Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet FCP_FSA_AD-5.0 - FCP - FortiSandbox 5.0 Administrator

Page: 1 / 2
Total 42 questions

An organization has an existing FortiGate provisioned as a data center firewall (DCFW) that submits inbound files to FortiSandbox for inline scanning. As a result of a network redesign, traffic between the FortiSandbox and the DCFW now passes through an intermediate firewall. Inline scanning is no longer working. While examining the configuration of the intermediate firewall you notice that it is configured to allow traffic on ports TCP/3389, UDP/53, and TCP/443. What must you change for the integration to work? (Choose one answer)

A.

FortiGate must be able to access FortiSandbox on TCP/4443.

B.

FortiGate must be able to access FortiSandbox on TCP/8890.

C.

FortiGate must be able to access FortiSandbox on UDP/8888.

D.

FortiGate must be able to access FortiSandbox on UDP/1344.

A FortiSandbox VM has been deployed and has been functioning correctly for several months. Suddenly, the system begins rejecting file submissions with an error message indicating a licensing problem. How can you determine, using the CLI, if the license is still valid? (Choose one answer)

A.

vm-status

B.

hc-setting -1

C.

vm-license -1

D.

status

On a FortiClient EMS integrated with FortiSandbox, how can you apply FortiSandbox profile configurations to endpoints even if they are off fabric? (Choose one answer)

A.

As part of the fabric connectors configuration

B.

As part of an endpoint workgroup configuration

C.

As part of the endpoint policy configuration

D.

As part of the sandbox profile configuration

Which three actions does FortiSandbox perform when it is integrated with FortiMail for advanced threat protection (ATP)? (Choose three answers)

A.

It updates FortiGuard databases.

B.

It assigns and returns a rating for analyzed objects.

C.

It submits objects for sandbox scanning.

D.

It analyzes file and URL objects.

E.

It queues email during analysis.

You are asked to configure a FortiSandbox HA cluster. Port 4 on the primary and secondary nodes is dedicated for HA-specific communication. Which command must you use to configure the primary node? (Choose one answer)

A.

hc-settings -sc -tN -nPrimaryNode -cFSAGrp -p -iport4

B.

hc-settings -sc -tR -nPrimaryNode -cFSAGrp -p -iport4

C.

hc-settings -sc -tF -nPrimaryNode -cFSAGrp -p -iport4

D.

hc-settings -sc -tM -nPrimaryNode -cFSAGrp -p -iport4

What are three roles of the rating engine component of FortiSandbox? (Choose three answers)

A.

Rates the security effectiveness of third-party devices

B.

Checks file hashes against FortiGuard

C.

Shares verdicts with other Fortinet devices

D.

Generates verdicts

E.

Analyzes the information from the tracer engine

Refer to the exhibits.

You are asked to configure a FortiSandbox to leverage the real-time anti-phishing (RTAP) feature. After configuring the scan profile, testing shows that URLs are not being submitted to the RTAP service. What could cause this issue? (Choose one answer)

A.

The URL option is not selected as a Web file type.

B.

The WEBLink file type is not selected in the profile.

C.

The VM scan timeout for URLs should be at least 300 to provide enough time for a FortiGuard response.

D.

The URLs are not designated for active content pre-scan.

You are asked to create some custom VMs to better represent your security environment. In which two FortiSandbox deployments is this supported? (Choose two answers)

A.

Private cloud

B.

Azure non-nested mode

C.

Device-based

D.

FortiSandbox Cloud

Refer to the exhibits.

A FortiClient EMS server is integrated with a FortiSandbox device. You are asked to find ways to expedite all scan jobs that require dynamic scanning so end users do not have to wait too long for a rating on suspicious attachments and URLs. Which configuration change will maintain a high security level but expedite all dynamic scan job requests? (Choose one answer)

A.

On FortiClient EMS, disable Wait for FortiSandbox Results before Allowing File Access.

B.

On FortiSandbox, in the Advanced settings, enable Pipeline Mode.

C.

On FortiClient EMS, change FortiSandbox Detection Verdict Level to Medium.

D.

On FortiSandbox, in the Pre-Filter settings, enable Office, PDF, URL, and Archive.

You are troubleshooting long delays between FortiMail file submissions to FortiSandbox and verdicts being returned form FortiSandbox. Which FortiMail debug tool must you use to troubleshoot this issue further? (Choose one answer)

A.

diagnose debug application hoststatd

B.

diagnose debug application deferd

C.

diagnose debug application oftpd

D.

diagnose debug application mailfilterd