Fortinet NSE5 Exam Practice Questions (P. 1)
- Full Access (313 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
An administrator wants to assign a set of UTM features to a group of users. Which of the following is the correct method for doing this?
- AEnable a set of unique UTM profiles under "Edit User Group".
- BThe administrator must enable the UTM profiles in an identity-based policy applicable to the user group.
- CWhen defining the UTM objects, the administrator must list the user groups which will use the UTM object.
- DThe administrator must apply the UTM features directly to a user object.
Correct Answer:
B
B
send
light_mode
delete
Question #2
When firewall policy authentication is enabled, only traffic on supported protocols will trigger an authentication challenge.
Select all supported protocols from the following:
Select all supported protocols from the following:
send
light_mode
delete
Question #3
A client can create a secure connection to a FortiGate device using SSL VPN in web-only mode.
Which one of the following statements is correct regarding the use of web-only mode SSL VPN?
Which one of the following statements is correct regarding the use of web-only mode SSL VPN?
- AWeb-only mode supports SSL version 3 only.
- BA Fortinet-supplied plug-in is required on the web client to use web-only mode SSL VPN.
- CWeb-only mode requires the user to have a web browser that supports 64-bit cipher length.Most Voted
- DThe JAVA run-time environment must be installed on the client to be able to connect to a web-only mode SSL VPN.
Correct Answer:
C
C
send
light_mode
delete
Question #4
A client can establish a secure connection to a corporate network using SSL VPN in tunnel mode.
Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that apply.)
Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that apply.)
- ASplit tunneling can be enabled when using tunnel mode SSL VPN.Most Voted
- BClient software is required to be able to use a tunnel mode SSL VPN.Most Voted
- CUsers attempting to create a tunnel mode SSL VPN connection must be authenticated by at least one SSL VPN policy.Most Voted
- DThe source IP address used by the client for the tunnel mode SSL VPN is assigned by the FortiGate unit.Most Voted
Correct Answer:
ABCD
ABCD
send
light_mode
delete
Question #5
In an IPSec gateway-to-gateway configuration, two FortiGate units create a VPN tunnel between two separate private networks.
Which of the following configuration steps must be performed on both FortiGate units to support this configuration? (Select all that apply.)
Which of the following configuration steps must be performed on both FortiGate units to support this configuration? (Select all that apply.)
- ACreate firewall policies to control traffic between the IP source and destination address.
- BConfigure the appropriate user groups on the FortiGate units to allow users access to the IPSec VPN connection.
- CSet the operating mode of the FortiGate unit to IPSec VPN mode.
- DDefine the Phase 2 parameters that the FortiGate unit needs to create a VPN tunnel with the remote peer.
- EDefine the Phase 1 parameters that the FortiGate unit needs to authenticate the remote peers.
Correct Answer:
ADE
ADE
send
light_mode
delete
Question #6
How is traffic routed onto an SSL VPN tunnel from the FortiGate unit side?
- AA static route must be configured by the administrator using the ssl.root interface as the outgoing interface.
- BAssignment of an IP address to the client causes a host route to be added to the FortiGate unit’s kernel routing table.
- CA route back to the SSLVPN IP pool is automatically created on the FortiGate unit.
- DThe FortiGate unit adds a route based upon the destination address in the SSL VPN firewall policy.
Correct Answer:
B
B
send
light_mode
delete
Question #7
An end user logs into the full-access SSL VPN portal and selects the Tunnel Mode option by clicking on the "Connect" button. The administrator has enabled split tunneling.

Given that the user authenticates against the SSL VPN policy shown in the image below, which statement below identifies the route that is added to the clients routing table.

Given that the user authenticates against the SSL VPN policy shown in the image below, which statement below identifies the route that is added to the clients routing table.
- AA route to destination matching the ‘WIN2K3’ address object.
- BA route to the destination matching the ‘all’ address object.
- CA default route.
- DNo route is added.
Correct Answer:
A
A
send
light_mode
delete
Question #8
Which of the following antivirus and attack definition update options are supported by FortiGate units? (Select all that apply.)
- AManual update by downloading the signatures from the support site.
- BPull updates from the FortiGate device
- CPush updates from the FortiGuard Distribution Network.
- D"update-AV/AS" command from the CLI
Correct Answer:
ABC
ABC
send
light_mode
delete
Question #9
A FortiGate AntiVirus profile can be configured to scan for viruses on SMTP, FTP, POP3, and SMB protocols using which inspection mode?
send
light_mode
delete
Question #10
Which of the following statements regarding Banned Words are correct? (Select all that apply.)
- AThe FortiGate unit can scan web pages and email messages for instances of banned words.
- BWhen creating a banned word list, an administrator can indicate either specific words or patterns.
- CBanned words can be expressed as simple text, wildcards or regular expressions.
- DContent is automatically blocked if a single instance of a banned word appears.
- EThe FortiGate unit updates banned words on a periodic basis.
Correct Answer:
ABC
ABC
send
light_mode
delete
All Pages