Firewall Policies and Authentication
FCP-FGT-AD-7-6 · 47 questions
- A utility NOC engineer creates a firewall policy permitting field-service laptops on the Field-VPN interface to reach the outage-management server on Corp-LAN over HTTPS, with a schedule object scoped to weekday business hours. A field technician reports the connection is refused when working an after-hours storm restoration call, even though the technician's laptop, destination address, and service all match the policy exactly. Why is the policy not matching this after-hours session?
- The security team at a regional utility adds a new, tightly scoped policy allowing only maintenance traffic from a single substation RTU host to a specific historian server, but places it below an existing broad policy that already permits all substation-to-corporate traffic on the same interface pair. After activation, traffic still matches the broad policy instead of the new narrow one. What is the correct explanation for this behavior in FortiOS 7.6?
- A utility's field-operations network includes three subnets used by different crew types: overhead-line trucks, substation maintenance vans, and metering technicians. The security engineer wants every crew subnet to share one identical firewall policy permitting access to the work-order dispatch server, and wants to add or remove a crew subnet later without editing the policy itself. Which approach best achieves this in FortiOS 7.6?
- A third-party protection-relay vendor provides remote support to a substation device from a cloud-hosted jump host whose public IP address changes periodically because the vendor uses a dynamic-DNS provider. The utility wants a firewall policy that keeps working automatically as the vendor's IP changes, without a scheduled task to update the policy. Which address-object type is designed for this in FortiOS 7.6?
- A work-order dispatch application at a utility's back-office site listens on TCP port 8443 instead of the standard HTTPS port, and no built-in FortiOS service object matches it. A field crew's laptops need a policy that permits only that exact application traffic, nothing broader. What should the engineer configure to match this traffic precisely?
- A field crew's laptops need to reach the work-order dispatch server over three separate custom TCP services the application uses for data sync, file transfer, and status polling. The security engineer wants a single firewall policy line, and wants to add a fourth service later without touching the policy. What should the service field reference?
- A utility schedules a one-night cutover maintenance window during which a vendor's support laptop needs firewall access to a substation relay that is normally blocked. The change window is a single calendar date and time range, never to repeat. Which FortiOS schedule object type fits this requirement, as opposed to the type normally used for standing business-hours access?
- A newly deployed FortiGate at a small substation has exactly one explicit firewall policy configured, permitting the local RTU to reach the NOC historian server over one specific service. A different device on the same substation subnet, not covered by that policy, attempts to reach an unrelated corporate server. What happens to that second device's traffic?
- A security auditor at the utility wants visibility into every connection attempt that field devices make toward the corporate back-office network that isn't explicitly permitted by any policy, to spot reconnaissance or misconfigured devices. Reviewing the FortiGate's traffic logs, the auditor finds no entries at all for denied sessions, even though explicit policies are correctly logging their own traffic. What is the most likely reason?
- A utility's SOC wants full session-level visibility into traffic between the corporate billing network and the field-operations network, including successful, uneventful sessions with no security profile hits, for a compliance audit trail. An engineer reviews an existing policy and finds its logging option set to log security events only. What does the engineer need to change to meet the SOC's requirement?
- A network engineer notices that a high-volume policy carrying routine telemetry between two internal utility segments has its logging option set to disable logging entirely, to keep log storage manageable. During a later incident investigation, the SOC needs to reconstruct exactly which internal hosts communicated across that policy during a specific hour, but the traffic log has no relevant entries. What is the best explanation, and the trade-off it represents?
- Field-service laptops on a utility's Field-VPN segment need outbound access to a cloud-hosted mapping service, but the utility wants those laptops to appear on the internet as the FortiGate's public WAN interface address rather than their internal private addresses. Which policy-level setting accomplishes this in a standard, non-central-NAT firewall policy?
- A utility is redesigning its NAT strategy across dozens of firewall policies that each need slightly different source-NAT behavior for field, substation, and back-office traffic. The network architect wants NAT rules managed as their own centralized rule set, separate from and independently ordered from the firewall policies that permit the traffic. Which FortiOS 7.6 NAT model matches this requirement, as opposed to configuring NAT directly on each firewall policy?
- A utility's back-office network has far more internal hosts needing outbound internet access than it has spare public IP addresses. The network engineer wants many internal hosts to share a small handful of public addresses simultaneously, distinguishing their sessions by source port rather than by a dedicated address per host. Which FortiOS IP pool type is designed for this?
- A substation's data-historian gateway needs a stable, individually identifiable public IP address for every outbound session it initiates, because a downstream cloud analytics partner allowlists connections by source IP and expects exactly one gateway per address, never a shared one. Which IP pool type fits this requirement?
- A utility shares one small overload IP pool across many back-office hosts for outbound access, and the SOC needs to trace a suspicious outbound connection reported by the analytics partner back to the specific internal host that generated it, using only the shared external address and port at the time of the connection. Which IP pool feature makes this kind of per-host attribution practical at scale?
- A vendor's field-diagnostic application on a utility crew's laptop requires that its outbound source port never change across the life of a session, because the receiving cloud service correlates requests by the exact source port the client first used. The laptop's traffic already passes through an overload IP pool shared with other crew laptops. What NAT adjustment addresses the application's requirement, and what does it cost?
- A utility exposes a substation's engineering-access web console to a small set of external vendor IP addresses for remote diagnostics, without giving the vendor a route into the substation's internal address space directly. External requests arrive at one of the FortiGate's public WAN addresses and must be redirected to the console's actual private address behind the firewall. Which FortiOS construct is designed to perform this kind of external-to-internal address translation for inbound traffic?
- A utility wants external vendor access to a substation console's management interface, which listens only on internal TCP port 8080, but wants vendors to connect using the more familiar external port 443 on the FortiGate's public address, rather than remembering a nonstandard port. Which VIP configuration accomplishes translating both the address and the port in a single object?
- A network engineer configures a virtual IP mapping a public WAN address to a substation console's private address, expecting that creating the VIP object alone is enough to let the vendor's traffic reach the console. After saving the VIP, vendor connection attempts still fail with no matching traffic appearing in any explicit policy's log. What additional step does FortiOS require before this VIP actually forwards traffic?
- After a utility redesigns its WAN routing so that return traffic from the corporate billing network to a field crew's VPN session now takes a different path back through a second FortiGate interface than the path the session originally went out on, the crew's application connections begin silently failing partway through. What FortiOS mechanism explains why asymmetric routing like this breaks stateful sessions?
- A utility engineer tightens a firewall policy to block a category of traffic between the field network and the corporate billing network that used to be allowed, expecting the change to take effect immediately. Several existing field-device sessions that were already open before the change continue passing traffic for some time afterward, even though the same traffic is now correctly blocked for brand-new connection attempts. Why do the existing sessions keep working after the policy change?
- A utility engineer finds that outbound sessions from the field-crew subnet are being denied, even though a central SNAT policy exists that matches the subnet and specifies the correct overload pool. Reordering the central SNAT policy list makes no difference to the denies. What does this indicate about how central SNAT relates to the firewall policy's accept-or-deny decision?
- A utility configures a VIP so an internal back-office subnet can reach a substation console using the substation's public-facing address, even though both networks sit behind the same FortiGate, a hairpin scenario where the traffic enters and exits through interfaces the firewall must handle carefully. The VIP and an appropriate inbound policy are both configured, but internal back-office hosts still cannot reach the console this way, while genuinely external vendor traffic to the same VIP works correctly. What is a likely missing piece specific to this internal hairpin case?
- A regional utility's NOC wants engineers to prove their identity before a firewall policy allows them onto the internet from the control-center LAN, rather than just letting any device on that subnet browse freely. What does adding firewall authentication to that policy actually change?
- A utility's control-center FortiGate needs firewall-authenticated access for only three short-term contractors doing a one-week substation audit, with no existing directory service reachable from that segment. Which authentication approach best fits this situation?
- A utility's NOC configures a FortiGate to authenticate field technicians against a central RADIUS server before granting VPN access into the substation network. What must the FortiGate and the RADIUS server share for this authentication exchange to succeed?
- A utility wants its FortiGate to authenticate corporate back-office staff against the existing Active Directory service used for billing and dispatch systems, without creating separate accounts. Which concept describes how the FortiGate locates and reads a user's entry in that directory during LDAP authentication?
- A utility's FortiGate has two firewall policies for the same source subnet: one referencing a 'Substation-Vendors' user group with limited access, and one referencing a 'NOC-Engineers' user group with broader access. A vendor logs in but was never added to either group. What happens to their traffic?
- A field contractor working on billing-system integration was mistakenly added to the utility's 'Substation-Vendors' group instead of the 'Back-Office-Contractors' group. What is the most direct consequence for that contractor's firewall-authenticated sessions?
- A utility's security team is documenting authentication methods for their FortiGate deployment and needs to distinguish active from passive authentication. Which statement correctly describes that distinction?
- Visitors to a utility's control-center building connect to a guest wireless network and are shown a branded web page requiring them to accept an acceptable-use disclaimer before internet access is granted. Which authentication mechanism is this?
- A NOC operator logs into their domain-joined workstation each morning and, without ever seeing a login prompt on the FortiGate, is immediately granted the access their user group is entitled to when browsing out to vendor documentation sites. Which authentication approach produces this experience?
- A utility wants its guest wireless captive portal to display a legal disclaimer and require a checkbox acceptance, but explicitly does not want to issue individual guest usernames and passwords. Is this achievable with a FortiGate captive portal?
- A utility deploys FSSO so that corporate back-office staff are transparently identified when their domain-joined workstations generate traffic through the FortiGate. Conceptually, how does the FortiGate typically learn which username is associated with a given workstation's IP address in this deployment?
- A contractor brings a personal, non-domain-joined laptop onto the utility's corporate network segment where FSSO is used to identify back-office staff. What happens to that contractor's identity from the FortiGate's perspective?
- A utility wants to strengthen authentication for a small set of high-privilege NOC accounts by requiring something beyond just a password. What does adding two-factor authentication accomplish?
- A vendor technician remotely connects over VPN to perform scheduled substation maintenance. The utility requires the vendor to supply both a password and a push-approved code from a mobile authenticator app before the session is established. What security property does this combination primarily provide compared to password-only VPN access?
- A utility issues a temporary local user account on the FortiGate for a two-day facility inspection by an outside auditor, with the account set to expire automatically at the end of the visit. What is the main operational benefit of using an expiring guest-style account here rather than a standard, permanent local account?
- A utility distinguishes between a 'Guest' access tier for unmanaged, walk-in visitors and a 'Contractor' group for vetted third parties with an ongoing work order. Why does this distinction matter for how firewall policies are written?
- A utility is evaluating certificate-based user authentication as an alternative to password-based login for a set of engineering laptops accessing the control-center network. Conceptually, what does this approach rely on instead of a shared password?
- A vendor's laptop presents a client certificate during an authentication attempt to the utility's FortiGate, but the certificate was issued by a certificate authority the FortiGate does not trust. What is the most likely outcome?
- A NOC operator authenticates once in the morning and then steps away from their workstation for an extended lunch, leaving the session idle. Why would the utility configure an authentication timeout on that firewall policy?
- A utility's FortiGate is configured to authenticate NOC staff against a RADIUS server first, with a local user group configured as a fallback. During a network outage, the RADIUS server becomes unreachable. What should happen for a NOC operator attempting to authenticate during the outage, assuming their account also exists locally?
- A utility's firewall policy references a user group called 'NOC-Engineers' rather than listing each engineer's individual username. What operational advantage does referencing the group provide over listing individuals directly in the policy?
- A utility configures LDAP authentication so that the FortiGate not only verifies a back-office employee's password against the corporate directory, but also checks which LDAP group the employee belongs to, in order to decide which firewall policy applies. What is this second check, beyond password verification, generally called?
- A utility offers NOC operators a choice between a FortiToken Mobile push notification they approve with a tap, or manually typing a rotating numeric code from the same app, as their second authentication factor. What is the key practical difference between these two options?