Free FCP - FortiGate 7.6 Administrator practice — 6 questions on Security Profiles (Content Inspection), with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Security Profiles (Content Inspection)
After an administrator enables Full SSL Inspection with the default deep-inspection profile, users report browser certificate warnings on every HTTPS site, even legitimate ones. The security requirement to decrypt and inspect all outbound HTTPS traffic must remain in place. What is the correct fix?
In full (deep) SSL inspection, FortiGate re-signs every HTTPS session with a CA certificate it generates on the fly. Browsers warn because that CA is untrusted by the client OS/browser. Distributing and trusting the FortiGate's CA cert (via GPO or MDM) eliminates the warning while decryption/inspection continues.
Question 2 of 6 · Security Profiles (Content Inspection)
A company wants to prevent users from bypassing FortiGate's DNS-based filtering by pointing their browsers at a DNS-over-HTTPS resolver such as cloudflare-dns.com. Which feature should the administrator configure?
FortiOS DNS Filter profiles include a dedicated toggle that uses FortiGuard's DoH server database to detect and block encrypted DNS attempts, forcing clients back to standard DNS that the DNS filter can inspect.
Question 3 of 6 · Security Profiles (Content Inspection)
An administrator notices that when the IPS engine on a FortiGate crashes due to resource exhaustion, all traffic subject to IPS-enabled policies stops passing until the engine restarts. Which CLI setting controls whether traffic is allowed to bypass inspection during such an IPS engine failure?
The 'fail-open' setting under 'config ips global' determines behavior if the IPS engine becomes unavailable. Disabled (default) means fail-closed, dropping traffic; enabling fail-open allows traffic to pass uninspected rather than blocking business traffic.
Question 4 of 6 · Security Profiles (Content Inspection)
A FortiGate policy uses an Application Control sensor with SSL Certificate Inspection (not full SSL inspection). The company reports that FortiGate consistently classifies both Google Drive uploads and Gmail webmail traffic as the generic 'Google' application rather than the specific cloud app, preventing granular per-app policy control. What should the administrator do to fix accurate classification?
With only certificate inspection, FortiGate can see just the SNI/certificate CN, which for many Google services is shared, so specific cloud apps sharing a domain can't be distinguished. Full SSL inspection decrypts the payload, giving the application control engine the additional data (URLs, headers) needed for accurate per-app classification of cloud services.
Question 5 of 6 · Security Profiles (Content Inspection)
An administrator wants to block executable files even when a user renames a file's extension from .exe to .txt before uploading it through the firewall. Which File Filter configuration approach correctly achieves this?
FortiOS File Filter profiles support rules based on true file type, which is determined by inspecting the file's actual binary content/header signature rather than its extension, so a renamed .exe is still correctly identified and blocked as an executable.
Question 6 of 6 · Security Profiles (Content Inspection)
The antivirus profile applied to an SMTP policy has its oversize file threshold left at the configured default, and a 50MB file well above that threshold arrives containing malware. The oversize action has not been changed from its default value. What happens to this file by default?
Antivirus scanning requires buffering the full file, which is impractical beyond the configured oversize limit. By default, files that exceed this threshold are passed through (with an oversize event logged) rather than blocked, since the AV engine cannot fully scan them — administrators must explicitly change the oversize action to Block to enforce stricter handling.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.