FCP Security Policy Management & Compliance 3 — Questions and Answers
Question 1: Which FortiGate feature allows an administrator to define acceptable use policies by displaying a disclaimer page to users before granting internet access?
- Captive portal with disclaimer (Correct answer)
- Web filter block page
- SSL inspection notice
- FortiAuthenticator guest portal
Correct answer: Captive portal with disclaimer
FortiGate captive portal can require users to acknowledge an acceptable use policy disclaimer before traffic is permitted through the policy.
Question 2: An administrator wants to enforce that all SSL/TLS connections to external sites use a minimum of TLS 1.2. Which FortiGate feature enforces this requirement?
- SSL/SSH inspection profile with minimum TLS version setting (Correct answer)
- Web filter HTTPS scanning
- IPS SSL anomaly signatures
- Application control TLS filter
Correct answer: SSL/SSH inspection profile with minimum TLS version setting
SSL/SSH inspection profiles allow administrators to configure minimum and maximum TLS version requirements, blocking connections that don't meet the threshold.
Question 3: When implementing a least-privilege firewall policy, which FortiGate practice best represents this principle?
- Using 'any/any/permit' as the default last rule
- Creating specific source/destination/service policies and ending with an implicit deny (Correct answer)
- Enabling all UTM profiles on every policy
- Relying on FortiGuard dynamic address objects only
Correct answer: Creating specific source/destination/service policies and ending with an implicit deny
Least privilege requires explicitly allowing only necessary traffic with specific criteria, with all other traffic denied by the implicit deny rule at the bottom.
Question 4: FortiAnalyzer's compliance reports map log data to which framework when generating SOX compliance evidence?
- CIS Controls
- PCI DSS requirements
- COBIT control objectives (Correct answer)
- NIST 800-171
Correct answer: COBIT control objectives
FortiAnalyzer includes built-in SOX compliance reports that map collected log data to COBIT control objectives for financial system audit evidence.
Question 5: An administrator must ensure FortiGate policies are reviewed quarterly. Which FortiManager workflow feature helps enforce this review process?
- Approval workflow requiring dual administrator sign-off (Correct answer)
- Policy hit count reset with scheduled report
- Locked ADOM preventing edits
- FortiGuard subscription renewal alerts
Correct answer: Approval workflow requiring dual administrator sign-off
FortiManager's approval workflow requires designated administrators to review and approve policy changes before installation, supporting periodic review processes.
Question 6: Which FortiGate object type enables policy matching based on a user's Active Directory group membership rather than IP address?
- Dynamic address object with FSSO tag (Correct answer)
- Fabric connector address
- Virtual IP (VIP) mapping
- ISDB Internet Service object
Correct answer: Dynamic address object with FSSO tag
FSSO (Fortinet Single Sign-On) tags IP addresses with AD group membership, allowing FortiGate policies to match traffic based on user identity.
Question 7: Under HIPAA Security Rule requirements, which FortiGate capability helps meet the Audit Controls standard (§164.312(b))?
- Traffic logging with FortiAnalyzer retention and reporting (Correct answer)
- FortiToken MFA for VPN access
- IPS profile with exploit prevention
- FortiClient endpoint compliance check
Correct answer: Traffic logging with FortiAnalyzer retention and reporting
HIPAA §164.312(b) requires audit controls to record and examine activity in systems containing ePHI, which FortiGate logging sent to FortiAnalyzer satisfies.
Which FortiGate feature allows an administrator to define acceptable use policies by displaying a disclaimer page to users before granting internet access?