Skip to content

FCSS-NST-SE-7.6 Fortinet FCSS - Network Security 7.6 Support Engineer Practice Questions

Prepare for FCSS-NST-SE-7.6 with more than an answer.

196 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$200 USD
Level
Solution Specialist
Valid for
2 years
Domains covered on the exam 5
  1. System Troubleshooting20%
  2. Authentication20%
  3. Security Profiles20%
  4. Routing20%
  5. VPN20%
  1. 1

    A FortiGate is configured to use a RADIUS server for administrator authentication. An administrator is unable to log in. The output of the debug command diagnose debug application fnbamd -1 shows the RADIUS server sending an Access-Reject message. The administrator is certain the password is correct. Which of the following is a plausible reason for the Access-Reject message in this scenario?

    Show answer details

    Correct answer: C

    An Access-Reject is an explicit reply, so the request reached the server and was evaluated. With correct credentials, the reject comes from the server's policy conditions. RADIUS servers such as NPS can require a specific client or NAS-IP-Address; if the FortiGate sources its requests from another IP (see source-ip in config user radius), the policy doesn't match and the server rejects. The other options would give no reply (no route, wrong port) or don't apply to a RADIUS-authenticated admin (local user status). Use diagnose test authserver radius with diagnose debug application fnbamd -1 to confirm (FortiOS 7.6 Administration Guide - RADIUS servers).

  2. 2

    True or False: When configuring a policy-based static route in FortiOS, if the incoming packet matches the policy route criteria, the FortiGate will bypass the regular FIB (Forwarding Information Base) lookup for that packet.

    Show answer details

    Correct answer: A

    True. Policy-based routing is evaluated before the main routing table (FIB). If a packet's source, destination, protocol, or port matches a configured policy route, the FortiGate will use the gateway specified in that policy route to forward the packet, effectively bypassing the standard destination-based lookup in the FIB.

  3. 3

    After a firmware upgrade to FortiOS 7.6, a FortiGate 100F enters conserve mode. The output of diagnose hardware sysinfo memory shows that Slab (kernel slab) memory is extremely high. Which of the following is a likely cause of high kernel slab memory usage?

    Show answer details

    Correct answer: D

    Slab memory is allocated by the FortiOS kernel for its own data structures. Session-table entries, NAT entries and TCP session data are kept in kernel slab caches, so a very large number of concurrent sessions, such as a SYN flood or a scanning host opening huge numbers of connections, makes slab usage grow. diagnose hardware sysinfo slab then shows the session-related caches at the top. The IPS engine (ipsengine) is a user-space daemon, so its memory counts as process memory, not kernel slab. Reference: Fortinet Community 'How to do initial troubleshooting of high memory utilization issues (conserve mode)'.

  4. 4

    A support engineer is using the packet sniffer on a FortiGate with the command diagnose sniffer packet any 'host 10.1.1.1 and host 8.8.8.8' 4 0 l. What is the purpose of the l argument at the end of this command?

    Show answer details

    Correct answer: D

    In the diagnose sniffer packet command, the final optional argument controls timestamp format. The l argument specifically adds local time timestamps to the output, which is useful for correlating the packet capture with log files that also use the FortiGate's local time.

  5. 5

    An administrator is troubleshooting a dial-up IPsec VPN where remote users are assigned virtual IP addresses from a specific IP pool. One user reports that they are unable to connect. The IKE debug shows that Phase 1 completes successfully, but Phase 2 fails. The logs indicate a NO_PROPOSAL_CHOSEN error during Quick Mode. What is a common cause for this error in a dial-up VPN scenario?

    Show answer details

    Correct answer: B

    NO_PROPOSAL_CHOSEN is returned when the responder finds no acceptable proposal among the transforms the initiator offered (RFC 7296 §3.10.1, and the same notify in IKEv1 Quick Mode). If phase 1 completes but phase 2 fails with this notify for one user, that client's phase 2 encryption/authentication (or PFS/DH group) proposal does not match any proposal in the FortiGate's phase 2 configuration. Selector (proxy ID) mismatches are signalled differently, for example with TS_UNACCEPTABLE in IKEv2. An exhausted IP pool or a NAT setting on the policy does not produce this notify. Source: RFC 7296; FortiOS 7.6 IPsec diagnose commands.

  6. 6

    A network administrator manages an FGCP HA cluster running in Active-Passive mode on FortiOS 7.6. FGT-A has priority 200 and FGT-B has priority 100, and override is disabled on both units. FGT-A, the original primary, rebooted after a power failure and FGT-B took over. Ten minutes after FGT-A rejoined the cluster, get system ha status shows both units are in sync with healthy heartbeats, but FGT-B is still the primary. Which of the following explains this behavior?

    Show answer details

    Correct answer: B

    In FortiOS 7.6 FGCP, with override disabled (the default), primary selection compares connected monitored interfaces first, then HA uptime, then priority, then serial number. An HA uptime difference of more than 300 seconds decides the primary, and a less than 5-minute difference counts as a tie. A unit's HA uptime resets to zero when it restarts or a monitored interface fails. After the original primary recovers, its uptime is lower than the current primary's, so it stays secondary despite its higher priority. Enabling override would make priority be considered before uptime. Session pickup and heartbeat addressing do not affect primary selection. (FortiOS 7.6 Administration Guide: HA primary unit selection criteria.)

  7. 7

    A support engineer is analyzing BGP issues on a FortiGate. The BGP peering session with an ISP is established, and the FortiGate is receiving routes. However, a specific prefix, 198.51.100.0/24, learned from another iBGP peer, is not being advertised to the ISP. The configuration does not include any route maps or prefix lists that would explicitly deny this prefix. What is the most probable reason for this behavior?

    Show answer details

    Correct answer: B

    The BGP synchronization rule states that a BGP router should not advertise a route learned from an iBGP peer to an eBGP peer unless that route is also present in its Interior Gateway Protocol (IGP) routing table (e.g., learned via OSPF or a static route). This is a loop-prevention mechanism. Since the prefix is learned from iBGP and not being advertised to the eBGP peer (ISP), and no explicit filters are in place, synchronization being enabled is the most likely cause. Modern networks typically disable synchronization as full-mesh iBGP or route reflectors are used.

  8. 8

    A user is unable to authenticate to the network via an SSL VPN portal that uses an LDAP server for authentication. The support engineer runs the debug command diagnose debug application fnbamd -1 and observes the error message [fnbamd_ldap_parse_response_page:1320] a_ldap_parse_page_response-Error: 7-Authentication method not supported. What is the most likely cause of this error?

    Show answer details

    Correct answer: B

    The error Authentication method not supported from fnbamd during an LDAP authentication attempt typically indicates a mismatch in the authentication or bind method between the FortiGate and the LDAP server. For example, the FortiGate might be configured for Simple bind when the server requires Regular, or vice-versa. An incorrect password would result in a credentials error, and a certificate issue would cause a TLS handshake failure, not this specific message.

  9. 9

    True or False: In FortiOS 7.6, the diagnose sys top command can be used to identify the process ID (PID) of a specific IPsec VPN tunnel daemon to troubleshoot high CPU usage related to that tunnel.

    Show answer details

    Correct answer: B

    False. IPsec VPN tunnel processing is handled by the iked daemon for control plane (IKE negotiations) and the kernel (ksoftirqd) for data plane (encryption/decryption). While diagnose sys top can show high CPU usage from these processes, it does not break down the usage per individual tunnel. To troubleshoot a specific tunnel's performance, you would need to use other tools like diagnose vpn tunnel list and specific debugs, not diagnose sys top for a per-tunnel PID.

  10. 10

    A company has a Security Fabric with a root FortiGate 601F and a downstream FortiGate 60F, both running FortiOS 7.6. The administrator notices that the Security Rating score on the root FortiGate is not updating with data from the 60F. Connectivity between the devices is confirmed, and other Fabric features are working. Which of the following is the most likely reason for this issue?

    Show answer details

    Correct answer: B

    In FortiOS 7.6, to improve stability and performance on entry-level models, features like Security Rating and Topology visibility are disabled on FortiGates with 2GB of RAM or less. The FortiGate 60F falls into this category. Therefore, it will not run Security Rating checks or send results to the root FortiGate, explaining the missing data.

Create an account to continue.