Official Bank 0/47

Fortinet Certified Network Security Professional (FCNSP v4.0) (FCNSP) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
47 Total Questions
1
Question
Refer to the exhibit to view the firewall policy.

Exhibit

Firewall policy configuration Edit Policy Name O Internet_ Access Incoming Interface # port2 Outgoing Interface # port1 + Source © all Destination • all Schedule To always
Service • DNS

• FTP
@ HTTP @ HTTPS Action • ACCEPT © DENY x Proxy-based Inspection Mode Flow based Firewall/Network Options NAT IP Pool Configuration Use Outgoing Interface Address Use Dynamic IP Pool Preserve Source Port O Protocol Options default Security Profiles AntiVirus default Web Filter DNS Filter Why would the firewall policy not block a well-known virus, for example eicar?
Options
A The action on the firewall policy is not set to deny.
B The firewall policy is not configured in proxy-based inspection mode.
C The firewall policy does not apply deep content inspection.
D Web filter is not enabled on the firewall policy to complement the antivirus profile.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibit showing a FortiGuard connection debug output.

Exhibit

Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
Select 2
Options
A One server was contacted to retrieve the contract information.
B There is at least one server that lost packets consecutively.
C FortiGate is using default FortiGuard communication settings.
D A local FortiManaqer is one of the servers FortiGate communicates with.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings.

What is true about the DNS connection to a FortiGuard server?
Options
A It uses UDP 8888.
B It uses DNS over HTTPS.
C It uses UDP 53.
D It uses DNS over TLS.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable the
service on the interface.
In this scenario, what prevents the administrator from enabling DHCP service?
Options
A The role of the interface prevents setting a DHCP server.
B The DHCP server setting is available only on the CLI.
C The FortiGate model does not support the DHCP server.
D Another interface is configured as the only DHCP server on FortiGate.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Refer to the exhibit.

Exhibit

Why did FortiGate drop the packet?
Options
A 11 matched an explicitly configured firewall policy with the action DENY
B It failed the RPF check.
C It matched the default implicit firewall policy
D The next-hop IP address is unreachable.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.