Fortinet Certified Network Security Professional (FCNSP v4.2) Sample Questions:
1. Examine the Exhibit shown below; then answer the question following it.
In this scenario, the Fortigate unit in Ottawa has the following routing table: S* 0.0.0.0/0 [10/0] via 172.20.170.254, port2 C 172.20.167.0/24 is directly connected, port1 C 172.20.170.0/24 is directly connected, port2
Sniffer tests show that packets sent from the Source IP address 172.20.168.2 to the Destination IP address 172.20.169.2 are being dropped by the FortiGate unit located in Ottawa. Which of the following correctly describes the cause for the dropped packets?
A) The reverse path forwarding check.
B) The subnet 172.20.169.0/24 is NOT in the Ottawa FortiGate unit's routing table.
C) The forward policy check.
D) The destination workstation 172.20.169.2 does NOT have the subnet 172.20.168.0/24 in its routing table.
2. What advantages are there in using a hub-and-spoke IPSec VPN configuration instead of a fully-meshed set of IPSec tunnels? (Select all that apply.)
A) Using a hub and spoke topology is required to achieve full redundancy.
B) Using a hub and spoke topology provides stronger encryption.
C) Using a hub and spoke topology reduces the number of tunnels.
D) Using a hub and spoke topology simplifies configuration.
3. In HA, what is the effect of the Disconnect Cluster Member command as given in the Exhibit.
A) The Firewall rules are purged on the disconnected unit.
B) All other interface IP settings are maintained.
C) The HA mode changes to standalone.
D) Port3 is configured with an IP address for management access.
4. When configuring a server load balanced virtual IP, which of the following is the best distribution algorithm to be used in applications where the same physical destination server must be maintained between sessions?
A) Round robin
B) Static
C) Weighted round robin
D) Least connected
5. Shown below is a section of output from the debug command diag ip arp list.
index=2 ifname=port1 172.20.187.150 00:09:0f:69:03:7e state=00000004 use=4589 confirm=4589 update=2422 ref=1
In the output provided, which of the following best describes the IP address 172.20.187.150?
A) It is one of the secondary IP addresses of the port1 interface.
B) It is the IP address of another network device located in the same LAN segment as the FortiGate unit's port1 interface.
C) It is the primary IP address of the port1 interface.
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C,D | Question # 3 Answer: C,D | Question # 4 Answer: B | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Lionel

