About the Exam

This exam is part of Fortinet's FCP Security Operations track and evaluates FortiSandbox administration, including configuration, operation, incident analysis, integration with FortiGate, FortiMail, FortiWeb, FortiClient EMS, and third-party products, plus troubleshooting. It is designed for network and security professionals responsible for designing, implementing, and maintaining a FortiSandbox-based advanced threat protection solution. Passing demonstrates practical knowledge of FortiSandbox 5.0 administration.

Exam Topics

  • SOC and SOAR Overview0%
  • System Configuration0%
  • Security Management0%
  • System Operation0%
  • System Monitoring and Maintenance0%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 26, 2026 at 11:50 PM

Topic filter
Retired questions
Question sort

QuestionQ1

System Configuration

You are asked to create custom VMs to better represent your security environment.

In which two FortiSandbox deployments is this supported?

Choose two
  • A Private cloud
  • B Azure non-nested mode
  • C Device-based
  • D FortiSandbox Cloud
Explanation

FortiSandbox supports creating custom VMs on appliance-based (device-based) and private-cloud deployments. The feature is not supported on Azure non-nested deployments or FortiSandbox Cloud.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

System Configuration

Which two statements are accurate about creating an API interface?

Choose two
  • A Ports configured for HA communication can also be configured as API ports.
  • B API ports will not accept HTTP traffic.
  • C The configuration must be performed using the CLI.
  • D The interface must also be designated as an administrative interface.
Explanation

A FortiSandbox API interface accepts API access only through HTTPS; HTTP access is not permitted. Configuring or removing an API port is a CLI-only operation. An API port cannot also be configured as an HA port or an administrative port.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Security Management

Which Cyber Kill Chain stage does the integration of FortiSandbox and FortiClient EMS help block?

  • A Delivery
  • B Weaponization
  • C Reconnaissance
  • D Command and control
Explanation

FortiClient can submit files downloaded from email, the internet, removable media, or mapped drives to FortiSandbox, and can block access until the sandbox verdict is returned. This stops malicious payloads as they are delivered to the endpoint, before they can execute, which corresponds to the Delivery stage.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

System Monitoring and Maintenance

When using SIMNET, which two inspections cannot be carried out using real traffic?

Choose two
  • A AV inspection
  • B Dynamic scan
  • C IP reputation
  • D URL rating
Explanation

SIMNET substitutes simulated network-service responses when a FortiSandbox VM has no external-network access. It therefore cannot perform antivirus inspection on an actually downloaded file or determine the reputation of the real IP address used for a callback connection. Dynamic behavioral scanning and URL rating remain available. Fortinet documents that SIMNET starts when VM Internet access is unavailable and is not a real Internet connection.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

System Configuration

You need to increase a FortiSandbox device’s scanning capacity by raising the number of clones, but the FortiSandox local clone limit is already at its maximum.

Which two actions can you take to expand the unit’s scanning capacity?

Choose two
  • A Deploy remote WindowsCloudVM and MACOSX clones
  • B Reorganize the scan priority list
  • C Add custom VMs
  • D Add VM licenses to FortiSandbox
Explanation

FortiSandbox can expand scan power beyond the local clone limit by purchasing additional VM Clone subscriptions and enabling remote WindowsCloudVM and MACOSX clones. Custom VMs still consume the local clone quota, while scan-priority changes only affect scheduling.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
SOC and SOAR OverviewSystem ConfigurationSecurity ManagementSystem OperationSystem Monitoring and Maintenance
Know a question that should be here? Contribute to this exam
Back home