Pre-Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet FCP_FSA_AD-5.0 Dumps

FCP - FortiSandbox 5.0 Administrator Questions and Answers

Question 1

On a FortiClient EMS integrated with FortiSandbox, how can you apply FortiSandbox profile configurations to endpoints even if they are off fabric? (Choose one answer)

Options:

A.

As part of the fabric connectors configuration

B.

As part of an endpoint workgroup configuration

C.

As part of the endpoint policy configuration

D.

As part of the sandbox profile configuration

Question 2

What is the default timeout value on FortiGate for inline scanning mode? (Choose one answer)

Options:

A.

300 seconds

B.

50 seconds

C.

40 minutes

D.

30 minutes

Question 3

Refer to the exhibits.

as

A FortiClient EMS server is integrated with a FortiSandbox device. You are asked to find ways to expedite all scan jobs that require dynamic scanning so end users do not have to wait too long for a rating on suspicious attachments and URLs. Which configuration change will maintain a high security level but expedite all dynamic scan job requests? (Choose one answer)

Options:

A.

On FortiClient EMS, disable Wait for FortiSandbox Results before Allowing File Access.

B.

On FortiSandbox, in the Advanced settings, enable Pipeline Mode.

C.

On FortiClient EMS, change FortiSandbox Detection Verdict Level to Medium.

D.

On FortiSandbox, in the Pre-Filter settings, enable Office, PDF, URL, and Archive.

Question 4

You notice a recent file downloaded by some end stations is exhibiting malware behavior, however, on the sandbox the file is rated clean. After further investigation you determine that only end stations using the Opera browser are being affected. What must you do to prevent these infections? (Choose one answer)

Options:

A.

Enable the STIX/TAXII Integration setting on FortiSandbox.

B.

Configure a custom VM to use the same browser as the exploited end stations.

C.

Modify the scan profile to include the malware file type.

D.

Change the job queue priority to process web-based files first.

Question 5

A FortiSandbox HA cluster is configured with the MTA adapter. What does the primary node do when it receives MTA jobs? (Choose one answer)

Options:

A.

It distributes the MTA jobs to secondary members.

B.

It distributes the MTA jobs to itself or to worker nodes.

C.

It assigns the MTA jobs to itself ز

D.

It assigns the MTA jobs only to worker members.

Question 6

You are attempting to troubleshoot a FortiGate device that is not sending samples to FortiSandbox. Which CLI command will provide you with useful diagnostic information? (Choose one answer)

Options:

A.

diagnose antivirus quarantine purge

B.

diagnose test application quarantined 8

C.

diagnose test application ipsmonitor 99

D.

diagnose debug application quarantine -1

Question 7

What are three roles of the rating engine component of FortiSandbox? (Choose three answers)

Options:

A.

Rates the security effectiveness of third-party devices

B.

Checks file hashes against FortiGuard

C.

Shares verdicts with other Fortinet devices

D.

Generates verdicts

E.

Analyzes the information from the tracer engine

Question 8

Refer to the exhibit.

as

Which command must you use to configure the FortiSandbox device as the primary node? (Choose one answer)

Options:

A.

hc-settings -si iport1 -a10.25.1.30

B.

hc-settings -si iport1 -a10.25.1.40

C.

hc-settings -si iport1 -a10.25.1.254

D.

hc-settings -si iport1 -a10.25.1.50

Question 9

Refer to the exhibit.

as

Which two statements about the scanned file are true? (Choose two answers)

Options:

A.

The advanced AI feature identified the threat.

B.

The URL was identified as a known malicious URL.

C.

The analysis resulted are defined.

D.

The analysis resulted in a malicious verdict.

Question 10

A FortiSandbox VM has been deployed and has been functioning correctly for several months. Suddenly, the system begins rejecting file submissions with an error message indicating a licensing problem. How can you determine, using the CLI, if the license is still valid? (Choose one answer)

Options:

A.

vm-status

B.

hc-setting -1

C.

vm-license -1

D.

status

Question 11

You are asked to configure a FortiSandbox HA cluster. Port 4 on the primary and secondary nodes is dedicated for HA-specific communication. Which command must you use to configure the primary node? (Choose one answer)

Options:

A.

hc-settings -sc -tN -nPrimaryNode -cFSAGrp -p -iport4

B.

hc-settings -sc -tR -nPrimaryNode -cFSAGrp -p -iport4

C.

hc-settings -sc -tF -nPrimaryNode -cFSAGrp -p -iport4

D.

hc-settings -sc -tM -nPrimaryNode -cFSAGrp -p -iport4

Question 12

A FortiGate root VDOM is authorized on FortiSandbox, and FortiGate is configured to send suspicious files to FortiSandbox for inspection. You create a new VDOM and then generates some traffic so that the new VDOM sends a file to FortiSandbox for the first time. In this scenario, which action will FortiSandbox take? (Choose one answer)

Options:

A.

FortiSandbox will inspect all files, based on the root VDOM authorization state and configuration.

B.

FortiSandbox will accept the file, but not inspect the file until the administrator manually authorizes the new VDOM on FortiSandbox.

C.

FortiSandbox will authorize the new VDOM by default and inspect files as they are received.

D.

FortiSandbox will accept the file; but not inspect the file until the administrator manually configures the new VDOM on FortiSandbox.

Page: 1 / 4
Total 42 questions