FCP Network Security Fundamentals & Fortinet Solutions 2 — Questions and Answers
Question 1: Which Fortinet product provides centralized management and visibility across the entire security fabric?
- FortiAnalyzer
- FortiManager (Correct answer)
- FortiSIEM
- FortiOrchestrator
Correct answer: FortiManager
FortiManager provides centralized policy management, configuration, and orchestration across FortiGate and other Fortinet devices in the Security Fabric.
Question 2: In a FortiGate SD-WAN deployment, what is the purpose of a Performance SLA?
- To encrypt SD-WAN traffic between branches
- To monitor link quality metrics like latency, jitter, and packet loss (Correct answer)
- To assign static routes to specific WAN interfaces
- To authenticate remote SD-WAN peers using certificates
Correct answer: To monitor link quality metrics like latency, jitter, and packet loss
Performance SLAs in FortiGate SD-WAN continuously measure link health metrics (latency, jitter, packet loss) to determine the best path for traffic.
Question 3: What is the default behavior of FortiGate when it receives traffic that does not match any firewall policy?
- The traffic is logged and forwarded
- The traffic is sent to the implicit deny rule and dropped (Correct answer)
- The traffic is quarantined for inspection
- The traffic triggers an alert but is allowed
Correct answer: The traffic is sent to the implicit deny rule and dropped
FortiGate uses an implicit deny-all policy at the bottom of the policy list; any traffic not matching an explicit allow rule is dropped.
Question 4: Which protocol does FortiAuthenticator use to integrate with Active Directory for user authentication?
- SNMP
- LDAP (Correct answer)
- SMTP
- BGP
Correct answer: LDAP
FortiAuthenticator uses LDAP (and optionally Kerberos) to query Active Directory for user credentials and group membership.
Question 5: What does UTM stand for in the context of FortiGate security features?
- Unified Threat Management (Correct answer)
- Universal Traffic Monitoring
- User Trust Mechanism
- Upstream Traffic Multiplexer
Correct answer: Unified Threat Management
UTM (Unified Threat Management) refers to the bundled security inspection features on FortiGate, including antivirus, IPS, web filtering, and application control.
Question 6: In FortiGate SSL inspection, what is the difference between 'certificate inspection' and 'deep inspection'?
- Certificate inspection decrypts and re-encrypts all SSL traffic; deep inspection only checks the certificate
- Certificate inspection only checks the server certificate SNI/CN without decrypting; deep inspection fully decrypts and inspects payload (Correct answer)
- Certificate inspection applies only to HTTPS; deep inspection applies to all protocols
- There is no functional difference between the two modes
Correct answer: Certificate inspection only checks the server certificate SNI/CN without decrypting; deep inspection fully decrypts and inspects payload
Certificate inspection validates the server certificate without decrypting payload, while deep (full) SSL inspection decrypts, inspects, and re-encrypts traffic.
Question 7: Which FortiGate feature allows administrators to block or allow applications regardless of port or protocol?
- Web Filtering
- Application Control (Correct answer)
- Intrusion Prevention System
- DNS Filter
Correct answer: Application Control
FortiGate Application Control uses deep packet inspection to identify and control applications based on their traffic signatures, independent of port or protocol.
Which Fortinet product provides centralized management and visibility across the entire security fabric?