FCP Security Policy Management & Compliance 5 — Questions and Answers
Question 1: An organization's compliance policy requires all remote access VPN connections to use certificate-based authentication. Which FortiGate configuration enforces this?
- SSL-VPN with username/password only
- IPsec VPN with pre-shared key
- SSL-VPN or IPsec VPN configured with PKI peer certificate authentication (Correct answer)
- FortiToken SMS-based OTP only
Correct answer: SSL-VPN or IPsec VPN configured with PKI peer certificate authentication
Configuring SSL-VPN or IPsec VPN with PKI peer (certificate) authentication ensures only clients with valid certificates can establish remote access sessions.
Question 2: Which FortiGate feature detects when a managed device's running configuration diverges from the approved baseline stored in FortiManager?
- Configuration drift detection via FortiManager's 'retrieve' and diff comparison (Correct answer)
- FortiAnalyzer anomaly detection
- Security Fabric topology alerts
- FortiGate SNMP trap on config change
Correct answer: Configuration drift detection via FortiManager's 'retrieve' and diff comparison
FortiManager can retrieve the current running configuration from a managed device and compare it to the stored revision, highlighting any configuration drift.
Question 3: Under the CIS Controls framework, which control is most directly satisfied by maintaining an up-to-date inventory of FortiGate firewall rules and reviewing unused policies?
- CIS Control 1: Inventory of Enterprise Assets
- CIS Control 12: Network Infrastructure Management (Correct answer)
- CIS Control 3: Data Protection
- CIS Control 8: Audit Log Management
Correct answer: CIS Control 12: Network Infrastructure Management
CIS Control 12 covers network infrastructure management including maintaining and reviewing firewall rules, making it the closest match for firewall policy hygiene.
Question 4: A security policy requires blocking access to social media during work hours but allowing it after 6 PM on weekdays and all day on weekends. Which combination of FortiGate features achieves this?
- Two web filter policies with different schedule objects attached (Correct answer)
- A single policy with multiple source IP ranges
- FortiAnalyzer scheduled reports
- FortiManager time-based ADOM locking
Correct answer: Two web filter policies with different schedule objects attached
Two separate web filter policies—one blocking social media with a business-hours schedule and one allowing it with an after-hours schedule—achieves this requirement.
Question 5: Which FortiGate diagnostic command helps verify whether a specific traffic flow matches the intended security policy before it reaches the network?
- diagnose debug flow filter (Correct answer)
- get system performance status
- diagnose sys session list
- execute policy-check
Correct answer: diagnose debug flow filter
The 'diagnose debug flow filter' command with flow trace enables real-time policy lookup debugging, showing which policy matches a specific traffic flow.
Question 6: An administrator needs to ensure that firewall policy changes go through a formal approval process. Which FortiManager setting enables a mandatory review-before-install workflow?
- Enabling workspace mode with approval workflow in ADOM settings (Correct answer)
- Setting ADOM to read-only mode
- Enabling FortiGuard policy validation
- Configuring FortiAnalyzer alert thresholds
Correct answer: Enabling workspace mode with approval workflow in ADOM settings
FortiManager workspace mode with approval workflow requires designated approvers to review and authorize policy changes before they can be installed on managed devices.
Question 7: Which compliance regulation specifically mandates that organizations implement 'appropriate technical measures' for personal data protection, which FortiGate's encryption and access control policies help satisfy?
- PCI DSS Requirement 7
- HIPAA Privacy Rule
- GDPR Article 32 (Correct answer)
- SOX Section 404
Correct answer: GDPR Article 32
GDPR Article 32 requires appropriate technical and organizational measures to protect personal data, which FortiGate's encryption enforcement and access control policies help satisfy.
An organization's compliance policy requires all remote access VPN connections to use certificate-based authentication.
Which FortiGate configuration enforces this?