Official Bank 0/15

FortiDDoS 4.0 Specialist (FortiDDoS) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
15 Total Questions
1
Question
As the exhibit shows, a FortiDDoS port2 is connected to the protected server. Its port1 is connected to the Internet. The FortiDDoS has 8 interfaces for user traffic. The exhibit also shows a screenshot of the unit dashboard.

Exhibit

Exhibit

The administrator noticed that the statistics are showing all the traffic coming from the Internet to the protected server as outbound, instead of inbound. Based on the exhibit, what is the cause of this mislabeling?
Options
A SPP 0 is operating in detection mode.
B The SPP 0 link is down.
C The protected server is connected to a wrong FortiDDoS interface. It must be connected to an interface from port 5 to port 8.
D FortiDDoS interfaces are wrongly connected. The interface port1 must be connected to the protected server and port2 must be connected to the Internet.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A FortiDDoS device is connected between a protected server and an Internet router. For the
Reveal Only
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Regarding the switching SPP feature, what is used to determine when FortiDDoS switches the traffic to an alternate SPP?
Options
A Destination IP addresses
B Mitigated attacks
C Traffic volume
D Blocked packets
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Which of the following events can make FortiDDoS drop packets? (Choose two.)
Select 2
Options
A Packets match an access list with action deny.
B One direction of the traffic is crossing the FortiDDoS, but the other direction is not (asymmetric routing).
C SPPs are working in detection mode.
D A violation of the TCP protocol in a TCP session.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A FortiDDoS device is configured to mitigate SYN flood attacks using the SYN cookie mode. What action does it take when it is mitigating an SYN flood attack and a SYN packet from a new source IP address arrives?
Options
A It replies with a SYN/ACK packets. One containing the right acknowledge value, the other one with a wrong acknowledge value.
B It replies with a RST packet if the SYN packet does not contain the right cookie in the sequence field.
C It replies with a SYN/ACK packet containing a cookie value in the TCP sequence field.
D It replies with a SYN/ACK packet containing a cookie value in the TCP acknowledge field.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.