Twenty-five questions on the whole course, using the course lab: FGT1 with port1 (WAN, 203.0.113.2), port2 (LAN 10.0.1.0/24) and port3 (DMZ, WEB1 at 10.0.2.10). If you get one wrong, the explanation names the lesson to go back to.
1. In an address group with members SRV1 and SRV2, which command adds SRV3 without removing the others?
2. Which setting stops strangers on the Internet reaching FGT1's login page on port1?
3. Two interfaces are in a zone with default settings. Can hosts on one reach hosts on the other?
4. An accept policy for all LAN web traffic is at sequence 2; a deny for a gambling site is at sequence 5. Is the site blocked?
5. Debug flow shows "Denied by forward policy check (policy 0)". What does it mean?
6. PC1 matches the LAN-to-Internet policy, but web pages never load, and the session shows act=noop with no translated address. What is missing?
7. A policy has nat enable and set poolname, but users still appear as the interface address. What is missing?
8. In policy NAT mode, what is the destination of the policy that allows Internet users to a VIP?
9. The DMZ policy for a VIP has outgoing interface port1. Why does it never match?
10. Two default routes: port1 distance 10, port4 distance 20. Both links are up. Which is in the routing table?
11. Debug flow shows "reverse path check fail, drop" for a packet arriving on port2 from 172.16.9.5. What is wrong?
12. In which order does FortiOS look for a path for a new session?
13. An SD-WAN rule uses Lowest Cost (SLA) preferring port1, then port4. port1 is up but misses the SLA. Where do new matching sessions go?
14. A policy has source LAN-subnet and user group Staff. A user not in Staff logs in from 10.0.1.40. Does the policy match?
15. Users never see the captive portal when opening websites. What is most likely missing?
16. Which IKE phase agrees the subnets a tunnel protects?
17. IKE debug shows a successful SA_INIT, then AUTHENTICATION_FAILED. What do you check?
18. A route-based tunnel is up. HQ can reach the branch, but sessions started at the branch fail at FGT1. What is missing on FGT1?
19. Why add a blackhole route with distance 254 for the branch subnet?
20. Which phase 1 setting lets remote users connect from unknown addresses?
21. Antivirus is on, SSL inspection is certificate-inspection. Is malware in an HTTPS download caught?
22. After enabling deep inspection, every HTTPS site shows a certificate warning. Why?
23. Gambling is blocked by category, but a static URL filter entry exempts casino.example. Can users open it?
24. HA with override disabled: the higher-priority unit reboots and returns while the other has been primary. Who is primary afterwards?
25. A small FortiGate without a disk shows no logs from before last night's reboot. What should be configured?