Fortinet Certified Expert (FCX) - Cybersecurity Free Sample Questions

20 free sample questions216 in the full practice test

Try simulator

NSE8 Sample Questions

  1. Question 1

    A financial services company is deploying a FortiGate HA cluster in active-passive mode between two data centers using a stretched VLAN for the HA heartbeat. During a network event, administrators observe that both FortiGates temporarily become master, creating a split-brain scenario. Which FortiOS HA setting is specifically designed to mitigate this condition by allowing a master to shut down monitored interfaces on the secondary unit if it fails to receive heartbeats?

    Answer and explanation

    Correct answer: B

    The set link-failed-signal enable command is specifically designed to prevent split-brain scenarios in HA clusters, particularly those with remote links. When enabled on the master unit, if it stops receiving heartbeats from the slave, it sends a link-failed signal. This signal instructs the slave unit to shut down its monitored interfaces, preventing it from incorrectly taking over the master role and causing a network outage.

  2. Question 2

    An architect is designing a secure SD-WAN solution for a retail company with 200 branches. Each branch has one MPLS link and one broadband internet link. The primary requirement is that real-time Point of Sale (POS) traffic must always be sent over both links simultaneously to ensure zero packet loss, even if one link experiences intermittent degradation. All other traffic should fail over based on link quality. Which SD-WAN feature must be configured to meet the requirement for the POS traffic?

    Answer and explanation

    Correct answer: B

    Forward Error Correction (FEC) is the feature designed for this exact use case. It sends redundant packets (either always or based on packet loss) over a secondary link to reconstruct any lost packets on the primary link. For the most critical traffic like POS, setting the FEC to 'always' ensures packet duplication, providing the highest level of resiliency against packet loss.

  3. Question 3

    Multiple answers

    A security engineer has created an automation stitch to block suspicious source IPs that trigger a specific IPS signature. The stitch is configured with a trigger for 'IPS Signature' and an action to add the source IP to an address group used in a deny policy. However, the stitch is not working as expected. During troubleshooting, the engineer observes that the trigger event is generated correctly in the logs. Which TWO of the following configuration issues could be the cause of the failure? (Select TWO).

    Answer and explanation

    Correct answers: A, D

  4. Question 4

    True or False: When configuring BGP route redistribution into OSPF on a FortiGate, the redistribute bgp command under router ospf is sufficient to advertise BGP routes to OSPF neighbors without any additional route maps or filters.

    Answer and explanation

    Correct answer: A

    True. Unlike some other vendors that require a route-map for redistribution even if no filtering is intended, FortiOS allows the simple redistribute bgp command to advertise all learned BGP routes into OSPF. Route maps are optional and are only required if you need to filter or modify the attributes of the routes being redistributed.

  5. Question 5

    A systems administrator is configuring a FortiGate to act as a SAML Service Provider (SP) for administrative access. The Identity Provider (IdP) is a third-party service. After configuring the SAML settings, authentication fails. The SAML debug output indicates a SubjectNotOnOrAfter error. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: D

    The SubjectNotOnOrAfter condition in a SAML assertion defines the expiration time for the assertion's validity. If the Service Provider's (FortiGate's) clock is ahead of the Identity Provider's clock, it may evaluate the assertion as already expired upon receipt. This is a classic symptom of a clock skew or NTP synchronization issue between the two systems.

  6. Question 6

    An organization uses FortiClient EMS to manage endpoints and enforce compliance. The security team wants to implement a Zero Trust Network Access (ZTNA) policy where only endpoints with an active FortiClient, a specific software version installed, and a high security posture tag can access internal applications. Which component is responsible for collecting the endpoint posture information and assigning the relevant ZTNA tags?

    Answer and explanation

    Correct answer: C

    FortiClient EMS (Endpoint Management Server) is the central management component that communicates with FortiClient on the endpoints. It is responsible for defining compliance rules, collecting posture information (like software versions and security status), and dynamically assigning ZTNA tags to endpoints based on whether they meet the defined criteria. The FortiGate then uses these tags in its ZTNA policies.

  7. Question 7

    A large enterprise has deployed FortiGate 7000 series chassis in their data centers. A network architect needs to explain the data path for traffic that can be fully offloaded by the NP7 processors. Which option correctly describes the 'fast path' for a TCP session through the chassis?

    Answer and explanation

    Correct answer: B

    In a FortiGate 7000 series chassis, fully offloaded traffic follows the 'fast path'. The packet enters through an ingress FortiGate Interface Module (FIM), travels across the high-speed fabric backplane directly to a FortiGate Processor Module (FPM) containing an NP7 processor. The NP7 handles all session processing, including firewall policy, NAT, and inspection, and then sends the packet back across the backplane to the egress FIM. The main FortiGate CPU is not involved in per-packet processing for these offloaded sessions.

  8. Question 8

    An engineer is using the FortiGate REST API to automate the creation of firewall address objects. The following Python code snippet is used to send the request. Assuming the API key and FortiGate IP are correct, what must be added to the request headers for it to be accepted by the FortiGate?

    import requests
    
    api_key = 'your_api_key'
    fg_ip = '10.0.1.1'
    
    headers = {
    'Authorization': f'Bearer {api_key}',
    # Missing header here
    }
    
    url = f'https://{fg_ip}/api/v2/cmdb/firewall/address'
    
    response = requests.post(url, headers=headers, verify=False)
    
    Answer and explanation

    Correct answer: C

    When sending data to the FortiGate REST API using methods like POST or PUT, the 'Content-Type' header is mandatory. It informs the API server about the format of the data in the request body. For FortiGate's API, this is typically 'application/json'. Without this header, the API will reject the request.

  9. Question 9

    A global enterprise has a complex hub-and-spoke ADVPN deployment. They are experiencing issues where spoke-to-spoke shortcut tunnels are not forming for VoIP traffic, causing calls to hairpin through the hub and increasing latency. The IPsec, BGP, and underlying network connectivity have been verified as correct. What is a common ADVPN-specific reason for this behavior?

    Answer and explanation

    Correct answer: D

    For ADVPN to trigger a shortcut, the initial packet from one spoke to another must pass through the hub. The firewall policy on the hub that matches this traffic must have set auto-discovery-shortcut enable configured. This command instructs the FortiGate to send the IKE informational messages to the initiating and destination spokes, which allows them to build a direct shortcut tunnel. If this is missing, the traffic will simply be routed through the hub.

  10. Question 10

    A consultant is reviewing an SD-WAN deployment where application performance is poor despite having two high-quality internet links. The configuration uses a performance SLA with latency, jitter, and packet loss thresholds. The SD-WAN rule is set to 'Best Quality'. The consultant observes from the performance SLA logs that both links are consistently marked as 'dead' (red), even though manual ping tests show low latency and no loss. What is the most likely configuration error?

    Answer and explanation

    Correct answer: B

    The performance SLA relies on probes sent to a health-check server to measure link quality. If this server is unreachable (e.g., due to routing issues, upstream firewall blocks, or the server being down), all probes will fail. This will cause the FortiGate to mark the links as 'dead' because it cannot measure their quality, regardless of the actual link performance for other traffic.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 216 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon