 1 entirely. Which explanation best accounts for this specific failure pattern?
- A utility is standardizing its substation IPsec design and wants new engineers to understand why route-based tunnels are generally preferred over policy-based tunnels for sites likely to need dynamic routing, redundancy, or per-application firewall control later. What is the core structural difference that explains this preference?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.