Exam Details

  • Exam Code
    :FCNSA.V5
  • Exam Name
    :Fortinet Certified Network Security Administrator (FCNSA.v5)
  • Certification
    :Fortinet Certification
  • Vendor
    :Fortinet
  • Total Questions
    :119 Q&As
  • Last Updated
    :May 15, 2024

Fortinet Fortinet Certification FCNSA.V5 Questions & Answers

  • Question 21:

    The command structure of the FortiGate CLI consists of commands, objects, branches, tables, and parameters. Which of the following items describes user?

    A. A command.

    B. An object.

    C. A table.

    D. A parameter.

  • Question 22:

    The command structure of the CLI on a FortiGate unit consists of commands, objects, branches, tables and parameters.

    Which of the following items describes port1?

    A. A command.

    B. An object.

    C. A table.

    D. A parameter.

  • Question 23:

    Each UTM feature has configurable UTM objects such as sensors, profiles or lists that define how the feature will function.

    An administrator must assign a set of UTM features to a group of users.

    Which of the following is the correct method for doing this?

    A. Enable a set of unique UTM features under "Edit User Group".

    B. The administrator must enable the UTM features in an identify-based policy applicable to the user group.

    C. When defining the UTM objects, the administrator must list the user groups which will use the UTM object.

    D. The administrator must apply the UTM features directly to a user object.

  • Question 24:

    The ordering of firewall policies is very important. Policies can be re-ordered within the FortiG- ate Web Config and also using the CLI. The command used in the CLI to perform this function is __________.

    A. set order

    B. edit policy

    C. reorder

    D. move

  • Question 25:

    Which of the following network protocols can be used to access a FortiGate unit as an adminis- trator?

    A. HTTPS, HTTP, SSH, TELNET, PING, SNMP

    B. FTP, HTTPS, NNTP, TCP, WINS

    C. HTTP, NNTP, SMTP, DHCP

    D. Telnet, FTP, RLOGIN, HTTP, HTTPS, DDNS

    E. Telnet, UDP, NNTP, SMTP

  • Question 26:

    Which of the following statements is correct regarding a FortiGate unit operating in NAT/Route mode?

    A. The FortiGate unit requires only a single IP address for receiving updates and configuring from a management computer.

    B. The FortiGate unit must use public IP addresses on both the internal and external networks.

    C. The FortiGate unit commonly uses private IP addresses on the internal network but hides them using rk address translation.

    D. The FortiGate unit uses only DHCP-assigned IP addresses on the internal network.

  • Question 27:

    Which of the following statements correctly describes how a FortiGate unit functions in Trans- parent mode?

    A. To manage the FortiGate unit, one of the interfaces must be designated as the management in-terface. This interface may not be used for forwarding data.

    B. An IP address is used to manage the FortiGate unit but this IP address is not associated with a specific interface.

    C. The FortiGate unit must use public IP addresses on the internal and external networks.

    D. The FortiGate unit uses private IP addresses on the internal network but hides them using ad- dress translation.

  • Question 28:

    The Idle Timeout setting on a FortiGate unit applies to which of the following?

    A. Web browsing

    B. FTP connections

    C. User authentication

    D. Administrator access

    E. Web filtering overrides.

  • Question 29:

    You wish to create a firewall policy that applies only to traffic intended for your web server. The server has an IP address of 192.168.2.2 and belongs to a class C subnet. When defining the fire- wall address for use in this policy, which one of the following addressing formats is correct?

    A. 192.168.2.0 / 255.255.255.0

    B. 192.168.2.2 / 255.255.255.0

    C. 192.168.2.0 / 255.255.255.255

    D. 192.168.2.2 / 255.255.255.255

  • Question 30:

    If a FortiGate unit has a dmz interface IP address of 210.192.168.2 with a subnet mask of 255.255.255.0, what is a valid dmz DHCP addressing range?

    A. 172.168.0.1 - 172.168.0.10

    B. 210.192.168.3 - 210.192.168.10

    C. 210.192.168.1 - 210.192.168.4

    D. All of the above.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your FCNSA.V5 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.