A financial services company is deploying a FortiGate 7000 series chassis in a new datacenter to handle high-frequency trading traffic. A primary requirement is to ensure that session failover between FortiGate Interface Modules (FIMs) is deterministic and that specific high-priority traffic is always processed by a designated FIM unless it fails. The current configuration uses the default session-aware load balancing. Which configuration change is required to meet this requirement?
Answer and explanation
Correct answer: C
To achieve deterministic session handling and steer specific traffic to a designated FIM, policy-based session affinity is required. The set affinity-group command within a firewall policy allows an administrator to bind traffic matching that policy to a specific FIM, overriding the default load balancing behavior. This ensures high-priority traffic is handled by the preferred module, providing predictable performance and failover behavior.
Question 2
A network security architect is designing an ADVPN solution with two hubs in different geographical regions for redundancy. The design requires spokes to dynamically build shortcuts to other spokes, regardless of which hub they are connected to. What is a critical design consideration to ensure seamless spoke-to-spoke communication across both hubs?
Answer and explanation
Correct answer: D
In a dual-hub ADVPN setup, spokes connected to Hub A need to learn the routes for spokes connected to Hub B to trigger shortcut tunnel creation. The most effective way to achieve this is by establishing an iBGP peering between the two hubs. This allows each hub to share the routes learned from its connected spokes with the other hub, providing all spokes with a complete routing table of the entire ADVPN domain.
Question 3
A global retailer is using Fortinet Secure SD-WAN and has configured a performance SLA to monitor latency on its primary MPLS and secondary internet underlay links. The SD-WAN rule is set to prefer MPLS. During a period of network congestion, the latency on the MPLS link exceeds the configured threshold. However, an administrator observes that existing long-lived sessions, such as a large file transfer, do not fail over to the internet link. New sessions correctly use the internet link. What is the most likely reason for this behavior?
Answer and explanation
Correct answer: C
When nat is enabled on the firewall policy that handles the SD-WAN traffic, existing sessions are tied to the specific NAT IP of the outgoing interface (MPLS in this case). By default, FortiOS will not move an existing, NATed session to a new interface even if the SD-WAN rules dictate a path change. This is to prevent breaking the session, as the source IP would change mid-session. New sessions are not affected and will correctly choose the better-performing link. To allow existing sessions to fail over, set session-snat-route-change enable must be configured in the system settings.
Question 4
Multiple answers
A security team is implementing Zero Trust Network Access (ZTNA) to provide secure access to an internal web application. They have configured a ZTNA server on the FortiGate, ZTNA connection rules on FortiClient EMS, and a ZTNA policy on the FortiGate. A user reports they can connect to the ZTNA access proxy but receive a 'Permission Denied' error when trying to access the application. The FortiGate logs show the traffic is hitting the ZTNA policy and being denied. What are the two most likely causes of this issue? (Select TWO).
Answer and explanation
Correct answers: A, C
ZTNA relies on client certificates to cryptographically identify and authenticate the connecting device. If the user's FortiClient does not present a valid certificate that is trusted by the FortiGate ZTNA server, the connection will be denied at the policy level.
ZTNA policies enforce access based on both device identity (certificate) and user identity. If the authenticated user is not part of the user group authorized in the ZTNA policy's source field, the traffic will be denied, resulting in a 'Permission Denied' error.
Question 5
True or False: When configuring a FortiGate automation stitch with a FortiAnalyzer event as the trigger, the FortiGate must be configured to send logs to the FortiAnalyzer in real-time mode for the stitch to execute immediately upon event detection.
Answer and explanation
Correct answer: A
For a FortiGate automation stitch to react promptly to an event detected on FortiAnalyzer (such as a specific log pattern or IOC), the FortiGate must be configured to upload logs in real-time. If logs are sent in store-and-upload mode, there will be a delay between the event occurrence and its detection on FortiAnalyzer, which would prevent the stitch from executing in a timely manner.
Question 6
A large enterprise has deployed FortiSwitch units in a multi-chassis link aggregation (MCLAG) configuration for switch-level redundancy. An administrator needs to perform a firmware upgrade on the MCLAG peer switches with minimal disruption to network traffic. What is the recommended procedure to achieve this?
Answer and explanation
Correct answer: C
The correct, non-disruptive procedure for upgrading an MCLAG pair is to upgrade one switch at a time. The recommended practice is to first set the secondary (passive) peer to standalone mode, which isolates it from the MCLAG domain. After upgrading and rebooting the secondary switch, you can fail over traffic to it (by shutting down links on the primary or rebooting it) and then proceed with upgrading the original primary switch. This rolling upgrade process ensures that at least one switch is always active and forwarding traffic.
Question 7
Case Study:
Global Logistics Inc. (GLI) is a multinational shipping company that is modernizing its security infrastructure. They have deployed a central FortiManager and FortiAnalyzer at their primary datacenter for managing hundreds of branch office FortiGates. To improve their security posture, GLI wants to implement a solution where if a threat is detected at any branch (e.g., a malware-infected host), the compromised host is automatically quarantined across the entire organization, preventing it from accessing any network resources at any branch or the datacenter.
The current setup involves Security Fabric enabled between the branch FortiGates and the central management devices. Each branch uses FortiSwitch and FortiAP for local access, managed by the local FortiGate. The security team wants to leverage their existing Fortinet investment to achieve this automated, global quarantine without significant new hardware purchases.
As the lead security architect, you are tasked with designing this solution. The solution must be scalable and react in near real-time. Which approach best meets GLI's requirements for automated, fabric-wide threat response?
Answer and explanation
Correct answer: D
This solution leverages the existing central management infrastructure to create a scalable, automated, and fabric-wide response. FortiAnalyzer acts as the central detection point. The FortiAnalyzer-FortiManager webhook integration provides the trigger mechanism. FortiManager's automation stitch and scripting capabilities can then update a dynamic address group (like an IP list or threat feed) that is already part of a shared policy package. When this object is updated on FortiManager, the change is automatically pushed to all managed FortiGates, effectively quarantining the host across the entire organization in a synchronized and efficient manner.
Question 8
Multiple answers
A FortiGate is configured in transparent mode between an internal network and a core router. An administrator notices that traffic passing through the FortiGate is not being accelerated by the NP7 processor as expected. Which TWO of the following configurations could cause the traffic to bypass NP7 acceleration? (Select TWO).
Answer and explanation
Correct answers: A, C
Traffic shaping is a feature that requires CPU processing to manage queues and enforce bandwidth limits. When a traffic shaper is applied to a firewall policy, sessions matching that policy are sent to the CPU and cannot be offloaded to NP7 processors.
Proxy-based inspection mode requires the FortiGate to terminate and re-initiate connections to perform in-depth analysis. This process is handled by the CPU and the content processors (CPs), not the network processors (NPs). Therefore, traffic subject to proxy-based inspection cannot be offloaded to NP7.
Question 9
A systems administrator is configuring a FortiGate to act as a SAML Service Provider (SP) for SSL-VPN access, using a third-party Identity Provider (IdP). The IdP provides group membership information in a SAML attribute named memberOf. The administrator needs to map users to different SSL-VPN realms based on this attribute. Which FortiGate CLI setting is used to specify the SAML attribute that contains the user's group information?
Answer and explanation
Correct answer: C
Within the config user saml CLI context, the set group-claim parameter is used to define the name of the SAML attribute that the IdP will send to convey group membership. The FortiGate will parse the SAML assertion for this attribute (in this case, memberOf) to identify the user's groups and match them against FortiGate user groups for authorization.
Question 10
A consultant is tasked with designing a resilient email security solution using two FortiMail appliances in a high availability (HA) active-passive cluster. A key requirement is that in the event of a primary unit failure, the secondary unit must take over with minimal email service interruption and no loss of the mail queue. Which FortiMail HA mode must be configured to meet this requirement?
Answer and explanation
Correct answer: D
FortiMail's Full HA mode provides the highest level of redundancy. In this mode, both configuration and mail data (including mail queues, user data, and archives) are continuously synchronized between the primary and secondary units. If the primary unit fails, the secondary unit has an identical, up-to-date copy of all data and can take over processing immediately, ensuring no emails are lost and service interruption is minimized.
Register free for 10 more questions
Or unlock all 248 NSE8-812 questions with explanations, timed mode and flashcards.