Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCP_FSA_AD-5.0 FCP - FortiSandbox 5.0 Administrator Exam Practice Test

Demo: 12 questions
Total 42 questions

FCP - FortiSandbox 5.0 Administrator Questions and Answers

Question 1

Refer to the exhibit.

Which command must you use to configure the secondary node? (Choose one answer)

Options:

A.

hc-worker -a -s10.25.1.30 -p < password >

B.

hc-worker -a -s10.50.1.30 -p < password >

C.

hc-worker -a -s10.50.1.40 -p < password >

D.

hc-worker -a -s10.25.1.50 -p < password >

Question 2

You must increase the scanning capacity of a FortiSandbox device by increasing the number of clones, but the FortiSandbox local clone limit is already at maximum. Which two actions can you take to expand the scanning capacity of the unit? (Choose two answers)

Options:

A.

Deploy remote WindowsCloudVM and MACOSX clones

B.

Reorganize the scan priority list

C.

Add custom VMs

D.

Add VM licenses to FortiSandbox

Question 3

Which two statements are true about creating an API interface? (Choose two answers)

Options:

A.

Ports configured for HA communication can also be configured as API ports.

B.

API ports will not accept HTTP traffic.

C.

The configuration must be performed using the CLI

D.

The interface must also be designated as an administrative interface.

Question 4

Refer to the exhibits.

A FortiClient EMS server is integrated with a FortiSandbox device. You are asked to find ways to expedite all scan jobs that require dynamic scanning so end users do not have to wait too long for a rating on suspicious attachments and URLs. Which configuration change will maintain a high security level but expedite all dynamic scan job requests? (Choose one answer)

Options:

A.

On FortiClient EMS, disable Wait for FortiSandbox Results before Allowing File Access.

B.

On FortiSandbox, in the Advanced settings, enable Pipeline Mode.

C.

On FortiClient EMS, change FortiSandbox Detection Verdict Level to Medium.

D.

On FortiSandbox, in the Pre-Filter settings, enable Office, PDF, URL, and Archive.

Question 5

Which FortiGate daemon can you monitor in real time to verify that verdicts are being received by FortiGate? (Choose one answer)

Options:

A.

fsd

B.

quarantined

C.

wad

D.

scanunitd

Question 6

You are asked to create an 802.3ad interface on FortiSandbox with port 2 and port 4. However, when attempting to make the configuration change, you discover that you cannot select port 4 for the aggregate bonding. What are two reasons for this issue? (Choose two answers)

Options:

A.

Port 4 is an administration interface.

B.

Port 4 does not have an IP address.

C.

Port 4 is an api interface.

D.

Port 4 is a sniffer interface.

Question 7

A FortiGate root VDOM is authorized on FortiSandbox, and FortiGate is configured to send suspicious files to FortiSandbox for inspection. You create a new VDOM and then generates some traffic so that the new VDOM sends a file to FortiSandbox for the first time. In this scenario, which action will FortiSandbox take? (Choose one answer)

Options:

A.

FortiSandbox will inspect all files, based on the root VDOM authorization state and configuration.

B.

FortiSandbox will accept the file, but not inspect the file until the administrator manually authorizes the new VDOM on FortiSandbox.

C.

FortiSandbox will authorize the new VDOM by default and inspect files as they are received.

D.

FortiSandbox will accept the file; but not inspect the file until the administrator manually configures the new VDOM on FortiSandbox.

Question 8

When using SIMNET, which two inspections cannot be performed with real traffic? (Choose two answers)

Options:

A.

AV inspection

B.

Dynamic scan

C.

IP reputation

D.

URL rating

Question 9

A security analyst is reviewing a scan job report that indicates a true positive match. The job report displays that the malware attempts to replace vital system executables. Which type of malware is the analyst observing? (Choose one answer)

Options:

A.

Exploit

B.

Trojan

C.

Dropper

D.

Rootkit

Question 10

Refer to the exhibit.

Which command must you use to configure the FortiSandbox device as the primary node? (Choose one answer)

Options:

A.

hc-settings -si iport1 -a10.25.1.30

B.

hc-settings -si iport1 -a10.25.1.40

C.

hc-settings -si iport1 -a10.25.1.254

D.

hc-settings -si iport1 -a10.25.1.50

Question 11

You are asked to create some custom VMs to better represent your security environment. In which two FortiSandbox deployments is this supported? (Choose two answers)

Options:

A.

Private cloud

B.

Azure non-nested mode

C.

Device-based

D.

FortiSandbox Cloud

Question 12

You are troubleshooting long delays between FortiMail file submissions to FortiSandbox and verdicts being returned form FortiSandbox. Which FortiMail debug tool must you use to troubleshoot this issue further? (Choose one answer)

Options:

A.

diagnose debug application hoststatd

B.

diagnose debug application deferd

C.

diagnose debug application oftpd

D.

diagnose debug application mailfilterd

Demo: 12 questions
Total 42 questions