Fortinet FCSS - Network Security 7.6 Support Engineer Free Sample Questions

20 free sample questions196 in the full practice test

Try simulator

FCSS-NST-SE-7.6 Sample Questions

  1. Question 1

    A network administrator manages an FGCP HA cluster running in Active-Passive mode on FortiOS 7.6. FGT-A has priority 200 and FGT-B has priority 100, and override is disabled on both units. FGT-A, the original primary, rebooted after a power failure and FGT-B took over. Ten minutes after FGT-A rejoined the cluster, get system ha status shows both units are in sync with healthy heartbeats, but FGT-B is still the primary. Which of the following explains this behavior?

    Answer and explanation

    Correct answer: A

    In FortiOS 7.6 FGCP, with override disabled (the default), primary selection compares connected monitored interfaces first, then HA uptime, then priority, then serial number. An HA uptime difference of more than 300 seconds decides the primary, and a less than 5-minute difference counts as a tie. A unit's HA uptime resets to zero when it restarts or a monitored interface fails. After the original primary recovers, its uptime is lower than the current primary's, so it stays secondary despite its higher priority. Enabling override would make priority be considered before uptime. Session pickup and heartbeat addressing do not affect primary selection. (FortiOS 7.6 Administration Guide: HA primary unit selection criteria.)

  2. Question 2

    A support engineer is analyzing BGP issues on a FortiGate. The BGP peering session with an ISP is established, and the FortiGate is receiving routes. However, a specific prefix, 198.51.100.0/24, learned from another iBGP peer, is not being advertised to the ISP. The configuration does not include any route maps or prefix lists that would explicitly deny this prefix. What is the most probable reason for this behavior?

    Answer and explanation

    Correct answer: B

    The BGP synchronization rule states that a BGP router should not advertise a route learned from an iBGP peer to an eBGP peer unless that route is also present in its Interior Gateway Protocol (IGP) routing table (e.g., learned via OSPF or a static route). This is a loop-prevention mechanism. Since the prefix is learned from iBGP and not being advertised to the eBGP peer (ISP), and no explicit filters are in place, synchronization being enabled is the most likely cause. Modern networks typically disable synchronization as full-mesh iBGP or route reflectors are used.

  3. Question 3

    A user is unable to authenticate to the network via an SSL VPN portal that uses an LDAP server for authentication. The support engineer runs the debug command diagnose debug application fnbamd -1 and observes the error message [fnbamd_ldap_parse_response_page:1320] a_ldap_parse_page_response-Error: 7-Authentication method not supported. What is the most likely cause of this error?

    Answer and explanation

    Correct answer: B

    The error Authentication method not supported from fnbamd during an LDAP authentication attempt typically indicates a mismatch in the authentication or bind method between the FortiGate and the LDAP server. For example, the FortiGate might be configured for Simple bind when the server requires Regular, or vice-versa. An incorrect password would result in a credentials error, and a certificate issue would cause a TLS handshake failure, not this specific message.

  4. Question 4

    True or False: In FortiOS 7.6, the diagnose sys top command can be used to identify the process ID (PID) of a specific IPsec VPN tunnel daemon to troubleshoot high CPU usage related to that tunnel.

    Answer and explanation

    Correct answer: B

    False. IPsec VPN tunnel processing is handled by the iked daemon for control plane (IKE negotiations) and the kernel (ksoftirqd) for data plane (encryption/decryption). While diagnose sys top can show high CPU usage from these processes, it does not break down the usage per individual tunnel. To troubleshoot a specific tunnel's performance, you would need to use other tools like diagnose vpn tunnel list and specific debugs, not diagnose sys top for a per-tunnel PID.

  5. Question 5

    A company has a Security Fabric with a root FortiGate 601F and a downstream FortiGate 60F, both running FortiOS 7.6. The administrator notices that the Security Rating score on the root FortiGate is not updating with data from the 60F. Connectivity between the devices is confirmed, and other Fabric features are working. Which of the following is the most likely reason for this issue?

    Answer and explanation

    Correct answer: B

    In FortiOS 7.6, to improve stability and performance on entry-level models, features like Security Rating and Topology visibility are disabled on FortiGates with 2GB of RAM or less. The FortiGate 60F falls into this category. Therefore, it will not run Security Rating checks or send results to the root FortiGate, explaining the missing data.

  6. Question 6

    A support engineer is troubleshooting a web filtering issue where access to a specific HTTPS website is unexpectedly blocked. The web filter profile is set to flow-based inspection mode. The logs show the reason for the block is Blocked by FortiGuard category. The administrator confirms the website's category is set to 'Allow' in the web filter profile. What is the most likely cause of this discrepancy?

    Answer and explanation

    Correct answer: C

    Without deep inspection, the FortiGate cannot see the HTTPS URL. For flow-based web filtering it rates the hostname from the SNI in the TLS Client Hello, or the server certificate's CN when there is no SNI. If the site is served under a hostname (for example a CDN or shared hosting name) whose FortiGuard category differs from the category the administrator checked, the session is blocked by that other category. The log's category field shows which one. If 'Rate URLs by domain and IP address' is enabled, the IP rating can also override the domain rating by weight. Checking the category in the log, adding a local rating or URL filter exemption, or using deep inspection so the full URL is rated resolves the discrepancy. (FortiOS 7.6 Administration Guide: Configuring a web filter profile; Rating options.)

  7. Question 7

    Multiple answers

    When troubleshooting a static route on a FortiGate, an administrator finds that the route is present in the routing table, but traffic is not being forwarded correctly. Which TWO of the following CLI commands are most effective for diagnosing why the next-hop gateway might be considered unreachable by the FortiGate? (Select TWO).

    Answer and explanation

    Correct answers: B, D

    If a static route is in the routing table but traffic is not forwarded, check whether the next hop is actually reachable at Layer 2 and Layer 3. diagnose ip arp list shows whether the FortiGate has resolved the gateway's MAC address; an incomplete or missing entry points to a Layer 2 or addressing problem. execute ping tests Layer 3 reachability of the gateway directly. get router info routing-table all only confirms what is already known (the route is present). get system performance status shows resource usage, and diagnose debug flow traces a packet's policy and route decisions rather than gateway reachability.

  8. Question 8

    An administrator has configured an automation stitch to block a source IP address using a CLI script when a high-severity IPS event is detected. The stitch is not working as expected. To troubleshoot, the administrator wants to view a history of all automation stitches that have been triggered and their execution status (success or failure). Which command should be used?

    Answer and explanation

    Correct answer: D

    diagnose test application autod 3 displays statistics for all automation stitches: how many times each stitch was triggered (local hit), the last trigger time, and each action's done/drop counters. It shows which stitches ran and whether their actions succeeded or failed. diagnose automation stitch-history, diagnose automation stitch-trace and diagnose sys csf-log aren't FortiOS commands, and get system automation stitch doesn't show execution history. Reference: FortiOS 7.6 Administration Guide, Diagnosing automation stitches.

  9. Question 9

    A financial services company is using FortiGate for perimeter security. They have an IPsec VPN tunnel to a business partner. The tunnel is established, but the company's internal monitoring system reports that the tunnel flaps (goes down and comes back up) approximately every 5 minutes. Both sides have confirmed that their Phase 1 and Phase 2 proposals match perfectly. What is the most likely cause of this periodic flapping?

    Answer and explanation

    Correct answer: B

    When Dead Peer Detection (DPD) is configured as 'On Idle' on one FortiGate, it will only send DPD probes when there is no outbound traffic to send. If the other side has DPD disabled, it will not respond to these probes. After a few failed probes, the 'On Idle' FortiGate will tear down the tunnel, assuming the peer is dead. If there is periodic keep-alive or monitoring traffic, the tunnel will re-establish, creating a flapping cycle. A DPD timer mismatch would not typically cause this issue, and Phase 2 lifetime expiry would be on a much longer interval (usually hours).

  10. Question 10

    A FortiGate is configured with two OSPF neighbors over a point-to-point link. The administrator notices that the OSPF adjacency is stuck in the ExStart state. What is the most common reason for OSPF getting stuck in this state?

    Answer and explanation

    Correct answer: B

    The ExStart state is where OSPF routers decide which router will be the master for exchanging Database Descriptor (DBD) packets. If the routers have different interface MTU values, the larger DBD packets from the router with the higher MTU will be dropped by the router with the lower MTU. This prevents the DBD exchange from completing, causing the adjacency to be stuck in ExStart. Timer mismatches would prevent the state from even reaching 2-Way, and area ID or authentication mismatches would also cause earlier failures.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 196 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon