FCSS-NST-SE-7.6 Sample Questions & Answers
Five troubleshooting areas share the weighting evenly: Security Fabric and automation-stitch issues plus resource problems, authentication failures including FSSO, FortiGuard, web-filtering, and IPS faults, routing problems, and IPsec VPN troubleshooting.
Launch the full FCSS-NST-SE-7.6 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Security profiles · Troubleshoot web filtering issues
A support engineer is troubleshooting a web filtering issue where access to a specific HTTPS website is unexpectedly blocked. The web filter profile is set to flow-based inspection mode. The logs show the reason for the block is
Blocked by FortiGuard category. The administrator confirms the website's category is set to 'Allow' in the web filter profile. What is the most likely cause of this discrepancy?Show answer & explanation
Correct answer: A
Without deep inspection, the FortiGate cannot see the HTTPS URL. For flow-based web filtering it rates the hostname from the SNI in the TLS Client Hello, or the server certificate's CN when there is no SNI. If the site is served under a hostname (for example a CDN or shared hosting name) whose FortiGuard category differs from the category the administrator checked, the session is blocked by that other category. The log's category field shows which one. If 'Rate URLs by domain and IP address' is enabled, the IP rating can also override the domain rating by weight. Checking the category in the log, adding a local rating or URL filter exemption, or using deep inspection so the full URL is rated resolves the discrepancy. (FortiOS 7.6 Administration Guide: Configuring a web filter profile; Rating options.)
- Question 2IntermediateSelect 2
Routing · Troubleshoot routing packets using static routes
When troubleshooting a static route on a FortiGate, an administrator finds that the route is present in the routing table, but traffic is not being forwarded correctly. Which TWO of the following CLI commands are most effective for diagnosing why the next-hop gateway might be considered unreachable by the FortiGate? (Select TWO).
Show answer & explanation
Correct answers: B, C
If a static route is in the routing table but traffic is not forwarded, check whether the next hop is actually reachable at Layer 2 and Layer 3.
diagnose ip arp listshows whether the FortiGate has resolved the gateway's MAC address; an incomplete or missing entry points to a Layer 2 or addressing problem.execute pingtests Layer 3 reachability of the gateway directly.get router info routing-table allonly confirms what is already known (the route is present).get system performance statusshows resource usage, anddiagnose debug flowtraces a packet's policy and route decisions rather than gateway reachability.If a static route is in the routing table but traffic is not forwarded, check whether the next hop is actually reachable at Layer 2 and Layer 3.
diagnose ip arp listshows whether the FortiGate has resolved the gateway's MAC address; an incomplete or missing entry points to a Layer 2 or addressing problem.execute pingtests Layer 3 reachability of the gateway directly.get router info routing-table allonly confirms what is already known (the route is present).get system performance statusshows resource usage, anddiagnose debug flowtraces a packet's policy and route decisions rather than gateway reachability. - Question 3Intermediate
System troubleshooting · Troubleshoot automation stitches
An administrator has configured an automation stitch to block a source IP address using a CLI script when a high-severity IPS event is detected. The stitch is not working as expected. To troubleshoot, the administrator wants to view a history of all automation stitches that have been triggered and their execution status (success or failure). Which command should be used?
Show answer & explanation
Correct answer: D
diagnose test application autod 3displays statistics for all automation stitches: how many times each stitch was triggered (local hit), the last trigger time, and each action'sdone/dropcounters. It shows which stitches ran and whether their actions succeeded or failed.diagnose automation stitch-history,diagnose automation stitch-traceanddiagnose sys csf-logaren't FortiOS commands, andget system automation stitchdoesn't show execution history. Reference: FortiOS 7.6 Administration Guide, Diagnosing automation stitches. - Question 4Advanced
VPN · Troubleshoot IPsec IKE version 1 and 2 issues
A financial services company is using FortiGate for perimeter security. They have an IPsec VPN tunnel to a business partner. The tunnel is established, but the company's internal monitoring system reports that the tunnel flaps (goes down and comes back up) approximately every 5 minutes. Both sides have confirmed that their Phase 1 and Phase 2 proposals match perfectly. What is the most likely cause of this periodic flapping?
Show answer & explanation
Correct answer: B
When Dead Peer Detection (DPD) is configured as 'On Idle' on one FortiGate, it will only send DPD probes when there is no outbound traffic to send. If the other side has DPD disabled, it will not respond to these probes. After a few failed probes, the 'On Idle' FortiGate will tear down the tunnel, assuming the peer is dead. If there is periodic keep-alive or monitoring traffic, the tunnel will re-establish, creating a flapping cycle. A DPD timer mismatch would not typically cause this issue, and Phase 2 lifetime expiry would be on a much longer interval (usually hours).
- Question 5Intermediate
Routing · Troubleshoot OSPF to route the enterprise traffic
A FortiGate is configured with two OSPF neighbors over a point-to-point link. The administrator notices that the OSPF adjacency is stuck in the
ExStartstate. What is the most common reason for OSPF getting stuck in this state?Show answer & explanation
Correct answer: B
The
ExStartstate is where OSPF routers decide which router will be the master for exchanging Database Descriptor (DBD) packets. If the routers have different interface MTU values, the larger DBD packets from the router with the higher MTU will be dropped by the router with the lower MTU. This prevents the DBD exchange from completing, causing the adjacency to be stuck inExStart. Timer mismatches would prevent the state from even reaching2-Way, and area ID or authentication mismatches would also cause earlier failures. - Question 6Advanced
Security profiles · Troubleshoot the intrusion prevention system (IPS)
A support engineer is troubleshooting a FortiGate where the
ipsengineprocess is consuming over 80% of the CPU and traffic through IPS-enabled policies is delayed. As a temporary test, the engineer wants to toggle the IPS engine into bypass mode (traffic is not sent to the IPS engine) without removing the IPS sensors from the firewall policies. Which command should be used?Show answer & explanation
Correct answer: A
The ipsmonitor test menu offers: 1 = display IPS engine information, 2 = toggle IPS engine enable/disable status, 3 = display restart log, 4 = clear restart log, 5 = toggle bypass status, 97/98/99 = start/stop/restart all IPS engines.
diagnose test application ipsmonitor 5therefore toggles IPS bypass. It is a quick, reversible way to confirm whether the IPS engine is behind the CPU load and latency, and it leaves the policy configuration unchanged. Option 99 restarts all IPS engines, which the Fortinet Community article on IPS memory optimization uses after changing IPS global settings. Option 1 only shows engine information, and option 3 shows the restart log. Run the same command again to leave bypass mode. - Question 7Intermediate
Authentication · Troubleshoot Fortinet Single Sign-On (FSSO) issues
A network engineer is troubleshooting FSSO. Users who are members of the 'Domain Admins' group are being correctly identified, but users who are only members of the 'Sales_Users' group are not appearing in the FSSO user list on the FortiGate. The FSSO Collector Agent is running in Advanced mode with DC Agents installed. What is a common misconfiguration that would cause this specific issue?
sequenceDiagram participant User participant DC as Domain Controller participant DCAgent as DC Agent participant Collector as Collector Agent participant FGT as FortiGate User->>DC: Logon Event (Sales_Users) DC->>DCAgent: Forward Logon Event DCAgent->>Collector: Send User Info Note over Collector: Group Filter applied Collector-->>FGT: No update sent (User filtered out)Show answer & explanation
Correct answer: D
The Collector Agent can apply a group filter (Set Group Filters > Monitored groups) per FortiGate. Once a filter is configured, logon events for users who are not in a monitored group are received from the DC Agent but not forwarded to that FortiGate. If the filter lists 'Domain Admins' but not 'Sales_Users', only the Domain Admins users appear. With no filter configured, all groups are forwarded. The fix is to add 'Sales_Users' to the monitored groups (Fortinet Community: Configure FSSO in DC Agent mode / FSSO Group Filter configured on Collector Agent).
- Question 8Intermediate
System troubleshooting · Troubleshoot connectivity problems using built-in tools
During a connectivity test, an administrator uses the command
execute traceroute-options device autofollowed byexecute traceroute. The goal is to trace a path for traffic originating from the LAN interface. However, the trace appears to be sourcing from the WAN interface instead. What is the most likely reason for this behavior?Show answer & explanation
Correct answer: D
With
execute traceroute-options device auto(the default), FortiOS chooses the egress interface for self-originated traceroute traffic from the routing table of the current VDOM, and uses that interface's IP as the source. When the best route to the destination is a default route out the WAN interface, the probes are sourced from the WAN. To make the probes originate from the LAN side, set the source explicitly withexecute traceroute-options source(or setdeviceto the LAN interface). Reference: FortiOS 7.6 CLI Reference, execute traceroute-options. - Question 9Beginner
VPN · Troubleshoot IPsec IKE version 1 and 2 issues
A FortiGate running FortiOS 7.6.1 has an IKEv2 site-to-site tunnel configured with
set transport auto. The remote peer sits behind a firewall that blocks UDP 500/4500.diagnose debug application ike -1shows the messageauto transport timeout, use tcp port 4500, and the tunnel then comes up. What does this message indicate?Show answer & explanation
Correct answer: D
With IKEv2,
set transport automakes FortiOS start IKE over UDP. If the UDP negotiation does not establish withinauto-transport-threshold(1–300 s, default 15), it automatically falls back to TCP, as the debug line 'auto transport timeout, use tcp port 4500' shows. The TCP port comes fromike-tcp-portunderconfig system settings, which defaults to 4500. The transport option is only available whenike-versionis 2, and NAT-T does not switch IKE to TCP. Sources: FortiOS 7.6 New Features, 'Automatic selection of IPsec tunneling protocol'; FortiOS 7.6 Administration Guide, 'Dialup IPsec VPN using custom TCP port'. - Question 10Advanced
Routing · Troubleshoot OSPF to route the enterprise traffic
An OSPF network is configured with a hub-and-spoke topology. The hub FortiGate is redistributing a default static route into OSPF. The spoke FortiGates are learning the default route but are not installing it in their routing tables. All OSPF adjacencies are FULL. What setting on the spoke FortiGates would prevent the installation of the redistributed default route?
Show answer & explanation
Correct answer: D
In
config router ospf,set distribute-list-in('Filter incoming routes') stops matching OSPF routes from being installed in the routing table. The LSAs are still received and kept in the OSPF database, which matches the symptom: FULL adjacencies and a learned but not installed default route.database-filter-out(underconfig ospf-interface) only controls flooding of LSAs out of an interface. Router priority only affects DR/BDR election. The hub is already advertising the default route, since the spokes learn it. Source: FortiOS 7.6 CLI Reference, config router ospf.
Ready for the real thing?
The full FCSS-NST-SE-7.6 simulator has every exam-style question, timed mode, and instant scoring.