NSE8-812 Fortinet Certified Expert (FCX) - Cybersecurity Practice Questions
Prepare for NSE8-812 with more than an answer.
- Exam fee
- $400 USD
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 7
- Security Architecture15%
- Infrastructure15%
- Networking20%
- Secure SD-WAN15%
- Security Solutions20%
- Security Operations10%
- Automation5%
- 1
When designing an OSPF network that includes multiple FortiGate devices, an architect wants to ensure that routing updates between areas are summarized to reduce the size of the routing tables on internal routers. The FortiGate connecting the two areas is configured as an Area Border Router (ABR). Which type of OSPF route is created by the ABR to represent these summarized inter-area routes?
Show answer details
Correct answer: D
Area Border Routers (ABRs) are responsible for summarizing routes from one area and advertising them into another. These advertisements are sent as Type 3 Link-State Advertisements (LSAs), also known as Summary LSAs. Routers within an area will see these Type 3 LSAs in their database and install them as inter-area (O IA) routes in their routing table.
- 2
A hospital is deploying a FortiGate high-availability cluster to protect its critical patient data systems. Due to the nature of medical applications, it is imperative that long-lived TCP sessions, such as those used for large medical imaging file transfers, survive a firewall failover. Which command must be enabled to ensure TCP sessions are fully synchronized and can be seamlessly picked up by the secondary unit?
Show answer details
Correct answer: D
While
set session-pickup enableis the primary command for enabling session synchronization, it only synchronizes basic session information by default. For stateful TCP sessions to be fully resilient to failover, TCP sequence numbers must also be synchronized. Theset session-pickup-delay enablecommand (which requiressession-pickupto be enabled) activates this enhanced TCP session synchronization. This ensures that the secondary unit has the correct sequence numbers to continue the conversation after a failover, preventing TCP resets and application disruption. Note: In modern FortiOS versions, this is often enabled by default whensession-pickupis on, but knowing its function is key. - 3
Case Study:
A managed security service provider (MSSP) uses a single FortiGate to provide firewall services for two distinct customers, Customer A and Customer B. The MSSP has configured two VDOMs, VDOM-A and VDOM-B, to maintain administrative and traffic separation. Customer A's network (10.10.0.0/16) is connected to port1 in VDOM-A, and Customer B's network (10.20.0.0/16) is connected to port2 in VDOM-B. Both customers need to access a shared resource, a logging server with the IP address 192.168.100.10, which is connected to port3 in the root VDOM.
The MSSP has created inter-VDOM links: VLINK_A (from root to VDOM-A) and VLINK_B (from root to VDOM-B). The goal is to allow both customers to reach the logging server while ensuring that Customer A and Customer B cannot communicate with each other. The routing and policies must be configured correctly across all three VDOMs.
Which set of configurations is required to enable this access securely?
graph TD subgraph VDOM-A NetA[Customer A Network 10.10.0.0/16] -- port1 --> FGT_A[FortiGate VDOM-A] FGT_A -- vlink0 --> VLINK_A end subgraph VDOM-B NetB[Customer B Network 10.20.0.0/16] -- port2 --> FGT_B[FortiGate VDOM-B] FGT_B -- vlink0 --> VLINK_B end subgraph root VDOM LogServer[Logging Server 192.168.100.10] -- port3 --> FGT_ROOT[FortiGate root VDOM] FGT_ROOT -- vlink1 --> VLINK_A FGT_ROOT -- vlink1 --> VLINK_B endShow answer details
Correct answer: D
This configuration correctly establishes the required bidirectional communication paths while maintaining separation. 1) Each customer VDOM needs a route to the server and a policy to allow traffic out. 2) The root VDOM needs return routes to send traffic back to each customer. 3) Crucially, the root VDOM needs two separate firewall policies (one for each customer VDOM-to-server path). This ensures traffic is explicitly permitted from each customer to the shared resource, and because there is no policy allowing traffic between VLINK_A and VLINK_B, the customers remain isolated from each other.
- 4
A FortiGate is configured with BGP to peer with an ISP. The administrator wants to prevent the FortiGate from advertising certain internal prefixes to the ISP. Which BGP feature should be used to filter outbound route advertisements?
Show answer details
Correct answer: C
To control which routes are advertised to a BGP peer, an outbound route-map is used. The administrator would first define a prefix-list to match the specific internal prefixes to be filtered. Then, a route-map is created that references this prefix-list with a
denyaction. Finally, this route-map is applied in theoutdirection to the BGP neighbor configuration, preventing the matched prefixes from being sent. - 5
A FortiGate is configured for SD-WAN with two member interfaces: port1 (MPLS) and port2 (Internet). An SD-WAN rule is configured to route VoIP traffic, and it uses a Performance SLA that measures jitter. Packet duplication is enabled for this rule. During testing, it is observed that call quality is poor despite both links being up. Analysis shows that the jitter on port2 frequently spikes above the SLA threshold. What is the expected behavior of the FortiGate in this scenario?
Show answer details
Correct answer: A
When packet duplication is enabled, the FortiGate sends copies of packets over multiple member interfaces. However, it still monitors the Performance SLA for each of those members. If a member (port2) fails to meet the SLA criteria (e.g., jitter is too high), the FortiGate will stop sending the duplicated packets over that specific link. It will continue to send the primary stream over the links that are still within the SLA (port1). This prevents the poor-performing link from negatively impacting the application while maintaining the benefit of the healthy link.
- 6
A financial services company is deploying a FortiGate 7000 series chassis in a new datacenter to handle high-frequency trading traffic. A primary requirement is to ensure that session failover between FortiGate Interface Modules (FIMs) is deterministic and that specific high-priority traffic is always processed by a designated FIM unless it fails. The current configuration uses the default session-aware load balancing. Which configuration change is required to meet this requirement?
Show answer details
Correct answer: C
To achieve deterministic session handling and steer specific traffic to a designated FIM, policy-based session affinity is required. The
set affinity-groupcommand within a firewall policy allows an administrator to bind traffic matching that policy to a specific FIM, overriding the default load balancing behavior. This ensures high-priority traffic is handled by the preferred module, providing predictable performance and failover behavior. - 7
A network security architect is designing an ADVPN solution with two hubs in different geographical regions for redundancy. The design requires spokes to dynamically build shortcuts to other spokes, regardless of which hub they are connected to. What is a critical design consideration to ensure seamless spoke-to-spoke communication across both hubs?
Show answer details
Correct answer: D
In a dual-hub ADVPN setup, spokes connected to Hub A need to learn the routes for spokes connected to Hub B to trigger shortcut tunnel creation. The most effective way to achieve this is by establishing an iBGP peering between the two hubs. This allows each hub to share the routes learned from its connected spokes with the other hub, providing all spokes with a complete routing table of the entire ADVPN domain.
- 8
A global retailer is using Fortinet Secure SD-WAN and has configured a performance SLA to monitor latency on its primary MPLS and secondary internet underlay links. The SD-WAN rule is set to prefer MPLS. During a period of network congestion, the latency on the MPLS link exceeds the configured threshold. However, an administrator observes that existing long-lived sessions, such as a large file transfer, do not fail over to the internet link. New sessions correctly use the internet link. What is the most likely reason for this behavior?
Show answer details
Correct answer: C
When
natis enabled on the firewall policy that handles the SD-WAN traffic, existing sessions are tied to the specific NAT IP of the outgoing interface (MPLS in this case). By default, FortiOS will not move an existing, NATed session to a new interface even if the SD-WAN rules dictate a path change. This is to prevent breaking the session, as the source IP would change mid-session. New sessions are not affected and will correctly choose the better-performing link. To allow existing sessions to fail over,set session-snat-route-change enablemust be configured in the system settings. - 9
A security team is implementing Zero Trust Network Access (ZTNA) to provide secure access to an internal web application. They have configured a ZTNA server on the FortiGate, ZTNA connection rules on FortiClient EMS, and a ZTNA policy on the FortiGate. A user reports they can connect to the ZTNA access proxy but receive a 'Permission Denied' error when trying to access the application. The FortiGate logs show the traffic is hitting the ZTNA policy and being denied. What are the two most likely causes of this issue? (Select TWO).
Show answer details
Correct answer: A, C
ZTNA relies on client certificates to cryptographically identify and authenticate the connecting device. If the user's FortiClient does not present a valid certificate that is trusted by the FortiGate ZTNA server, the connection will be denied at the policy level.
ZTNA policies enforce access based on both device identity (certificate) and user identity. If the authenticated user is not part of the user group authorized in the ZTNA policy's source field, the traffic will be denied, resulting in a 'Permission Denied' error.
- 10
True or False: When configuring a FortiGate automation stitch with a FortiAnalyzer event as the trigger, the FortiGate must be configured to send logs to the FortiAnalyzer in real-time mode for the stitch to execute immediately upon event detection.
Show answer details
Correct answer: A
For a FortiGate automation stitch to react promptly to an event detected on FortiAnalyzer (such as a specific log pattern or IOC), the FortiGate must be configured to upload logs in real-time. If logs are sent in store-and-upload mode, there will be a delay between the event occurrence and its detection on FortiAnalyzer, which would prevent the stitch from executing in a timely manner.
