FCP Network Security Fundamentals & Fortinet Solutions 4 — Questions and Answers
Question 1: Which FortiGate feature uses machine learning to establish a baseline of normal network behavior and alert on anomalies?
- Web Application Firewall (WAF)
- FortiGuard Outbreak Prevention
- Behavioral Analytics via FortiAI
- Intrusion Prevention System (IPS) in anomaly mode (Correct answer)
Correct answer: Intrusion Prevention System (IPS) in anomaly mode
FortiGate IPS in anomaly detection mode monitors traffic patterns and flags deviations from established baselines, such as unusual connection rates or protocol violations.
Question 2: In a FortiGate IPsec VPN, what is Phase 1 responsible for establishing?
- The data encryption tunnel for user traffic
- The IKE security association used to authenticate peers and negotiate Phase 2 parameters (Correct answer)
- The routing entries for VPN subnets
- The firewall policies permitting VPN traffic
Correct answer: The IKE security association used to authenticate peers and negotiate Phase 2 parameters
IKE Phase 1 establishes the ISAKMP/IKE Security Association, authenticating the VPN peers and creating a secure channel over which Phase 2 negotiations occur.
Question 3: What is the function of the FortiGate 'Security Fabric' topology view?
- It displays real-time bandwidth graphs for all WAN interfaces
- It provides a visual map of connected Fortinet devices and their trust relationships (Correct answer)
- It shows BGP routing tables across all FortiGate devices
- It generates compliance reports for PCI DSS audits
Correct answer: It provides a visual map of connected Fortinet devices and their trust relationships
The Security Fabric topology view gives administrators a graphical overview of all connected Fortinet devices, their roles, and their integration status within the fabric.
Question 4: Which authentication method does FortiGate use for 'certificate-based' SSL VPN authentication?
- RADIUS shared secret
- Pre-shared key (PSK)
- PKI user certificate validated against a trusted CA (Correct answer)
- LDAP username and password
Correct answer: PKI user certificate validated against a trusted CA
Certificate-based SSL VPN authentication requires users to present a valid PKI certificate issued or trusted by the configured CA on the FortiGate.
Question 5: What does FortiGate's 'geo-IP filtering' capability allow administrators to do?
- Route traffic through the closest FortiGate PoP based on geography
- Block or allow traffic based on the geographic location of source or destination IP addresses (Correct answer)
- Apply different QoS policies depending on the continent
- Map IP addresses to user identities using GeoIP data
Correct answer: Block or allow traffic based on the geographic location of source or destination IP addresses
Geo-IP filtering uses a database that maps IP addresses to countries, allowing policies to block or permit traffic based on the source or destination nation.
Question 6: In FortiGate, what is the purpose of the 'DoS policy' feature?
- To establish SLA targets for critical applications
- To detect and mitigate volumetric attacks such as SYN floods and UDP floods at the interface level (Correct answer)
- To configure denial-of-service protection for management access only
- To block DoS attacks from specific geographic regions
Correct answer: To detect and mitigate volumetric attacks such as SYN floods and UDP floods at the interface level
FortiGate DoS policies detect and drop anomalous traffic volumes (e.g., SYN floods, ICMP floods) to protect servers and network infrastructure from volumetric denial-of-service attacks.
Question 7: Which Fortinet solution provides endpoint detection and response (EDR) capabilities integrated with the Security Fabric?
- FortiNAC
- FortiClient EMS with EDR features (Correct answer)
- FortiDeceptor
- FortiWeb
Correct answer: FortiClient EMS with EDR features
FortiClient EMS (Endpoint Management Server) with its EDR add-on provides endpoint telemetry, threat detection, and response actions integrated into the Fortinet Security Fabric.
Which FortiGate feature uses machine learning to establish a baseline of normal network behavior and alert on anomalies?