FCP Security Policy Management & Compliance 4 — Questions and Answers
Question 1: A FortiGate policy is configured with action 'accept' but traffic is still being blocked. After checking all explicit deny rules, what should the administrator investigate next?
- Policy order—a higher-priority deny rule may match first (Correct answer)
- FortiAnalyzer correlation rules
- FortiManager ADOM lock status
- SD-WAN rule priority
Correct answer: Policy order—a higher-priority deny rule may match first
FortiGate evaluates policies top-to-bottom; a deny rule earlier in the list that also matches the traffic will take effect before the accept rule is reached.
Question 2: Which security compliance framework requires organizations to maintain a formal risk management program, which FortiGate's Security Rating and FortiAnalyzer reports help document?
- GDPR Article 32
- ISO/IEC 27001 Annex A
- NIST CSF Identify/Protect functions (Correct answer)
- CIS Benchmark Level 2
Correct answer: NIST CSF Identify/Protect functions
NIST CSF's Identify and Protect functions require risk assessments and security controls documentation, which Security Rating scores and FortiAnalyzer reports provide evidence for.
Question 3: An administrator wants to automatically quarantine a FortiClient endpoint that fails a posture check. Which integration achieves this?
- FortiClient EMS with compliance enforcement and quarantine VLAN (Correct answer)
- FortiAnalyzer IOC detection
- FortiGate IPS quarantine action
- FortiManager device quarantine
Correct answer: FortiClient EMS with compliance enforcement and quarantine VLAN
FortiClient EMS enforces endpoint compliance policies and can place non-compliant endpoints into a quarantine VLAN until they meet posture requirements.
Question 4: Which FortiGate feature allows writing custom traffic-matching criteria using Boolean logic for scenarios where standard policy fields are insufficient?
- Policy-based routing with advanced criteria
- Custom IPS signatures
- Security policy with ZTNA tags
- FortiGate scripting with custom match conditions via CLI (Correct answer)
Correct answer: FortiGate scripting with custom match conditions via CLI
FortiGate CLI scripting and custom match conditions allow administrators to craft complex Boolean logic for traffic selection beyond standard GUI policy fields.
Question 5: A SOC manager needs to demonstrate that security policies are enforced 24/7. Which FortiAnalyzer report type provides continuous policy compliance evidence?
- Traffic summary reports with policy hit counts over time (Correct answer)
- Real-time dashboard widgets only
- FortiGate CPU usage graphs
- SD-WAN performance reports
Correct answer: Traffic summary reports with policy hit counts over time
FortiAnalyzer traffic summary reports showing policy hit counts over time demonstrate that security policies are actively enforcing traffic continuously.
Question 6: When FortiGate's implicit deny rule drops a packet, where is this event recorded by default?
- It is not logged unless explicit logging is enabled on the implicit deny policy (Correct answer)
- It is always logged to FortiAnalyzer automatically
- It is recorded in the system event log
- It is only visible in the flow debug output
Correct answer: It is not logged unless explicit logging is enabled on the implicit deny policy
The implicit deny policy does not log by default; administrators must explicitly enable logging on it to capture denied traffic for compliance purposes.
Question 7: Which FortiGate object is used to group multiple firewall policies into a logical unit for easier management and consistent application across sites?
- Policy package (Correct answer)
- Address group
- Service group
- VDOM
Correct answer: Policy package
FortiManager policy packages group sets of firewall policies that can be assigned and deployed consistently across multiple FortiGate devices.
A FortiGate policy is configured with action 'accept' but traffic is still being blocked.
After checking all explicit deny rules, what should the administrator investigate next?