FORTISANDBOX Practice Questions
Prepare for FORTISANDBOX with more than an answer.
- Exam fee
- $400 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 4
- Deployment and System Settings30%
- Scanning and Rating Components35%
- Integrations25%
- Results Analysis and Reporting10%
- 1
The two-stage analysis process in FortiSandbox is designed to optimize performance and detection efficacy. What is the correct flow of this process for a file that is determined to be malicious by the second stage?
Show answer details
Correct answer: B
The correct flow is: The file first passes through pre-filters (AV scan, hash checks). If not definitively clean or malicious, it undergoes the high-speed Static AI Scan. If the static scan cannot determine the file is clean, it is passed to the second stage, Dynamic VM Analysis. The file is executed in a VM, and its behavior is traced. The combined results from both stages are sent to the Rating Engine, which then issues the final verdict.
- 2
A FortiSandbox is configured in Sniffer Mode, but the dashboard shows no files being captured or analyzed. An administrator uses the
diagnose sniffer packetcommand and sees traffic from the correct VLAN. They have also confirmed the sniffer interface is up and the policy is enabled. Which of the following is the most likely cause for the issue?Show answer details
Correct answer: B
In Sniffer Mode, even if the interface is receiving packets from a SPAN port, the FortiSandbox must be explicitly configured to inspect the application-layer protocols over which files are transferred (like HTTP, FTP, SMTP, IMAP, POP3, SMB). If the relevant protocols are not enabled in the sniffer policy, the appliance will see the traffic but will not parse it to extract and analyze files, resulting in a zero file count.
- 3
Which statement accurately describes the 'URL Sandboxing' feature when FortiSandbox is integrated with FortiGate?
Show answer details
Correct answer: D
URL Sandboxing involves FortiSandbox launching a browser within a secure guest VM to visit the submitted URL. It monitors the entire session for malicious activities such as browser exploit attempts, malicious redirects, or drive-by downloads. If a file is downloaded as a result of visiting the URL, that file is then subjected to the standard two-stage file analysis process.
- 4
When reviewing a FortiSandbox analysis report, what does the 'Code Analysis' section primarily provide?
Show answer details
Correct answer: C
The 'Code Analysis' section of the report contains the findings from the static analysis stage. This includes information extracted from the file without executing it, such as its PE header information, imported libraries and functions (which can indicate capabilities), embedded strings that might reveal C2 servers or commands, and other structural characteristics.
- 5
A security consultant is reviewing the architecture of a FortiSandbox deployment. The current setup is shown below. The goal is to ensure that files downloaded by users in the Internal Network are scanned by the FortiSandbox before reaching the workstations.
Which change to the architecture is required for the FortiSandbox to receive files for analysis from the FortiGate?
graph TD Internet((Internet)) --> FG[FortiGate] FG --> Switch[Core Switch] Switch --> Workstations[Workstations] Switch --> FSA[FortiSandbox]Show answer details
Correct answer: B
The physical topology shown is correct for an out-of-band deployment. The missing piece is the logical integration. A Security Fabric connector must be configured on the FortiGate, pointing to the FortiSandbox's IP address. This enables the FortiGate to send files to the FortiSandbox for analysis over the network. No physical re-cabling is necessary.
graph TD Internet((Internet)) --> FG[FortiGate] FG --> Switch[Core Switch] Switch --> Workstations[Workstations] Switch --> FSA[FortiSandbox] FG -.->|Security Fabric Connector| FSA - 6
A financial services company is experiencing performance degradation on their FortiSandbox 2000F appliance after enabling analysis for a new branch office, which significantly increased the volume of submitted Microsoft Office documents. The job queue is consistently high, and analysis times have tripled. The administrator has already confirmed that the hardware is not bottlenecked. Which configuration change would most effectively alleviate the high job queue and improve processing throughput for this specific file type?
Show answer details
Correct answer: B
Enabling 'Static Scan Only' for trusted or high-volume file types like Microsoft Office documents leverages the high-speed static AI engine, which can process files much faster than dynamic VM analysis. This significantly reduces the load on the VM resources and clears the job queue more efficiently without completely bypassing analysis. Increasing concurrent VMs would help but could lead to resource contention and doesn't address the root cause as effectively as offloading to the faster static scan engine.
- 7
A security analyst is investigating a malware sample that successfully exfiltrated data. The FortiSandbox report provides a detailed breakdown of the malware's behavior, which is mapped to the MITRE ATT&CK framework. The report notes the following key actions:
- The malware created a new service to run at startup.
- The malware connected to a command-and-control server over port 443.
- The malware captured screenshots of the user's desktop.
Which MITRE ATT&CK tactics are directly represented by these three actions? (Select THREE)
Show answer details
Correct answer: A, B, D
Creating a new service to run at startup is a classic example of the Persistence tactic (T1543.003 - Create or Modify System Process: Windows Service), allowing the malware to survive reboots.
Connecting to a C2 server over a common port like 443 is a core behavior of the Command and Control tactic (T1071 - Application Layer Protocol), used to receive instructions and exfiltrate data.
Capturing screenshots (T1113 - Screen Capture) is a method used to gather information from the victim's system, which falls under the Collection tactic.
- 8
During the initial setup of a FortiSandbox appliance, an administrator configures the network interfaces, system time, and DNS settings. However, the appliance is unable to download updated guest VM images from the FortiGuard Distribution Network (FDN). The administrator has verified that the appliance has a valid license and can ping public IP addresses. What is the most likely cause of this issue?
Show answer details
Correct answer: D
Even if the administrator has configured the system time, if it is significantly out of sync with the actual time, SSL certificate validation will fail when the FortiSandbox attempts to connect to the FDN over HTTPS. This is a common and often overlooked issue. Since the device can ping public IPs, basic network connectivity is confirmed, pointing towards a higher-level protocol issue like SSL/TLS.
- 9
A security architect is designing an integration between a third-party Security Orchestration, Automation, and Response (SOAR) platform and FortiSandbox. The goal is for the SOAR platform to programmatically submit suspicious files, check the analysis status, and retrieve the full PDF report upon completion. Which sequence of API calls is required to accomplish this workflow?
Show answer details
Correct answer: C
The correct workflow is: First, upload the file using a POST request to the
/scan/upload/fileendpoint, which returns ajob_id. Second, periodically poll the/scan/result/job/{job_id}endpoint to check the analysis status until it is complete. Once complete, the result will contain the file's SHA256 hash. Third, use the SHA256 hash to retrieve the final PDF report with a GET request to/scan/report/pdf/{sha256}. - 10
True or False: In a FortiSandbox High Availability (HA) cluster, the primary unit handles all file analysis, while the secondary unit only synchronizes configuration and remains in a passive state until a failover event.
Show answer details
Correct answer: A
This statement is true. FortiSandbox HA operates in an active-passive mode. The primary (master) unit is responsible for all network traffic, file submissions, and analysis. The secondary (slave) unit receives configuration and state synchronization data from the primary but does not perform any analysis tasks itself until it takes over as the primary during a failover.
