Fortinet NSE 7 Cloud Security 6.0 Exam
Question 1 Which of the following is the primary function of a firewall policy on a FortiGate?
- To determine password strength requirements
- To filter and control network traffic based on specific criteria
- To provide automatic firmware updates
- To manage user device registration
Answer: B
Explanation: Firewall policies are used to inspect, filter, and control traffic, determining which traffic is allowed or blocked based on rules.
Question 2 When defining a firewall policy, which element specifies the kind of network service or protocol inspected?
- NAT configuration
- Schedule
- Service
- Session timeout
Answer: C
Explanation: The Service field designates the protocol or application (e.g., HTTP, HTTPS, SSH) that a firewall policy will handle.
- / 4
Fortinet NSE 7 Cloud Security 6.0 Exam
Question 3 FortiGate processes firewall policies in which of the following orders?
- By interface name
- From most specific to least specific
- From highest to lowest policy ID
- Top to bottom based on the policy list
Answer: D
Explanation: FortiGate examines firewall policies from the top of the policy list downward until it finds a match.
Question 4 You have created a new firewall policy that uses a security profile for web filtering. What must be enabled in the policy to effectively log blocked website categories?
- Session tracking
- Log all sessions
- SSL offloading
- Identity-based access
Answer: B
Explanation: To see logs of blocked web activities, you must enable at least “Log Allowed and Blocked Traffic” or “Log All Sessions” within the policy.
- / 4
Fortinet NSE 7 Cloud Security 6.0 Exam
Question 5 What happens if no firewall policy matches the traffic flow on a FortiGate device?
- The default policy automatically allows all traffic
- The traffic is blocked by the implicit deny policy
- Traffic is rerouted to the next available interface
- It triggers an alert without denying the traffic
Answer: B
Explanation: If no firewall policy matches, FortiGate enforces an implicit deny, dropping the traffic by default.
Question 6 A FortiGate administrator needs to create a firewall policy that allows traffic only during business hours. Which parameter helps achieve this?
- Log settings
- Authentication scheme
- Schedule
- Application control
Answer: C
Explanation: The Schedule parameter lets you define the time window during which the policy is active.
- / 4
Fortinet NSE 7 Cloud Security 6.0 Exam
Question 7 Which firewall policy action will allow traffic through the FortiGate but not record any logs of the sessions?
- Accept with no security profiles
- Accept with logging disabled
- Deny action
- IPsec encryption
Answer: B
Explanation: An Accept action combined with logging disabled will allow traffic without generating logs.
Question 8 What is the main advantage of using identity-based policies in a FortiGate firewall?
- Simplifies SNMP trap configuration
- Applies security controls based on username or user group
- Eliminates the need for password management
- Increases bandwidth for authenticated users
Answer: B
Explanation: Identity-based policies let you enforce policies by user or group membership, enhancing granular control.
- / 4