FCP Security Policy Management & Compliance 2 — Questions and Answers
Question 1: A FortiGate administrator needs to ensure that firewall policies are only applied during business hours (8 AM–6 PM). Which FortiGate feature enables time-based policy enforcement?
- Policy scheduling using schedule objects (Correct answer)
- FortiManager policy revision control
- FortiAnalyzer compliance reports
- Security rating schedules
Correct answer: Policy scheduling using schedule objects
FortiGate schedule objects (recurring or one-time) can be attached to firewall policies to restrict when they are active.
Question 2: Under NIST 800-53, which control family is most directly addressed by FortiGate's firewall policy logging and FortiAnalyzer audit trails?
- Access Control (AC)
- Audit and Accountability (AU) (Correct answer)
- System and Communications Protection (SC)
- Incident Response (IR)
Correct answer: Audit and Accountability (AU)
The AU control family covers audit logging and accountability, which aligns with FortiGate's traffic logging and FortiAnalyzer's audit trail capabilities.
Question 3: An organization wants to prevent shadow IT by blocking unsanctioned SaaS applications. Which FortiGate feature provides application-level policy control for this use case?
- URL category filtering
- Application control profiles (Correct answer)
- DNS filtering with FortiGuard
- Web rating overrides
Correct answer: Application control profiles
Application control profiles classify and block specific applications (including SaaS) at the policy level using deep packet inspection.
Question 4: Which FortiManager feature allows administrators to deploy a consistent baseline security policy across 50 FortiGate devices simultaneously?
- Policy packages with installation targets (Correct answer)
- FortiGate Cloud sync
- ADOM replication
- FortiAnalyzer policy push
Correct answer: Policy packages with installation targets
FortiManager policy packages can be assigned to multiple FortiGate devices as installation targets, enabling centralized consistent policy deployment.
Question 5: A compliance audit requires proof that no firewall rules have been modified without change control approval. Which FortiManager capability best satisfies this requirement?
- FortiManager revision history and audit log (Correct answer)
- FortiAnalyzer event correlation
- FortiGate configuration backup
- Security Fabric topology view
Correct answer: FortiManager revision history and audit log
FortiManager maintains a revision history of all policy changes with timestamps and administrator identity, satisfying change control audit requirements.
Question 6: Which FortiGate security profile type inspects outbound traffic to detect and block data exfiltration of sensitive files such as credit card numbers?
- Antivirus profile
- DLP (Data Loss Prevention) profile (Correct answer)
- Web filter profile
- IPS profile
Correct answer: DLP (Data Loss Prevention) profile
DLP profiles inspect traffic content for sensitive data patterns (PII, financial data) and can block or log matching transfers.
Question 7: A PCI DSS assessment requires that cardholder data environments be network-segmented from other zones. Which FortiGate concept is the primary enforcement mechanism?
- VDOMs (Virtual Domains) with inter-VDOM routing policies (Correct answer)
- FortiSwitch VLANs only
- FortiAnalyzer log segmentation
- Security rating network segmentation score
Correct answer: VDOMs (Virtual Domains) with inter-VDOM routing policies
VDOMs create logically separated firewall instances, and inter-VDOM routing policies strictly control traffic between the CDE and other network segments.
A FortiGate administrator needs to ensure that firewall policies are only applied during business hours (8 AM–6 PM).
Which FortiGate feature enables time-based policy enforcement?