✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Deployment and System Configuration
A company must insert a new FortiGate between two existing VLANs that are on the same IP subnet. The requirement is to apply firewall policies and UTM inspection between the VLANs without changing any existing host IP addresses, default gateways, or routing tables. Which FortiGate operation mode BEST meets this requirement?
Transparent mode makes the FortiGate act as a Layer 2 bridge with no IP re-addressing required on existing hosts, while still allowing firewall policies, UTM profiles, and security inspection to be applied between the bridged interfaces/VLANs.
Question 2 of 12 · Firewall Policies and Network Address Translation (NAT)
A FortiGate has three firewall policies configured in this order: Policy 10 (permits HTTP from LAN to WAN), Policy 20 (denies HTTP from a specific host to WAN), Policy 30 (permits all traffic from LAN to WAN). Traffic from the host referenced in Policy 20 attempts an HTTP session to the internet. What happens?
FortiGate evaluates firewall policies sequentially from top to bottom and applies the action of the FIRST policy whose criteria match the session; Policy 10 matches (LAN to WAN, HTTP) before the more restrictive Policy 20 is ever evaluated, so the host is permitted despite the intended deny rule below it.
Question 3 of 12 · Firewall Authentication and FSSO
A company wants to deploy Fortinet Single Sign-On (FSSO) to identify users transparently for firewall policies, but the security team refuses to allow any software to be installed on the domain controllers. Which FSSO mode should be configured?
Polling mode is agentless from the domain controller's perspective — the Collector Agent (installed on a separate Windows server) periodically polls the DC's security event logs via NetAPI or WMI, so no software is installed on the DCs themselves.
Question 4 of 12 · Security Profiles (Content Inspection)
A FortiGate administrator wants to use antivirus profile features that require full file buffering, such as blocking oversized archive files and showing a custom replacement message to the end user when a file is blocked. Which firewall policy inspection mode must be used for this antivirus profile to support these features?
Proxy-based inspection buffers the entire file on the FortiGate before forwarding it, which is required to support features like oversized-file handling with custom replacement messages.
Question 5 of 12 · Routing and SD-WAN
A FortiGate has two static default routes configured to two different ISPs, both with administrative distance 10. Route A has priority 0 and Route B has priority 10. SD-WAN is not configured. Which route(s) will FortiGate actually use in the routing table?
When distance is equal, FortiGate uses priority (metric) as the next tiebreaker, and a lower priority value is more preferred, so only the priority-0 route is installed as active.
Question 6 of 12 · VPN (IPsec and Remote Access)
A network engineer must connect two FortiGate HQ and branch sites over IPsec and run OSPF across the tunnel to dynamically exchange routes. The design must also support future expansion to a hub-and-spoke topology with minimal reconfiguration. Which VPN configuration BEST meets these requirements?
Route-based (interface mode) IPsec VPN creates a virtual tunnel interface that behaves like any other FortiGate interface, so it can be added to OSPF areas, referenced in the routing table, and easily extended to hub-and-spoke designs by adding more tunnel interfaces and phase2 selectors.
Question 7 of 12 · Security Fabric
A company deploys a HQ FortiGate as the Security Fabric root and three branch FortiGates as downstream devices. The administrator wants the branch devices to automatically appear in the Security Fabric topology on the root and be treated as trusted fabric members. Which configuration is required on ALL the FortiGates for this to work?
Security Fabric membership (CSF) is established under config system csf on every device, using a matching group-name and group-password. Once a downstream device connects, the root administrator must authorize it in the trusted list (System > Security Fabric > Fabric Connectors > Security Fabric Setup) before it fully joins the topology.
Question 8 of 12 · FortiGuard, Logging, Monitoring, and Diagnostics
A network engineer needs to determine exactly which firewall policy and security profile a specific host's traffic is matching, since the traffic seems to be silently dropped despite an apparently correct firewall policy. Which sequence of diagnostic commands BEST identifies the policy decision path for this traffic?
The debug flow toolset (filter, trace start, debug enable) traces a packet through the FortiOS packet flow, showing exactly which policy ID, route, and security profile decisions are applied or which stage causes a drop.
Question 9 of 12 · Deployment and System Configuration
An administrator wants to allow encrypted GUI management access to a FortiGate's port1 interface from the internal network, while ensuring management traffic is not sent in cleartext. Which administrative access service should be enabled on that interface?
HTTPS provides TLS-encrypted access to the FortiGate GUI, satisfying the requirement for secure, non-cleartext management traffic.
Question 10 of 12 · Firewall Policies and Network Address Translation (NAT)
An administrator needs every internal host behind a FortiGate to consistently use the SAME translated public IP address for all of its outbound sessions (a strict one-to-one mapping between internal and external addresses), rather than sharing a pool of addresses via port translation. Which IP Pool type should be configured for the source NAT?
The 'One-to-One' IP pool type maps each internal source IP to a dedicated external IP address without port-level translation, guaranteeing the same public IP is always used for a given internal host.
Question 11 of 12 · Firewall Authentication and FSSO
An organization uses Citrix XenApp/RDS servers where dozens of users share a single source IP address. Firewall policies must still apply per-user identity via FSSO. Which FSSO component is required for this deployment?
The Terminal Server Agent is specifically designed to track per-user sessions on multi-user servers (Citrix/RDS) by assigning a unique port range per user, since normal FSSO cannot distinguish users sharing one IP address.
Question 12 of 12 · Security Profiles (Content Inspection)
After enabling full SSL/TLS deep inspection on a firewall policy, internal users start seeing certificate warning errors in their browsers for HTTPS sites, even though FortiGate is correctly re-signing the traffic with its inspection CA. What is the most likely cause and correct remediation?
With deep inspection, FortiGate re-signs the server certificate using its own CA. Clients will show trust warnings unless that CA certificate is deployed as a trusted root certificate on client devices.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $400 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 8 domains: Deployment and System Configuration (~15% (instructional emphasis)), Firewall Policies and Network Address Translation (NAT) (~18% (instructional emphasis)), Firewall Authentication and FSSO (~12% (instructional emphasis)), Security Profiles (Content Inspection) (~20% (instructional emphasis)), Routing and SD-WAN (~13% (instructional emphasis)), VPN (IPsec and Remote Access) (~12% (instructional emphasis)), Security Fabric (~5% (instructional emphasis)), FortiGuard, Logging, Monitoring, and Diagnostics (~5% (instructional emphasis)). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.