FCP Fortinet Security Fabric Integration & Troubleshooting 4 β Questions and Answers
Question 1: Which Security Fabric Automation trigger can be used to automatically block an IP address when a FortiGate IPS signature fires?
- Scheduled trigger set to every 5 minutes
- FortiOS Event trigger on 'IPS Alert' (Correct answer)
- FortiAnalyzer Event Handler forwarding to a stitch
- FortiClient EMS compliance event trigger
Correct answer: FortiOS Event trigger on 'IPS Alert'
The FortiOS Event trigger type within a Fabric stitch can react to IPS Alert events and execute blocking actions automatically.
Question 2: An administrator configures a Security Fabric with a FortiGate root and two downstream FortiGates, but only one downstream appears in the topology. What should be verified on the missing downstream?
- That FortiAnalyzer is reachable from the missing downstream FortiGate
- That Security Fabric is enabled and the correct upstream FortiGate IP and pre-shared key are configured (Correct answer)
- That FortiManager is managing the missing downstream unit
- That the missing downstream FortiGate has a public IP address
Correct answer: That Security Fabric is enabled and the correct upstream FortiGate IP and pre-shared key are configured
For a downstream FortiGate to join the Fabric, Security Fabric must be enabled with the correct upstream IP and matching pre-shared key.
Question 3: What is the function of the 'FortiGate Cloud' Fabric Connector?
- It allows FortiGate to push firewall policies to cloud-hosted workloads directly
- It synchronizes threat intelligence and dynamic objects between FortiGate and the FortiCloud management portal
- It integrates cloud provider metadata (AWS/Azure/GCP) as dynamic address objects in FortiGate policies (Correct answer)
- It offloads SSL inspection processing to FortiCloud servers
Correct answer: It integrates cloud provider metadata (AWS/Azure/GCP) as dynamic address objects in FortiGate policies
The cloud Fabric Connectors (AWS, Azure, GCP) pull instance metadata and tags from cloud providers and expose them as dynamic address objects for policy use.
Question 4: A FortiGate administrator runs 'diagnose test application csf 1' and sees 'Fabric status: disconnected'. After confirming the pre-shared key is correct, what is the next troubleshooting step?
- Reinstall FortiOS on the root FortiGate
- Check network reachability and verify TCP port 8013 is not blocked between the devices (Correct answer)
- Reset the FortiAnalyzer connection and re-authorize the device
- Disable and re-enable FortiGuard services on both devices
Correct answer: Check network reachability and verify TCP port 8013 is not blocked between the devices
If the pre-shared key is correct but the Fabric is disconnected, network reachability issues or firewall rules blocking TCP 8013 are the next likely cause.
Question 5: In a Security Fabric, which device is responsible for sending Security Rating results to FortiGuard for benchmarking against other organizations?
- Each downstream FortiGate independently
- FortiAnalyzer on behalf of all Fabric members
- The root FortiGate on behalf of the entire Security Fabric (Correct answer)
- FortiManager after aggregating results from all devices
Correct answer: The root FortiGate on behalf of the entire Security Fabric
The root FortiGate collects Security Rating data from all Fabric members and submits the aggregated score to FortiGuard for industry benchmarking.
Question 6: Which log severity level must be configured on a FortiGate to ensure Security Fabric automation stitches can react to UTM security events?
- Emergency only
- Warning and above
- Notice and above
- Information and above (Correct answer)
Correct answer: Information and above
UTM security events are logged at the Information severity level, so logging must be set to 'Information' or lower to capture them for stitch triggers.
Question 7: What happens to Security Fabric automation stitches when FortiAnalyzer goes offline temporarily?
- All stitches stop functioning until FortiAnalyzer reconnects
- Stitches based on FortiOS local events continue to function; stitches requiring FortiAnalyzer correlation may be delayed or missed (Correct answer)
- FortiManager takes over stitch processing automatically
- Stitches queue all missed events and replay them when FortiAnalyzer reconnects
Correct answer: Stitches based on FortiOS local events continue to function; stitches requiring FortiAnalyzer correlation may be delayed or missed
Locally triggered stitches (FortiOS events) continue to operate independently, but stitches that depend on FortiAnalyzer-correlated events will not fire while FortiAnalyzer is offline.
Which Security Fabric Automation trigger can be used to automatically block an IP address when a FortiGate IPS signature fires?