Deployment and System Configuration
FCP-FGT-AD-7-6 · 47 questions
- A regional electric utility is placing a new FortiGate at the edge of its grid-operations control-center network. The device must route between internal subnets, act as the default gateway for utility servers, and translate addresses for outbound traffic to remote substations. Which operating mode should the deployment team configure on the FortiGate?
- A substation has protection-relay traffic and status-monitoring traffic arriving over a single physical uplink cable to the FortiGate, and the utility's network team wants each traffic type on its own logical interface so separate firewall policies and IP subnets can apply, without running additional cabling. Which interface type should they create on top of the existing physical port?
- Field-service technicians bring laptops to a switching station and connect to a dedicated FortiGate interface for temporary network access. The utility wants those laptops to automatically receive an IP address, default gateway, and DNS server from the FortiGate itself, with no separate server on site. What should the network team configure on that interface?
- The grid-operations NOC's security team is hardening the FortiGate interface that faces the wide-area link to remote substations. They want administrators to still be able to reach the interface for management, but only over encrypted protocols, with legacy plaintext management protocols disabled. Which administrative access combination best fits that goal?
- A junior operator has just joined the grid-operations NOC team and needs to log in to the FortiGate to view interface status and generate reports, but should not be able to modify firewall policies or system settings. What is the correct way to provision this operator's account?
- The utility's security policy states that a particular administrator account should only ever be able to log in to the FortiGate from workstations inside the NOC's management subnet, even if the correct password is entered from anywhere else. Which FortiGate feature enforces this on the account itself?
- The utility is deploying two identical FortiGates as a redundant pair protecting the control-center perimeter, and wants both units to be capable of actively forwarding traffic at the same time to make use of both units' processing capacity, rather than leaving one unit completely idle until a failure occurs. Which FGCP cluster mode meets this requirement?
- A utility is inserting a FortiGate into an existing back-office network between the core switch and the billing servers, but the network team has been told they cannot renumber any device or change the default gateway on the billing servers during the migration window. Which operating mode lets the FortiGate be added inline for inspection without changing any existing IP addressing?
- The link between the NOC's core switch and the perimeter FortiGate is becoming a bandwidth bottleneck, and the utility also wants the connection to survive the failure of a single cable or switch port without an outage. Two additional physical ports are available on both devices. What should the network team configure to meet both goals?
- The utility's internet service provider assigns the FortiGate's WAN interface a public IP address automatically and can change that address at any time, rather than allowing the utility to fix a permanent address on that link. How should the network team configure IP addressing on that WAN interface?
- The utility's internet-facing FortiGate interface must remain reachable for basic connectivity testing by the ISP's monitoring system, but the security team wants to prevent that interface from responding to any request that could be used to log in or make configuration changes. Which administrative access setting best achieves this on the internet-facing interface?
- After a phishing attempt targeted several NOC staff, the utility's CISO wants FortiGate administrator logins to require something beyond just a correct password before granting access, so a stolen password alone is not enough to log in. Which account-level feature should the team enable to meet this requirement?
- The utility's SOC notices a burst of failed login attempts against a NOC administrator account, all originating from inside the account's already-permitted management subnet and consistent with an automated password-guessing attempt. Trusted hosts already restrict the account to that subnet, and the attempts are still failing on the password itself. Which account-level control most directly slows or stops this kind of repeated-guessing attempt?
- In the utility's FGCP cluster protecting the control-center perimeter, the two FortiGate units continuously exchange configuration synchronization and status information over a link dedicated to that purpose, separate from the interfaces carrying substation and back-office traffic. What is this dedicated link used for?
- A utility network engineer initially deployed a FortiGate in transparent mode to bridge two segments of the back-office network, but now needs the unit to also perform source NAT for outbound traffic and to route between several newly added subnets. What must the engineer do to support this new requirement?
- A small utility back-office closet has four physical FortiGate ports connected to four unmanaged switches serving printers and workstations that all belong to the same trust level, and the network team wants these four ports to behave as one interface without needing a firewall policy between them, while still preserving other physical ports for zone separation elsewhere. What should they configure?
- The utility has three separate substation uplink interfaces on the FortiGate, and the security team wants to write one set of firewall policies that treats all three as a single named group of interfaces for policy matching, rather than writing three nearly identical policies for each individual interface. Which FortiGate construct is designed for grouping interfaces this way for policy purposes?
- The utility centralizes its DHCP server at the NOC, but a remote substation's device segment sits on the far side of a FortiGate interface and cannot reach that central server with its normal broadcast-based DHCP requests. The utility does not want to deploy a local DHCP server at the substation. What should be configured on the substation-facing interface?
- An automation team at the NOC uses scripted CLI sessions to push configuration changes to the FortiGate on its internal management interface, and never uses the web GUI on that interface. The security team wants to reduce the interface's attack surface to only what the automation actually uses. Which change accomplishes that?
- During a security assessment, the utility discovers that every technician on the NOC team logs in to the FortiGate using one shared superadmin account, since it was the only account created at deployment time. What is the main problem with continuing this practice, and what should replace it?
- A field technician, working temporarily from a hotel network while traveling, tries to log in to the FortiGate using their personal administrator account and the correct password, but the login is rejected. The account's trusted hosts are configured to only the NOC management subnet. What is the most likely reason the login failed?
- In the utility's FGCP cluster, the primary unit has a monitored WAN interface configured for link health monitoring. That specific physical link to the ISP goes down, while every other interface on the primary unit remains healthy. What is the expected FGCP behavior?
- A network engineer bundles two physical ports on the FortiGate with two ports on the NOC's core switch into an aggregate interface, but after cabling both links the interface still shows only one member port as active and traffic never balances across both. What is the most likely cause?
- In the utility's FGCP cluster, the original primary unit fails and the secondary unit takes over as primary. A few hours later, the original unit is repaired and rejoins the cluster with its higher configured priority restored. The utility wants the cluster to keep the current secondary-turned-primary unit in charge, rather than automatically switching primary roles back the moment the repaired unit returns. What HA setting controls this behavior?
- The grid-operations NOC wants every substation FortiGate to automatically pull the newest antivirus and IPS signature packages from Fortinet on a recurring schedule, without an engineer manually loading files onto each device. Which FortiGuard capability accomplishes this?
- A substation FortiGate's IPS and application-control signature packages stopped updating even though the unit has internet reachability to FortiGuard. What is the most likely cause the NOC should check first?
- Before scheduling a firmware upgrade on an unstaffed substation FortiGate, an engineer needs to confirm the device won't be pushed to a version it can't safely reach in a single jump. What should the engineer consult?
- Before applying a batch of policy and interface changes to a remote switching-station FortiGate, an engineer wants a safety net that lets them undo everything in minutes if the change goes wrong. What should they do first?
- A compliance auditor asks the NOC to confirm that configuration backups for control-center FortiGates cannot be read by anyone who happens to find the exported file on a USB drive left in a drawer. What should the NOC verify is enabled on those backups?
- A grid-operations security team wants six months of firewall log history available for a post-incident investigation, but the substation FortiGate has limited local disk space. Which logging approach best fits this requirement?
- A NOC analyst configures a substation FortiGate to send log entries to a central syslog server, but wants routine allowed-traffic events excluded so the server only receives security-relevant activity. What should the analyst adjust?
- The NOC's network monitoring platform needs to poll a substation FortiGate's CPU, memory, and interface counters every few minutes without being able to change any configuration on the device. Which feature fits this requirement?
- In addition to periodic polling, the NOC wants a substation FortiGate to proactively notify the monitoring platform the moment an interface goes down, rather than waiting for the next scheduled poll. What SNMP mechanism supports this?
- A regional utility runs both its grid-operations network and a physically separate corporate back-office network through the same physical FortiGate appliance at the control center, and wants each network's firewall configuration and routing table to be fully independent of the other. What FortiOS feature is designed for this?
- An engineer enabling the Security Fabric on a control-center FortiGate that has multiple VDOMs configured needs to decide which VDOM should host the fabric root role. What consideration should guide that decision?
- A NOC director wants a single consolidated view showing how the control-center FortiGate, downstream FortiGates at major substations, and their connected Fortinet devices relate to one another, along with an overall security posture score. What Fortinet capability provides this?
- In a Fortinet Security Fabric spanning the control-center FortiGate and several substation FortiGates, what role does the control-center device play as the fabric root?
- Before upgrading firmware on a switching-station FortiGate, an engineer wants to know whether any features currently in use will behave differently or be deprecated in the target version. Where should the engineer look?
- After successfully completing a change window on a substation FortiGate, an engineer wants to make sure the newly applied configuration itself is captured as a recovery point, not just the pre-change state. What should the engineer do once the change is confirmed stable?
- A substation FortiGate is configured to log only to its own local disk, with no external log destination. What operational risk does this configuration carry that is specific to a remote, unstaffed site?
- A NOC engineer notices that a substation FortiGate's hardware failed and needs an RMA replacement, and separately wonders whether that failure affects the unit's FortiGuard content subscription. What is the correct relationship between hardware support (RMA) entitlement and FortiGuard content subscription entitlement?
- An engineer is about to push a firmware upgrade to a remote switching-station FortiGate over a slow WAN link. Which precaution most directly reduces the risk of an unrecoverable outage if the upgrade fails partway through?
- A utility places its field-crew VPN termination in one VDOM and its corporate billing network in a separate VDOM on the same physical FortiGate. If a field-crew VPN policy is misconfigured, what is the expected effect on the corporate billing VDOM's firewall policies?
- The NOC wants the Security Fabric to be aware of resources beyond just other FortiGate devices, for example, information from a connected third-party or Fortinet ecosystem service that enriches the fabric's visibility. What general mechanism supports this kind of integration?
- A field engineer reports that a substation FortiGate can browse general internet sites fine but is failing to retrieve FortiGuard signature updates, and initially assumes a network outage. What check would most quickly distinguish a licensing problem from an actual connectivity problem?
- A NOC security reviewer flags that a substation FortiGate is using SNMPv1 community strings for monitoring and recommends moving to SNMPv3. What is the main security improvement SNMPv3 provides over SNMPv1/v2c community strings?
- Immediately after a firmware upgrade completes on a remote substation FortiGate, what is the most important verification step before considering the maintenance window closed?