Practice Free FCP_FSA_AD-5.0 Exam Online Questions
Question #11
Which stage of the Cyber Kill Chain does FortiSandbox and FortiClient EMS integration help to block? (Choose one answer)
- A . Deliverya
- B . Weaponization
- C . Reconnaissance
- D . Command and control
Correct Answer: A
A
Explanation:
From the FortiClient EMS Integration lesson, the Study Guide states that FortiSandbox and FortiClient EMS integration helps break the kill chain by monitoring all downloads, removable media, mapped network drives, and email client file downloads ― intercepting threats at the Delivery stage before they can execute on the endpoint.
Additionally, from the Attack Methodologies section: "When a USB is attached to a host protected with FortiClient, FortiClient can send the files on the USB drive to FortiSandbox for analysis, before allowing the user access to the files" ― further confirming the Delivery stage focus.
A
Explanation:
From the FortiClient EMS Integration lesson, the Study Guide states that FortiSandbox and FortiClient EMS integration helps break the kill chain by monitoring all downloads, removable media, mapped network drives, and email client file downloads ― intercepting threats at the Delivery stage before they can execute on the endpoint.
Additionally, from the Attack Methodologies section: "When a USB is attached to a host protected with FortiClient, FortiClient can send the files on the USB drive to FortiSandbox for analysis, before allowing the user access to the files" ― further confirming the Delivery stage focus.
Question #12
To allow access to the FortiSandbox GUI the administrator must configure an IP address and a default gateway.
Which two commands must the administrator use to accomplish this task? (Choose two answers)
- A . set default-gw <IP Address>
- B . set api-port port1
- C . set admin-port port1
- D . set port1-ip <IP address>
Correct Answer: A, D
A, D
Explanation:
From the Deployment and System Settings lesson, the Study Guide explicitly states:
"Initial port1 IP configuration must be performed from the console, using the commands shown on this slide. If your management computer is on a separate subnet from FortiSandbox, you must specify a gateway address using the commands shown on this slide."
The two required commands are:
set port1-ip <IP address> ― to assign the IP address to port1 for GUI access
set default-gw <IP Address> ― to configure the default gateway so the management computer can reach FortiSandbox from a different subnet
Option B (set api-port port1) is for API access configuration, and Option C (set admin-port port1) is not a valid FortiSandbox CLI command for this purpose.
A, D
Explanation:
From the Deployment and System Settings lesson, the Study Guide explicitly states:
"Initial port1 IP configuration must be performed from the console, using the commands shown on this slide. If your management computer is on a separate subnet from FortiSandbox, you must specify a gateway address using the commands shown on this slide."
The two required commands are:
set port1-ip <IP address> ― to assign the IP address to port1 for GUI access
set default-gw <IP Address> ― to configure the default gateway so the management computer can reach FortiSandbox from a different subnet
Option B (set api-port port1) is for API access configuration, and Option C (set admin-port port1) is not a valid FortiSandbox CLI command for this purpose.
Question #13
You are asked to configure a FortiSandbox HA cluster. Port 4 on the primary and secondary nodes is dedicated for HA-specific communication.
Which command must you use to configure the primary node? (Choose one answer)
- A . hc-settings -sc -tN -nPrimaryNode -cFSAGrp -p -iport4
- B . hc-settings -sc -tR -nPrimaryNode -cFSAGrp -p -iport4
- C . hc-settings -sc -tF -nPrimaryNode -cFSAGrp -p -iport4
- D . hc-settings -sc -tM -nPrimaryNode -cFSAGrp -p -iport4
Correct Answer: D
D
Explanation:
The Study Guide states that HA is configured from the CLI and that “the main HA cluster CLI commands are hc-settings, hc-slave, and hc-status”. It also explains that “You use the hc-settings command and options to configure the main HA settings… node alias, group name, group password, and the HA interface.” The same HA section further says that the primary and secondary nodes must have a dedicated HA communication interface, and specifically notes that “port4 in this example” is the HA interface between them.
On the primary-node example configuration shown on page 137 of the uploaded study guide, the command uses -tM for the primary node with -iport4 for the HA interface. That directly matches option
D. The other options use different node-type flags and do not correspond to the primary-node example. Therefore, the correct command is hc-settings -sc -tM -nPrimaryNode -cFSAGrp – p<password> -iport4.
D
Explanation:
The Study Guide states that HA is configured from the CLI and that “the main HA cluster CLI commands are hc-settings, hc-slave, and hc-status”. It also explains that “You use the hc-settings command and options to configure the main HA settings… node alias, group name, group password, and the HA interface.” The same HA section further says that the primary and secondary nodes must have a dedicated HA communication interface, and specifically notes that “port4 in this example” is the HA interface between them.
On the primary-node example configuration shown on page 137 of the uploaded study guide, the command uses -tM for the primary node with -iport4 for the HA interface. That directly matches option
D. The other options use different node-type flags and do not correspond to the primary-node example. Therefore, the correct command is hc-settings -sc -tM -nPrimaryNode -cFSAGrp – p<password> -iport4.
1 2
