FCP Fortinet Security Fabric Integration & Troubleshooting 5 — Questions and Answers
Question 1: A FortiGate is a member of a Security Fabric but its 'Security Rating' tab shows no data. FortiAnalyzer is connected. What is the most likely cause?
- Security Rating requires a FortiCare Premium subscription that has expired
- The FortiGate is a downstream member — Security Rating is only visible on the root FortiGate (Correct answer)
- FortiAnalyzer's disk quota is full, preventing rating data from being stored
- Security Rating must be manually triggered from the CLI using 'execute security-rating'
Correct answer: The FortiGate is a downstream member — Security Rating is only visible on the root FortiGate
Security Rating results are consolidated and displayed on the root FortiGate; downstream members contribute data but do not show the full rating dashboard independently.
Question 2: Which Fabric Connector type would an administrator use to dynamically update FortiGate address objects based on Kubernetes pod labels?
- ITSM Connector (ServiceNow)
- SDN Connector for Kubernetes (Correct answer)
- FortiClient EMS Connector
- Generic REST API Connector
Correct answer: SDN Connector for Kubernetes
The SDN Connector for Kubernetes synchronizes pod labels and namespace metadata as dynamic address objects that can be used in FortiGate security policies.
Question 3: During a Security Fabric upgrade, what is the recommended upgrade sequence to avoid connectivity issues?
- Upgrade all downstream FortiGates simultaneously, then upgrade the root
- Upgrade FortiAnalyzer first, then the root FortiGate, then downstream devices (Correct answer)
- Upgrade the root FortiGate first, then upgrade downstream devices one at a time
- Upgrade FortiManager first, then all FortiGates in any order
Correct answer: Upgrade FortiAnalyzer first, then the root FortiGate, then downstream devices
Fortinet recommends upgrading FortiAnalyzer first to ensure log compatibility, then the root FortiGate, followed by downstream FortiGates.
Question 4: An administrator wants to use Security Fabric to enforce a policy that blocks traffic from any endpoint not compliant with FortiClient EMS posture checks. Which feature enables this?
- FortiGate Zero Trust Network Access (ZTNA) with EMS tags (Correct answer)
- FortiNAC dynamic VLAN assignment
- FortiAuthenticator certificate-based NAC
- FortiManager compliance policy templates
Correct answer: FortiGate Zero Trust Network Access (ZTNA) with EMS tags
ZTNA with FortiClient EMS integration allows FortiGate to enforce access policies based on real-time endpoint compliance tags synchronized from EMS.
Question 5: What is the role of the 'Security Fabric group name' (csf group-name) setting on a FortiGate?
- It identifies the VDOM that participates in the Security Fabric
- It is a shared identifier that all Security Fabric members must match to join the same Fabric group (Correct answer)
- It is the hostname used by FortiManager to identify the Fabric root
- It sets the SNMP community string for Fabric health monitoring
Correct answer: It is a shared identifier that all Security Fabric members must match to join the same Fabric group
The Security Fabric group name must be identical across all devices in the same Fabric; mismatched group names prevent devices from joining the Fabric.
Question 6: A FortiGate administrator needs to verify which Security Fabric members are currently sending logs to FortiAnalyzer. Which FortiAnalyzer location provides this information?
- System > Dashboard > License Information
- Device Manager > Managed Devices list showing log status per device (Correct answer)
- Log View > Log Browse filtered by device
- Reports > Security Fabric Summary
Correct answer: Device Manager > Managed Devices list showing log status per device
FortiAnalyzer's Device Manager shows all registered devices with their connection and log-forwarding status, making it the quickest place to identify logging gaps.
Question 7: Which Security Fabric capability allows a FortiGate to share detected IoT device information discovered via network scanning with other Fabric members?
- FortiView Network topology export
- Fabric-wide device identification via FortiGate's device detection and Fabric sharing (Correct answer)
- FortiNAC profiling database synchronization
- FortiAnalyzer asset inventory replication
Correct answer: Fabric-wide device identification via FortiGate's device detection and Fabric sharing
FortiGate device detection identifies IoT and other devices on local segments, and Security Fabric sharing propagates this inventory to all Fabric members for unified visibility.
A FortiGate is a member of a Security Fabric but its 'Security Rating' tab shows no data.
FortiAnalyzer is connected.
What is the most likely cause?