Fortinet Certified Solution Specialist - Enterprise Firewall 7.4 Administrator Free Sample Questions

20 free sample questions204 in the full practice test Other versions: NSE7_EFW-6.2(53),NSE7-EFW-7-0(222),NSE7-EFW-7-2(203)

Try simulator

FCSS-EFW-AD-7-4 Sample Questions

  1. Question 1

    A financial services company is using FortiManager to centrally manage 50 FortiGate devices. An administrator needs to push a standardized web filtering security profile to all devices, but each device requires a unique override for a specific local regulatory website. What is the most efficient method to achieve this in FortiManager?

    Answer and explanation

    Correct answer: B

    The most efficient method is to use a single policy package for consistency and apply per-device mapping for the specific objects that need to be unique, such as the URL filter entry. This avoids the massive overhead of managing 50 separate policy packages and leverages FortiManager's dynamic object capabilities.

  2. Question 2

    Multiple answers

    An e-commerce platform uses an Auto-Discovery VPN (ADVPN) network with one hub and 20 spokes. The lead network architect wants to ensure that if the primary hub fails, ADVPN functionality remains operational with minimal downtime. Which two design choices should be implemented to achieve high availability for the ADVPN hub? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    To achieve hub redundancy in an ADVPN setup, you can either use a standard FortiGate HA cluster for the hub role, which provides device-level failover, or deploy two independent hubs and configure spokes to establish tunnels to both. The latter provides greater resiliency, including against ISP or site failure at the primary hub location.

  3. Question 3

    True or False: In a FortiGate Active-Passive HA cluster, enabling session pickup (session-pickup enable) guarantees that all active sessions, including UDP and ICMP, will be seamlessly transferred to the secondary unit upon a failover event.

    Answer and explanation

    Correct answer: B

    This statement is false. While session pickup synchronizes TCP sessions, it does not synchronize connectionless sessions like UDP and ICMP by default. These sessions will be dropped and must be re-established after a failover. For some specific protocols like SIP, session helpers can assist, but it is not a universal guarantee for all session types.

  4. Question 4

    A hospital's security team is deploying deep SSL inspection on their FortiGate. They need to exempt traffic destined for specific healthcare record services that use certificate pinning and will break if inspected. However, they must inspect all other HTTPS traffic for compliance. What is the recommended approach to configure this exclusion within the SSL Inspection profile?

    Answer and explanation

    Correct answer: B

    The correct and most direct method is to add the fully qualified domain names (FQDNs) of the problematic services to the exemption list within the SSL/SSH Inspection profile itself. This allows the firewall policy to remain simple while giving granular control over which destinations are bypassed by the deep inspection engine.

  5. Question 5

    During a security audit, an administrator discovers that a FortiGate is configured with two default routes with the same distance but different priorities. Route 1 has a priority of 10 and Route 2 has a priority of 20. Both routes are active in the routing table. How will the FortiGate handle traffic matching these routes?

    Answer and explanation

    Correct answer: B

    In FortiOS, when two static routes have the same destination and administrative distance, the route with the lower priority value is considered superior and will be installed as the active route in the routing table. The higher priority route will only be used if the lower priority route becomes inactive.

  6. Question 6

    An administrator is configuring a new VDOM named 'Guest-WiFi' on a FortiGate 1800F, which is equipped with NP7 processors. To maximize performance for the guest traffic, the administrator wants to ensure it is offloaded by the NP7 processors. Which step is essential to achieve this?

    Answer and explanation

    Correct answer: D

    On FortiGate models with multiple NP7 processors, you can dedicate specific processors to particular VDOMs. By using the config global and config system npu CLI commands to set vdom-npu-affinity, the administrator can bind the 'Guest-WiFi' VDOM to a specific NP7, ensuring its traffic is prioritized for hardware acceleration by that processor.

  7. Question 7

    A junior administrator is using the FortiManager script console to apply a configuration change to a group of FortiGate devices. The script fails with a 'permission denied' error. The administrator's account has 'Super_User' privileges on the ADOM containing the devices. What is the most likely reason for the script failure?

    Answer and explanation

    Correct answer: C

    In FortiManager, permissions are granular. Even with Super_User rights within an ADOM, the administrator's overall access profile must explicitly grant permissions for 'Script Management'. Without this specific permission, the administrator cannot create, edit, or run scripts, resulting in a 'permission denied' error.

  8. Question 8

    A manufacturing company uses a site-to-site IPsec VPN between its headquarters and a factory. Users report that the VPN tunnel disconnects every evening and does not automatically reconnect. The administrator confirms that Phase 1 and Phase 2 lifetimes are standard, and DPD (Dead Peer Detection) is enabled on both ends. What is the most likely cause for the tunnel failing to re-establish?

    Answer and explanation

    Correct answer: A

    When auto-negotiate is disabled, the FortiGate will not attempt to bring the tunnel up automatically after it goes down (for example, due to lifetime expiration). It will wait for interesting traffic to trigger the negotiation. Since the disconnection happens overnight when traffic is low, the tunnel remains down. Enabling auto-negotiate ensures the FortiGate proactively re-establishes the tunnel.

  9. Question 9

    An administrator is reviewing the logs on FortiAnalyzer and notices a large number of IPS events with the action pass from a signature designed to detect anomalous DNS queries. The security policy requires that these events are logged but not blocked, as they are part of a research project. However, the sheer volume of these logs is making it difficult to find other critical alerts. What is the best way to handle this situation without losing visibility?

    Answer and explanation

    Correct answer: C

    The best approach is to use a FortiAnalyzer event handler. An event handler can be configured to automatically process incoming logs that match specific criteria (like the IPS signature ID). It can then perform an action, such as marking the event as acknowledged or changing its severity, which effectively hides it from the default alert views without deleting the log data. This preserves visibility for forensic purposes while cleaning up the active monitoring console.

  10. Question 10

    Multiple answers

    A university has implemented multiple VDOMs on a single FortiGate to separate faculty, student, and administrative networks. The administrator needs to establish communication between the 'Faculty-VDOM' and the 'Admin-VDOM' for a specific application. Which two methods can be used to route traffic between these two VDOMs on the same FortiGate device? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    Traffic between VDOMs on the same device can be routed either virtually using an inter-VDOM link (a software or hardware-accelerated connection) or physically by connecting two ports with a cable and assigning each port to a different VDOM. The inter-VDOM link is the more common and efficient method.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 682 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon