FCP Fortinet Security Fabric Integration & Troubleshooting 2 — Questions and Answers
Question 1: A FortiManager administrator notices that a managed FortiGate is showing as 'Unregistered' in the Security Fabric topology. What is the most likely cause?
- The FortiGate's serial number is not added to FortiManager's device list
- The FortiGate has a mismatched firmware version with FortiManager
- The Security Fabric root has not authorized the FortiGate as a downstream device (Correct answer)
- FortiAnalyzer is offline and cannot validate the device
Correct answer: The Security Fabric root has not authorized the FortiGate as a downstream device
Downstream FortiGate devices must be explicitly authorized by the Security Fabric root before they appear as registered members.
Question 2: Which Security Fabric feature allows FortiGate to automatically quarantine an endpoint detected as compromised by FortiEDR?
- FortiGuard Outbreak Prevention
- Fabric Connectors with automated response actions
- Security Fabric Automation (Fabric Automation Stitches) (Correct answer)
- FortiNAC dynamic port segmentation
Correct answer: Security Fabric Automation (Fabric Automation Stitches)
Security Fabric Automation Stitches enable event-driven automated responses such as quarantining endpoints when FortiEDR detects a compromise.
Question 3: When troubleshooting Security Fabric connectivity, which CLI command on a downstream FortiGate shows the status of its connection to the root FortiGate?
- diagnose sys csf status (Correct answer)
- get system csf
- diagnose debug application csf -1
- execute csf show topology
Correct answer: diagnose sys csf status
The command 'diagnose sys csf status' displays the current Security Fabric connection status including root and upstream device information.
Question 4: A Security Fabric stitch is configured to trigger on 'Compromised Host' events, but no actions are firing. Which step should the administrator check first?
- Verify that FortiAnalyzer logging is enabled on the triggering FortiGate
- Confirm the stitch is set to 'Enabled' and the trigger matches the log event type (Correct answer)
- Restart the FortiManager daemon to refresh stitch configurations
- Ensure FortiClient EMS is connected to FortiAnalyzer
Correct answer: Confirm the stitch is set to 'Enabled' and the trigger matches the log event type
Stitches will not fire if they are disabled or if the trigger event type does not exactly match the log events being generated.
Question 5: In a Security Fabric deployment, what is the purpose of the 'Fabric Connector' for VMware NSX?
- It synchronizes FortiGate firewall policies to NSX distributed firewall rules
- It imports VMware VM tags as dynamic address objects usable in FortiGate policies (Correct answer)
- It enables FortiManager to manage NSX Edge gateways
- It provides SSL inspection for east-west VMware traffic
Correct answer: It imports VMware VM tags as dynamic address objects usable in FortiGate policies
The VMware NSX Fabric Connector imports VM security tags as dynamic address objects, enabling policy enforcement based on workload attributes.
Question 6: Which Security Fabric feature provides a unified view of all vulnerabilities detected across all connected Fortinet devices?
- FortiView Threats dashboard
- Security Rating (Correct answer)
- Security Fabric Topology
- Vulnerability Management in FortiManager
Correct answer: Security Rating
Security Rating aggregates compliance and vulnerability data across all Security Fabric members, providing a unified posture score and findings.
Question 7: A FortiAnalyzer is not receiving logs from a downstream FortiGate even though the Fabric connection is established. What should the administrator verify?
- That the FortiGate has a valid FortiCloud subscription
- That FortiAnalyzer's IP is configured under the FortiGate's logging settings and the device is authorized in FortiAnalyzer (Correct answer)
- That FortiManager has pushed the log policy to the FortiGate
- That Syslog forwarding is disabled so logs go to FortiAnalyzer instead
Correct answer: That FortiAnalyzer's IP is configured under the FortiGate's logging settings and the device is authorized in FortiAnalyzer
Logs are only sent to FortiAnalyzer if it is explicitly configured as a log server on FortiGate and the device is authorized within FortiAnalyzer.
A FortiManager administrator notices that a managed FortiGate is showing as 'Unregistered' in the Security Fabric topology.
What is the most likely cause?