NSE8 Fortinet Certified Expert (FCX) - Cybersecurity Practice Questions
Prepare for NSE8 with more than an answer.
- Level
- Expert
- Valid for
- 3 years from completion
Domains covered on the exam 7
- Security Architecture
- Infrastructure
- Networking
- Secure SD-WAN
- Security Solutions
- Security Operations
- Automation
- 1
An administrator needs to deploy a security solution that can detect zero-day malware embedded in files downloaded by users and in email attachments. The solution must analyze files in a contained environment and share the threat intelligence with the rest of the Security Fabric. Which Fortinet product is primarily designed for this purpose?
Show answer details
Correct answer: C
FortiSandbox is Fortinet's Advanced Threat Protection (ATP) solution. Its core function is to receive files from other Security Fabric devices (like FortiGate and FortiMail), execute them in a secure, virtualized environment (a sandbox), and analyze their behavior to detect previously unknown, zero-day threats. Once a threat is identified, it shares this intelligence back to the fabric to block the threat everywhere.
- 2
True or False: When using the FortiGate Auto-Script feature, scripts are executed only once at system boot-up and cannot be triggered by other events.
Show answer details
Correct answer: B
False. While FortiGate Auto-Script can be configured to run at startup, it can also be configured with a repeat interval, allowing it to execute periodically. Furthermore, it can be called as an action within an automation stitch, meaning it can be triggered by a wide variety of system events (e.g., an interface going down, high CPU, or an IPS detection).
- 3
A company is designing a BGP solution between their data center FortiGate and a public cloud provider. They need to ensure that if the primary link fails, traffic fails over to a backup link. The FortiGate receives the same prefixes from the cloud provider over both links. Which BGP attribute should be manipulated on the FortiGate's inbound route maps to consistently prefer the primary link?
Show answer details
Correct answer: C
Local Preference is the BGP attribute designed to influence outbound traffic path selection within a single Autonomous System (AS). By setting a higher Local Preference value (default is 100) on the routes received via the primary link, the FortiGate will always prefer that path. This is the standard and most effective method for this use case.
- 4
Which three of the following are valid actions that can be configured in a FortiGate automation stitch? (Select THREE).
Show answer details
Correct answer: A, C, E
- 5
An architect is deploying a FortiGate solution with full SSL deep inspection. To avoid certificate errors on client browsers, the FortiGate's CA certificate must be trusted by all endpoints. The organization uses Microsoft Active Directory and Group Policy. What is the most efficient and scalable method to distribute the FortiGate's CA certificate to all domain-joined Windows clients?
Show answer details
Correct answer: C
For domain-joined Windows environments, using Active Directory Group Policy is the standard and most efficient method. An administrator can create a GPO that imports the FortiGate's CA certificate into the 'Trusted Root Certification Authorities' store on all computers within the targeted Organizational Unit (OU). This ensures seamless and scalable deployment without any user interaction.
- 6
A financial services company is deploying a FortiGate HA cluster in active-passive mode between two data centers using a stretched VLAN for the HA heartbeat. During a network event, administrators observe that both FortiGates temporarily become master, creating a split-brain scenario. Which FortiOS HA setting is specifically designed to mitigate this condition by allowing a master to shut down monitored interfaces on the secondary unit if it fails to receive heartbeats?
Show answer details
Correct answer: B
The
set link-failed-signal enablecommand is specifically designed to prevent split-brain scenarios in HA clusters, particularly those with remote links. When enabled on the master unit, if it stops receiving heartbeats from the slave, it sends a link-failed signal. This signal instructs the slave unit to shut down its monitored interfaces, preventing it from incorrectly taking over the master role and causing a network outage. - 7
An architect is designing a secure SD-WAN solution for a retail company with 200 branches. Each branch has one MPLS link and one broadband internet link. The primary requirement is that real-time Point of Sale (POS) traffic must always be sent over both links simultaneously to ensure zero packet loss, even if one link experiences intermittent degradation. All other traffic should fail over based on link quality. Which SD-WAN feature must be configured to meet the requirement for the POS traffic?
Show answer details
Correct answer: B
Forward Error Correction (FEC) is the feature designed for this exact use case. It sends redundant packets (either always or based on packet loss) over a secondary link to reconstruct any lost packets on the primary link. For the most critical traffic like POS, setting the FEC to 'always' ensures packet duplication, providing the highest level of resiliency against packet loss.
- 8
A security engineer has created an automation stitch to block suspicious source IPs that trigger a specific IPS signature. The stitch is configured with a trigger for 'IPS Signature' and an action to add the source IP to an address group used in a deny policy. However, the stitch is not working as expected. During troubleshooting, the engineer observes that the trigger event is generated correctly in the logs. Which TWO of the following configuration issues could be the cause of the failure? (Select TWO).
Show answer details
Correct answer: A, D
- 9
True or False: When configuring BGP route redistribution into OSPF on a FortiGate, the
redistribute bgpcommand underrouter ospfis sufficient to advertise BGP routes to OSPF neighbors without any additional route maps or filters.Show answer details
Correct answer: A
True. Unlike some other vendors that require a route-map for redistribution even if no filtering is intended, FortiOS allows the simple
redistribute bgpcommand to advertise all learned BGP routes into OSPF. Route maps are optional and are only required if you need to filter or modify the attributes of the routes being redistributed. - 10
A systems administrator is configuring a FortiGate to act as a SAML Service Provider (SP) for administrative access. The Identity Provider (IdP) is a third-party service. After configuring the SAML settings, authentication fails. The SAML debug output indicates a
SubjectNotOnOrAftererror. What is the most likely cause of this issue?Show answer details
Correct answer: D
The
SubjectNotOnOrAftercondition in a SAML assertion defines the expiration time for the assertion's validity. If the Service Provider's (FortiGate's) clock is ahead of the Identity Provider's clock, it may evaluate the assertion as already expired upon receipt. This is a classic symptom of a clock skew or NTP synchronization issue between the two systems.
