Official Bank 0/47

Fortinet Certified Network Security Professional (FCNSP) - Fortinet Actual Exam Questions

Last updated on April 25, 2026

97% Exam Compliance
47 Total Questions
1
Question

Refer to the exhibits, which show the system performance output and the default configuration of high memory usage thresholds in a FortiGate. Based on the system performance output, what can be the two possible outcomes? (Choose two.)

Question image Question image
Select 2
Options
A

FortiGate will start sending all files to FortiSandbox for inspection.

B

FortiGate has entered conserve mode.

C

Administrators cannot change the configuration.

D

Administrators can access FortiGate onlythrough the console port.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

What are two features of collector agent advanced mode? (Choose two.)

Select 2
Options
A

In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.

B

Advanced mode supports nested or inherited groups.

C

In advanced mode, security profiles can be applied only to user groups, not individual users.

D

Advanced mode uses the Windows convention —NetBios: Domain\Username.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet. Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.)

Question image Question image Question image
Select 2
Options
A

In the firewall policy configuration, add 10. o. l. 3 as an address object in the source field.

B

In the IP pool configuration, set endig to 192.2.0.12.

C

Configure another firewall policy that matches only the address of PC3 as source, and then place the policy on top of the list.

D

In the IP pool configuration, set cype to overload.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

Refer to the exhibit to view the firewall policy. Why would the firewall policy not block a well-known virus, for example eicar?

Question image
Options
A

The action on the firewall policy is not set to deny.

B

The firewall policy is not configured in proxy-based inspection mode.

C

Web filter is not enabled on the firewall policy to complement the antivirus profile.

D

The firewall policy does not apply deep content inspection.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

Refer to the exhibit, which shows a partial configuration from the remote authentication server. Why does the FortiGate administrator need this configuration?

Question image
Options
A

To authenticate only the Training user group.

B

To set up a RADIUS server Secret

C

To authenticate and match the Training OU on the RADIUS server.

D

To authenticate Any FortiGate user groups.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.