About the Exam

This exam evaluates knowledge of Fortinet solutions in enterprise security infrastructure environments. It tests applied skills in integration, administration, troubleshooting, and central management of an enterprise firewall solution using FortiOS 7.6, FortiManager 7.6, and FortiAnalyzer 7.6. It is intended for network and security professionals responsible for designing, administering, and supporting enterprise security infrastructure built around many FortiGate devices. Fortinet lists the exam as discontinued, with last delivery on July 15, 2026.

Exam Topics

  • System configuration20–25%
  • Central management10–15%
  • Security profiles25–30%
  • Routing15–20%
  • VPN20–25%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated March 26, 2026 at 8:32 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Routing

Refer to the exhibit. An enterprise network that is connected to an ISP is shown.

Question Image

You must configure a loopback as the BGP source for connecting to the ISP.

Which two commands must be used to establish the connection?

Choose two
  • A ibgp-enfогсе-multihop
  • B ebgp-enfоrce-multihop
  • C recursive-next-hop
  • D update-source
Explanation

An eBGP session sourced from a loopback interface must use update-source to select that loopback as the source of the BGP TCP connection. It must also enable ebgp-enforce-multihop, because eBGP normally expects a directly connected peer and the loopback-based peer is reached across one or more routed hops.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Security profiles

To protect your enterprise network traffic, which action does FortiGate perform first when processing the initial packets of a session?

  • A Decryption
  • B Installation of the session key in the network processor (NP)
  • C A reverse path forwarding (RPF) check
  • D IP integrity header checking
Explanation

FortiGate performs IP integrity header checking during early ingress processing to validate the packet’s protocol-header length. IPsec decryption occurs after this check, and an NP session key is installed only after an eligible session is established for fast-path offloading. Fortinet: Parallel Path Processing

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Routing

In which two ways does FortiGate utilize the Internet Service Database (ISDB) in firewall policies and SD-WAN rules?

Choose two
  • A The ISDB works in proxy mode, allowing the analysis of packets in layers 3 and 4 of the OSI model.
  • B The ISDB blocks the IP addresses and ports of an application predefined by FortiGuard.
  • C The ISDB limits access by URL and domain.
  • D FortiGate has a predefined list of all IP addresses and ports for specific applications downloaded from FortiGuard.
Explanation

The ISDB is populated from FortiGuard data and defines Internet services using public IP address ranges and service port information. Firewall policies and SD-WAN rules can use those predefined service entries as matching criteria; a firewall policy configured with a deny action blocks traffic that matches the selected service. URL and domain restrictions are web-filtering functions, not ISDB functions, and ISDB matching is not a proxy-mode feature. Fortinet documents ISDB as a FortiGuard-sourced database that combines IP ranges, service port numbers, and related service information.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

You want to deploy ADVPN efficiently across the enterprise network.

Which two approaches can help enable this deployment?

Choose two
  • A On FortiGate, utilize loopback interfaces to reduce the number of routes and peers.
  • B On FortiManager, enable ADVPN on VPN Manager.
  • C On FortiGate, connect only the links with the best status.
  • D FortiManager, activate the recommended IPsec tunnel provisioning templates and enable ADVPN.
Explanation

BGP on loopback interfaces gives each SD-WAN/ADVPN node a stable identifier and lets a spoke establish one iBGP session per hub, which significantly reduces advertised routes and peer complexity. FortiManager recommended IPsec templates standardize scalable tunnel provisioning; after activation, the relevant templates provide an option to enable ADVPN.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

System configuration

Refer to the exhibit.

Question Image

An HA configuration for an active-active (A-A) cluster with the same HA uptime is shown. You want HQ-NGFW-2 to handle the Core2 VDOM traffic.

Which modification must you make to accomplish this?

  • A Enable override in virtual duster 2 for HQ-NGFW-2.
  • B Change the priority from 120 to 200 for HQ-NGFW-2.
  • C Change the priority from 100 to 160 for HQ-NGFW-2.
  • D Reboot HQ-NGFW-2.
Explanation

Core2 is assigned to virtual cluster 2. HQ-NGFW-2 must have the higher virtual-cluster-2 priority to become the primary unit processing that VDOM’s traffic. Raising its virtual-cluster-2 priority from 120 to 200 makes it higher than HQ-NGFW-1’s priority of 150. With HA uptime tied, the priority value determines the election at that criterion.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home