[Jul-2026] Feel Fortinet FCP_FSA_AD-5.0 Dumps PDF Will likely be The best Option
FCP_FSA_AD-5.0 exam torrent Fortinet study guide
NEW QUESTION # 12
A security analyst is reviewing a scan job report that indicates a true positive match. The job report displays that the malware attempts to replace vital system executables. Which type of malware is the analyst observing? (Choose one answer)
- A. Rootkit
- B. Exploit
- C. Trojan
- D. Dropper
Answer: A
Explanation:
The Results Analysis section gives direct malware-type definitions. It says: "A downloader attempts to download malicious content from a remote system", "A dropper installs malicious content", "A trojan appears to be a legitimate software application", and most importantly, "A rootkit attempts to hide its components by replacing valid system files." That exact wording matches the question statement about malware attempting to replace vital system executables. Replacing valid system files is classic rootkit behavior because the purpose is concealment and persistence by hiding malicious components behind trusted operating-system files. A dropper's main role is delivering payloads. A trojan is mainly deceptive software that appears legitimate. An exploit takes advantage of a vulnerability. None of those definitions match the described behavior as precisely as the rootkit definition in the Study Guide. Therefore, the malware type being observed is Rootkit.
NEW QUESTION # 13
A FortiSandbox VM has been deployed and has been functioning correctly for several months. Suddenly, the system begins rejecting file submissions with an error message indicating a licensing problem. How can you determine, using the CLI, if the license is still valid? (Choose one answer)
- A. hc-setting -1
- B. status
- C. vm-status
- D. vm-license -1
Answer: B
Explanation:
From the Deployment and System Settings lesson, the Study Guide explicitly states:
"The status command shows information about the system, including firmware level, device serial number, disk usage, Windows VM status, states of the boot and data disks, and more. For VM appliances, it will also show the FortiSandbox license status." The key phrase is "For VM appliances, it will also show the FortiSandbox license status" - making the status command the correct choice for verifying license validity on a FortiSandbox VM deployment.
While vm-license -l shows installed Windows/Microsoft Office license keys, and vm-status shows guest VM image information, neither directly reports on the FortiSandbox appliance license validity. The status command is the definitive command for checking overall system and license status.
NEW QUESTION # 14
You must increase the scanning capacity of a FortiSandbox device by increasing the number of clones, but the FortiSandbox local clone limit is already at maximum. Which two actions can you take to expand the scanning capacity of the unit? (Choose two answers)
- A. Deploy remote WindowsCloudVM and MACOSX clones
- B. Add VM licenses to FortiSandbox
- C. Reorganize the scan priority list
- D. Add custom VMs
Answer: A,B
Explanation:
From the Scanning and Rating Components lesson, the Study Guide states:
"The universal VM license is a single license that grants you access to multiple VMs. Provides a scalable and cost-effective solution with up to 200 VMs on a single unit. Clone count limits shown on the VM Settings view apply to all enabled VM Types."
"When you enable Adaptive Scan, FortiSandbox dynamically adjusts the number of clones of any local VMs you have enabled. Enabling this option does not affect the number of remote Mac OS or Windows cloud VMs." This confirms:
Option A - Deploying remote WindowsCloudVM and MACOSX clones expands capacity beyond local clone limits since remote VMs are not subject to local clone restrictions Option D - Adding VM licenses directly increases the number of available VMs up to 200 on a single unit Reorganizing the scan priority list (B) only affects scan order, not capacity. Adding custom VMs (C) would still be subject to the same local clone limits.
NEW QUESTION # 15
What is the default timeout value on FortiGate for inline scanning mode? (Choose one answer)
- A. 40 minutes
- B. 30 minutes
- C. 300 seconds
- D. 50 seconds
Answer: D
Explanation:
The correct answer is B. 50 seconds. The Study Guide explicitly states: "FortiGate holds the file while waiting for a verdict from FortiSandbox... The default file inspection timeout, and maximum, is 50 seconds." This is the clearest direct statement for the default timeout used with inline scanning mode on FortiGate.
The Lab Guide confirms the same design limit from the operational side. During the inline scanning exercise, it notes: "Because of the inline scanning time-out limit (maximum of 50 seconds), it's not recommended to submit files for VM inspection." That reinforces that inline scanning is designed for quick decision phases such as active content, community cloud, antivirus, and static analysis, not long VM dynamic analysis jobs. Therefore, options A, C, and D are incorrect because they are far above the documented inline inspection limit. The default FortiGate inline scanning timeout is 50 seconds.
NEW QUESTION # 16
Review the exhibits.

A FortiMail device is integrated with a FortiSandbox device. What is the expected behavior on FortiMail for emails that require FortiSandbox inspection? (Choose one answer)
- A. FortiMail will deliver all emails to the destination after the emails pass all local security checks.
- B. FortiMail will queue emails for up to 5 minutes during URL rating errors before submitting URLs to FortiSandbox
- C. FortiMail will queue emails for up to 30 minutes to allow FortiSandbox to finish scanning all attachments and URLs.
- D. FortiMail will not send attachments and URLs to FortiSandbox if their rating exists in the local cache.
Answer: C
Explanation:
From the FortiMail Integration lesson, the Study Guide explicitly states:
"The Scan timeout value determines how long FortiMail will wait for a response from FortiSandbox. The default is 30 minutes. So, if after 30 minutes FortiSandbox is unable to generate a verdict, FortiMail will release the email to the end user."
"SMTP is a store-and-forward protocol. This allows FortiMail to queue the email while FortiSandbox inspects all submitted samples. FortiMail will release the email only if there is a scan timeout event, or FortiSandbox returns a clean verdict." The Integration Settings exhibit clearly confirms Scan timeout = 30 minutes, and the AV Profile shows both Attachment analysis and URL analysis are enabled - meaning FortiMail will hold/queue emails for up to 30 minutes while FortiSandbox completes inspection of all attachments and URLs before taking action.
NEW QUESTION # 17
You are asked to create an 802.3ad interface on FortiSandbox with port 2 and port 4. However, when attempting to make the configuration change, you discover that you cannot select port 4 for the aggregate bonding. What are two reasons for this issue? (Choose two answers)
- A. Port 4 is an administration interface.
- B. Port 4 does not have an IP address.
- C. Port 4 is an api interface.
- D. Port 4 is a sniffer interface.
Answer: A,C
Explanation:
From the Deployment and System Settings lesson, the Study Guide states:
"Other ports, with the exception of port3, can also be configured as management ports from CLI."
"You can set additional ports as management port using the CLI command shown on this slide." From the Lab Guide (Exercise 4 - Using Inline Scanning):
"FortiGate and FortiSandbox communicate through port 4443. Management or API ports grant access through port 4443."
"Enter the following command to enable API access on port2: set api-port port2" Ports that are designated as either administration interfaces or API interfaces cannot be selected for 802.3ad aggregate bonding because:
Option A - Port 4 configured as an administration interface is reserved for management traffic and cannot be repurposed for link aggregation Option C - Port 4 configured as an API interface is dedicated for API communication (port 4443) and is similarly restricted from being used in aggregate bonding configurations Port 4 in the Lab Guide is specifically referenced as the HA communication and management port, confirming these restrictions apply when special roles are assigned to interfaces.
NEW QUESTION # 18
You are asked to configure a FortiSandbox HA cluster. Port 4 on the primary and secondary nodes is dedicated for HA-specific communication. Which command must you use to configure the secondary node? (Choose one answer)
- A. hc-settings -sc -tR -nSecondaryNode -cFSAGrp -p<password> -iport4
- B. hc-settings -sc -tP -nSecondaryNode -cFSAGrp -p<password> -iport4
- C. hc-settings -sc -tM -nSecondaryNode -cFSAGrp -p<password> -iport4
- D. hc-settings -sc -tN -nSecondaryNode -cFSAGrp -p<password> -iport4
Answer: D
Explanation:
From the High Availability and Management lesson, the Study Guide states:
"You use the hc-settings command and options to configure the main HA settings, such as enable HA, and to configure the node's mode of operation, node alias, group name, group password, and the HA interface." The CLI flags breakdown:
-sc = Set configuration
-t = Node type flag where N = Secondary node
-n = Node alias (SecondaryNode)
-c = Cluster/group name (FSAGrp)
-p = Password
-i = HA interface (port4)
The Study Guide confirms the secondary node type uses -tN designation. Option B (-tM) represents the primary/master node, Option C (-tP) and Option D (-tR) are not valid node type designators for secondary nodes in the FortiSandbox HA CLI syntax.
NEW QUESTION # 19
Which FortiGate daemon can you monitor in real time to verify that verdicts are being received by FortiGate? (Choose one answer)
- A. quarantined
- B. wad
- C. fsd
- D. scanunitd
Answer: A
Explanation:
From the FortiGate Integration lesson, the Study Guide explicitly states:
"The quarantine daemon is involved in submitting files to FortiSandbox."
"The quarantine daemon also receives the verdicts returned by FortiSandbox."
"The quarantine daemon is responsible for sending requests for the dynamic lists generated by FortiSandbox. This includes the malware package, URL package, and the extension lists." From the Lab Guide (Exercise 3 - Using FortiGate Diagnostics):
"Enter the following commands to enable debugging for the quarantine daemon: diagnose debug application quarantine -1" The quarantined daemon (Option B) handles both file submissions to FortiSandbox AND receives verdicts back from FortiSandbox in real time, making it the correct daemon to monitor for verdict reception verification.
NEW QUESTION # 20
A FortiSandbox HA cluster is configured with the MTA adapter. What does the primary node do when it receives MTA jobs? (Choose one answer)
- A. It distributes the MTA jobs to itself or to worker nodes.
- B. It distributes the MTA jobs to secondary members.
- C. It assigns the MTA jobs to itself
- D. It assigns the MTA jobs only to worker members.
Answer: A
Explanation:
The Study Guide states that in an HA cluster, "As well as normal scanning duties, the primary node also manages the cluster, distributes jobs, and gathers the verdicts." It also says that "The worker nodes provide load balancing. The primary node distributes scan jobs to the worker nodes." From those official statements, the primary node is not just a coordinator. It also performs normal scanning duties itself, while distributing scan jobs across worker nodes for load balancing. That rules out A, because the secondary node is for failover, not normal job distribution. It rules out C, because the primary is not restricted to itself only. It also rules out D, because the primary can still perform scanning duties and is not limited to sending all jobs only to workers. Therefore, when the primary receives MTA jobs, the correct behavior is that it distributes the MTA jobs to itself or to worker nodes.
NEW QUESTION # 21
Refer to the exhibit.
Which command must you use to configure the secondary node? (Choose one answer)
- A. hc-worker -a -s10.25.1.50 -p<password>
- B. hc-worker -a -s10.50.1.40 -p<password>
- C. hc-worker -a -s10.50.1.30 -p<password>
- D. hc-worker -a -s10.25.1.30 -p<password>
Answer: C
Explanation:
From the High Availability and Management lesson, the Study Guide states:
"You must configure the HA group name, password, and the virtual IP only on the primary node. After you configure those, you can add the secondary node to the group using the commands shown on this slide." The hc-slave command (shown as hc-worker for secondary) requires pointing to the Primary Node's HA interface IP, not the cluster virtual IP or the primary node's port1.
From the exhibit:
Primary Node port4 (HA interface) = 10.50.1.30
Secondary Node port4 = 10.50.1.40
Primary Node port1 = 10.25.1.30
Cluster Virtual IP = 10.25.1.50
The secondary node must connect to the Primary Node's dedicated HA communication port (port4 = 10.50.1.30) to join the cluster, making Option B the correct answer.
NEW QUESTION # 22
A security analyst is reviewing a scan job report that indicates a true positive match. The job report displays that the malware attempts to replace vital system executables. Which type of malware is the analyst observing? (Choose one answer)
- A. Rootkit
- B. Exploit
- C. Trojan
- D. Dropper
Answer: A
NEW QUESTION # 23
Refer to the exhibits.
You are unable to download guest VMs on a new FortiSandbox VM. What is the reason for this? (Choose one answer)
- A. There is no internet connectivity on port1.
- B. There is no internet connectivity on port3.
- C. FortiSandbox is using a private DNS server.
- D. FortiSandbox does not have the necessary licenses.
Answer: A
Explanation:
From the Scanning and Rating Components lesson, the Study Guide explicitly states:
"VM images are downloaded from FortiGuard, using port1. So, you must ensure FortiSandbox has a default route and internet connectivity for port1." The exhibit confirms this - the test-network output shows:
System DNS resolve: Failed for both bing.com and fsavm.fortinet.net
fsavm.fortinet.net is the FortiGuard VM image download server
This DNS failure on the system side (port1) confirms there is no internet connectivity on port1, preventing VM image downloads. Note that port3 internet shows "Warning: VM to access internet: Disabled" - but port3 is only for VM sandboxing traffic, not for downloading VM images.
NEW QUESTION # 24
You are asked to create some custom VMs to better represent your security environment. In which two FortiSandbox deployments is this supported? (Choose two answers)
- A. FortiSandbox Cloud
- B. Private cloud
- C. Device-based
- D. Azure non-nested mode
Answer: B,C
Explanation:
From the Scanning and Rating Components lesson, the Study Guide explicitly states:
"FortiSandbox allows you to modify the number of CPUs and memory assigned to a custom VM. This feature is supported on hardware models and private cloud VMs." Hardware models = Device-based (Option C) Private cloud VMs = Private cloud (Option A) Azure non-nested mode and FortiSandbox Cloud do not support custom VM creation as per the Study Guide.
NEW QUESTION # 25
Refer to the exhibit.
Which command must you use to configure the FortiSandbox device as the primary node? (Choose one answer)
- A. hc-settings -si iport1 -a10.25.1.50
- B. hc-settings -si iport1 -a10.25.1.40
- C. hc-settings -si iport1 -a10.25.1.254
- D. hc-settings -si iport1 -a10.25.1.30
Answer: A
Explanation:
The exhibit labels 10.25.1.50 as the cluster virtual IP address. The Study Guide explains that in HA configuration, "You must configure the HA group name, password, and the virtual IP only on the primary node." It also says: "You must also configure an external interface for external communication and an IP address that will be used as a virtual IP for the whole cluster. Devices will interact with the cluster using this virtual IP." That is why the command for the primary node must point to the cluster virtual IP, not to the individual port1 addresses of the primary, secondary, or upstream firewall. In the exhibit, 10.25.1.30 is the primary node's own port1 IP, 10.25.1.40 is the secondary node's port1 IP, and 10.25.1.254 is the network device. The only address that matches the required cluster virtual IP is 10.25.1.50, so the correct command is hc-settings -si iport1 -a10.25.1.50.
NEW QUESTION # 26
You are attempting to troubleshoot a FortiGate device that is not sending samples to FortiSandbox. Which CLI command will provide you with useful diagnostic information? (Choose one answer)
- A. diagnose antivirus quarantine purge
- B. diagnose test application quarantined 8
- C. diagnose test application ipsmonitor 99
- D. diagnose debug application quarantine -1
Answer: D
Explanation:
From the FortiGate Integration lesson, the Study Guide explicitly states:
"The quarantine daemon is involved in submitting files to FortiSandbox." From the Lab Guide (Exercise 3 - Using FortiGate Diagnostics), the following is explicitly documented:
"Enter the following commands to enable debugging for the quarantine daemon: diagnose debug application quarantine -1 diagnose debug enable"
"Use the following CLI debug command to diagnose the connection and file transfer issue between HQ-FGT-1 and HQ-FSA-1: diagnose debug application quarantine -1" This command enables real-time debug output for the quarantine daemon on FortiGate, which is specifically responsible for submitting files to FortiSandbox and receiving verdicts. Option B clears the analytics cache rather than providing diagnostic information, and the other options relate to different functions entirely.
NEW QUESTION # 27
A FortiGate root VDOM is authorized on FortiSandbox, and FortiGate is configured to send suspicious files to FortiSandbox for inspection. You create a new VDOM and then generates some traffic so that the new VDOM sends a file to FortiSandbox for the first time. In this scenario, which action will FortiSandbox take? (Choose one answer)
- A. FortiSandbox will accept the file, but not inspect the file until the administrator manually authorizes the new VDOM on FortiSandbox.
- B. FortiSandbox will inspect all files, based on the root VDOM authorization state and configuration.
- C. FortiSandbox will authorize the new VDOM by default and inspect files as they are received.
- D. FortiSandbox will accept the file; but not inspect the file until the administrator manually configures the new VDOM on FortiSandbox.
Answer: A
Explanation:
The uploaded FortiSandbox 5.0 Administrator Study Guide states that each VDOM is handled independently by FortiSandbox, not under the root VDOM's authorization. It explicitly explains that "each VDOM is treated as a separate input device on FortiSandbox" and that each device must be authorized before FortiSandbox will process its submissions. It further adds that only when auto-authorization is enabled will FortiSandbox automatically authorize VDOMs as files are submitted.
Therefore, the new VDOM does not inherit the root VDOM's authorized state. Since the question does not say that auto-authorization is enabled, FortiSandbox will not automatically trust or process that new VDOM as if it were already approved. This eliminates A and C. Option D is incorrect because the issue is not that the administrator must manually configure the VDOM on FortiSandbox; the study guide specifically identifies authorization as the required control. For that reason, B is the best answer: the new VDOM must be manually authorized before its submitted files are inspected.
NEW QUESTION # 28
......
Use Valid New FCP_FSA_AD-5.0 Test Notes & FCP_FSA_AD-5.0 Valid Exam Guide: https://passleader.briandumpsprep.com/FCP_FSA_AD-5.0-prep-exam-braindumps.html
