5.0 Administrator Free Sample Questions

Covers sandbox deployment models and high availability, scanning engine architecture and guest VM management, Security Fabric and API integration, and MITRE ATT&CK-based reporting.

20 free sample questions185 in the full practice test

Try simulator

FORTISANDBOX Sample Questions

  1. Question 1

    A financial services company is experiencing performance degradation on their FortiSandbox 2000F appliance after enabling analysis for a new branch office, which significantly increased the volume of submitted Microsoft Office documents. The job queue is consistently high, and analysis times have tripled. The administrator has already confirmed that the hardware is not bottlenecked. Which configuration change would most effectively alleviate the high job queue and improve processing throughput for this specific file type?

    Answer and explanation

    Correct answer: B

    Enabling 'Static Scan Only' for trusted or high-volume file types like Microsoft Office documents leverages the high-speed static AI engine, which can process files much faster than dynamic VM analysis. This significantly reduces the load on the VM resources and clears the job queue more efficiently without completely bypassing analysis. Increasing concurrent VMs would help but could lead to resource contention and doesn't address the root cause as effectively as offloading to the faster static scan engine.

  2. Question 2

    Multiple answers

    A security analyst is investigating a malware sample that successfully exfiltrated data. The FortiSandbox report provides a detailed breakdown of the malware's behavior, which is mapped to the MITRE ATT&CK framework. The report notes the following key actions:

    1. The malware created a new service to run at startup.
    2. The malware connected to a command-and-control server over port 443.
    3. The malware captured screenshots of the user's desktop.

    Which MITRE ATT&CK tactics are directly represented by these three actions? (Select THREE)

    Answer and explanation

    Correct answers: A, B, D

    Creating a new service to run at startup is a classic example of the Persistence tactic (T1543.003 - Create or Modify System Process: Windows Service), allowing the malware to survive reboots.

    Connecting to a C2 server over a common port like 443 is a core behavior of the Command and Control tactic (T1071 - Application Layer Protocol), used to receive instructions and exfiltrate data.

    Capturing screenshots (T1113 - Screen Capture) is a method used to gather information from the victim's system, which falls under the Collection tactic.

  3. Question 3

    During the initial setup of a FortiSandbox appliance, an administrator configures the network interfaces, system time, and DNS settings. However, the appliance is unable to download updated guest VM images from the FortiGuard Distribution Network (FDN). The administrator has verified that the appliance has a valid license and can ping public IP addresses. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: D

    Even if the administrator has configured the system time, if it is significantly out of sync with the actual time, SSL certificate validation will fail when the FortiSandbox attempts to connect to the FDN over HTTPS. This is a common and often overlooked issue. Since the device can ping public IPs, basic network connectivity is confirmed, pointing towards a higher-level protocol issue like SSL/TLS.

  4. Question 4

    A security architect is designing an integration between a third-party Security Orchestration, Automation, and Response (SOAR) platform and FortiSandbox. The goal is for the SOAR platform to programmatically submit suspicious files, check the analysis status, and retrieve the full PDF report upon completion. Which sequence of API calls is required to accomplish this workflow?

    Answer and explanation

    Correct answer: C

    The correct workflow is: First, upload the file using a POST request to the /scan/upload/file endpoint, which returns a job_id. Second, periodically poll the /scan/result/job/{job_id} endpoint to check the analysis status until it is complete. Once complete, the result will contain the file's SHA256 hash. Third, use the SHA256 hash to retrieve the final PDF report with a GET request to /scan/report/pdf/{sha256}.

  5. Question 5

    True or False: In a FortiSandbox High Availability (HA) cluster, the primary unit handles all file analysis, while the secondary unit only synchronizes configuration and remains in a passive state until a failover event.

    Answer and explanation

    Correct answer: A

    This statement is true. FortiSandbox HA operates in an active-passive mode. The primary (master) unit is responsible for all network traffic, file submissions, and analysis. The secondary (slave) unit receives configuration and state synchronization data from the primary but does not perform any analysis tasks itself until it takes over as the primary during a failover.

  6. Question 6

    A multinational corporation has deployed FortiSandbox in their central datacenter. They need to analyze malware targeting different regional offices, which use localized versions of Windows. Some malware samples are known to check for specific language packs or regional settings before executing their malicious payload. How can an administrator configure FortiSandbox to effectively analyze these region-specific threats?

    Answer and explanation

    Correct answer: B

    To combat malware that uses geo-fencing or checks for specific system locales as an anti-evasion technique, the most effective method is to create customized guest VM images. Administrators can build a Windows VM, install the required language packs and regional settings to mimic the target environment, and then upload this custom VHD file to the FortiSandbox for use in dynamic analysis.

  7. Question 7

    An administrator is configuring a FortiGate to send files to FortiSandbox for inspection. They want to ensure that if FortiSandbox is busy or offline, the FortiGate will still allow the file to be downloaded by the user after a timeout, rather than blocking it indefinitely. Which setting on the FortiGate's AntiVirus profile achieves this behavior?

    Answer and explanation

    Correct answer: C

    The fail-open setting, configured via the FortiGate CLI within the antivirus settings, dictates the behavior when a connection to the FortiSandbox cannot be established or a verdict is not returned in time. Enabling fail-open instructs the FortiGate to permit the traffic, representing a 'fail-open' stance. Disabling it would cause the FortiGate to block the traffic, a 'fail-close' stance.

  8. Question 8

    A healthcare organization is required by compliance regulations to store all malware analysis data, including detailed reports and tracer logs, for a minimum of seven years. The organization's FortiSandbox 1000F has limited onboard storage. Which solution allows the organization to meet this long-term retention requirement while integrating with their existing infrastructure?

    Answer and explanation

    Correct answer: B

    FortiAnalyzer is the designated Fortinet solution for centralized logging, analytics, and long-term data retention. By integrating FortiSandbox with FortiAnalyzer, all analysis logs and reports can be sent to the FortiAnalyzer, which can be equipped with large storage arrays. The administrator can then configure data retention policies on the FortiAnalyzer to meet the seven-year compliance requirement.

  9. Question 9

    What is the primary function of the 'Tracer Engine' within the FortiSandbox dynamic analysis environment?

    Answer and explanation

    Correct answer: B

    The Tracer Engine is the core component of dynamic analysis. It hooks into the guest VM's operating system to monitor and record all actions taken by the executed file, such as file system modifications, registry changes, network connections, and process creation. This detailed activity log, known as the tracer log, is then analyzed by the rating engine to determine if the behavior is malicious.

  10. Question 10

    A system administrator is reviewing the scan results for a submitted file and notices the verdict is 'Benign', but the report indicates several suspicious behaviors were detected, such as modifying system files and attempting to disable security software. What is the most likely reason for this discrepancy?

    Answer and explanation

    Correct answer: C

    FortiSandbox's rating engine processes multiple inputs. Even if the behavioral analysis engine flags suspicious activities, a match on a whitelist (either the global FortiGuard whitelist or a locally configured one) will override the behavioral score and force a 'Benign' verdict. This is a common scenario for legitimate software installers or system administration tools that perform actions similar to malware.