FORTISANDBOX Sample Questions & Answers
The scanning engine's architecture and how guest VMs are managed carry the most weight, alongside deployment models and high availability, integrating with the Security Fabric and third-party APIs, and reading scan results through MITRE ATT&CK-based reports.
Launch the full FORTISANDBOX simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Scanning and Rating Components · Guest VM Customization for Evasion Techniques
A multinational corporation has deployed FortiSandbox in their central datacenter. They need to analyze malware targeting different regional offices, which use localized versions of Windows. Some malware samples are known to check for specific language packs or regional settings before executing their malicious payload. How can an administrator configure FortiSandbox to effectively analyze these region-specific threats?
Show answer & explanation
Correct answer: B
To combat malware that uses geo-fencing or checks for specific system locales as an anti-evasion technique, the most effective method is to create customized guest VM images. Administrators can build a Windows VM, install the required language packs and regional settings to mimic the target environment, and then upload this custom VHD file to the FortiSandbox for use in dynamic analysis.
- Question 2Intermediate
Integrations · FortiGate Integration Fail-Open Behavior
An administrator is configuring a FortiGate to send files to FortiSandbox for inspection. They want to ensure that if FortiSandbox is busy or offline, the FortiGate will still allow the file to be downloaded by the user after a timeout, rather than blocking it indefinitely. Which setting on the FortiGate's AntiVirus profile achieves this behavior?
Show answer & explanation
Correct answer: C
The
fail-opensetting, configured via the FortiGate CLI within the antivirus settings, dictates the behavior when a connection to the FortiSandbox cannot be established or a verdict is not returned in time. Enablingfail-openinstructs the FortiGate to permit the traffic, representing a 'fail-open' stance. Disabling it would cause the FortiGate to block the traffic, a 'fail-close' stance. - Question 3Intermediate
Deployment and System Settings · Long-Term Log and Report Retention
A healthcare organization is required by compliance regulations to store all malware analysis data, including detailed reports and tracer logs, for a minimum of seven years. The organization's FortiSandbox 1000F has limited onboard storage. Which solution allows the organization to meet this long-term retention requirement while integrating with their existing infrastructure?
Show answer & explanation
Correct answer: B
FortiAnalyzer is the designated Fortinet solution for centralized logging, analytics, and long-term data retention. By integrating FortiSandbox with FortiAnalyzer, all analysis logs and reports can be sent to the FortiAnalyzer, which can be equipped with large storage arrays. The administrator can then configure data retention policies on the FortiAnalyzer to meet the seven-year compliance requirement.
- Question 4Beginner
Scanning and Rating Components · Tracer Engine Functionality
What is the primary function of the 'Tracer Engine' within the FortiSandbox dynamic analysis environment?
Show answer & explanation
Correct answer: B
The Tracer Engine is the core component of dynamic analysis. It hooks into the guest VM's operating system to monitor and record all actions taken by the executed file, such as file system modifications, registry changes, network connections, and process creation. This detailed activity log, known as the tracer log, is then analyzed by the rating engine to determine if the behavior is malicious.
- Question 5Intermediate
Results Analysis and Reporting · Interpreting Scan Verdicts vs. Behavior
A system administrator is reviewing the scan results for a submitted file and notices the verdict is 'Benign', but the report indicates several suspicious behaviors were detected, such as modifying system files and attempting to disable security software. What is the most likely reason for this discrepancy?
Show answer & explanation
Correct answer: C
FortiSandbox's rating engine processes multiple inputs. Even if the behavioral analysis engine flags suspicious activities, a match on a whitelist (either the global FortiGuard whitelist or a locally configured one) will override the behavioral score and force a 'Benign' verdict. This is a common scenario for legitimate software installers or system administration tools that perform actions similar to malware.
- Question 6Advanced
Integrations · ICAP Integration for Web Applications
An e-commerce company wants to leverage FortiSandbox to scan all user-uploaded product images for embedded malware before they are published. The web application is hosted on-premises and has a high volume of uploads. The company needs a solution that does not require modifying the web application's file upload logic. Which deployment and integration method is most suitable for this use case?
Show answer & explanation
Correct answer: D
Using FortiSandbox as an Internet Content Adaptation Protocol (ICAP) server is the ideal solution. Many web proxies and load balancers can act as ICAP clients, intercepting HTTP file uploads and forwarding them to the FortiSandbox ICAP server for analysis before they reach the web application. This provides inline scanning without requiring any code changes to the application itself and is well-suited for high-volume web traffic.
- Question 7IntermediateSelect 2
Scanning and Rating Components · Enabling Linux VM Analysis
A security team needs to analyze a suspicious Linux ELF binary. The company's FortiSandbox currently only has Windows guest VMs installed. What is the correct procedure to enable dynamic analysis for this Linux file? (Select TWO)
Show answer & explanation
Correct answers: A, C
Optional guest VM images, including those for Linux, are not installed by default. They must be explicitly downloaded from the FortiGuard 'Cloud VM' service via the FortiSandbox GUI.
After downloading the VM image, it is not automatically active. The administrator must navigate to the 'VM Settings' page, locate the new Linux VM, and enable it for use in dynamic analysis.
- Question 8BeginnerSelect 2
Deployment and System Settings · Deployment Modes and Network Connections
Which two deployment modes require a physical connection to a SPAN or mirror port on a network switch? (Select TWO)
Show answer & explanation
Correct answers: B, D
Sniffer Mode is designed for out-of-band inspection. It requires connecting one of its interfaces to a SPAN/mirror port on a switch to passively monitor network traffic and extract files for analysis without being in the direct path of traffic.
Sniffer with Collector Mode also uses a SPAN/mirror port for sniffing traffic. In this mode, the appliance not only analyzes files but also collects and forwards network metadata to a FortiAnalyzer or other syslog server.
- Question 9Intermediate
Integrations · Troubleshooting FortiMail Integration
A FortiSandbox is integrated with FortiMail. An administrator notices that URLs embedded in emails are being scanned, but file attachments are not. Both devices are part of the Security Fabric and show a green, connected status. What is the most likely misconfiguration on the FortiMail device?
Show answer & explanation
Correct answer: C
On FortiMail, URL scanning and attachment scanning are configured in different security profiles. URL sandboxing is typically enabled in the AntiSpam profile or a Content Profile. Attachment sandboxing, however, must be explicitly enabled within the AntiVirus profile that is being applied to the email traffic. If this option is not checked, attachments will not be submitted, even if the URL scanning is working correctly.
- Question 10Advanced
Deployment and System Settings · Hybrid Deployment for Internal and Perimeter Protection
Case Study
A global logistics company, GlobalShip, is deploying a FortiSandbox 3000F cluster in their primary datacenter to enhance their threat detection capabilities. The company has a strict security policy that requires all files traversing their core network, including internal file transfers, to be inspected for malware. They have a core switch with SPAN port capabilities.
The security team has two main objectives. First, they must inspect all traffic without introducing any latency or becoming a point of failure in the network. Second, they need to implement a mechanism to immediately block newly discovered threats at their edge FortiGate firewalls, which protect their internet perimeter. The edge FortiGates are already part of a Security Fabric.
To meet these requirements, the network architect has proposed a specific FortiSandbox configuration and integration strategy. The solution must satisfy both the zero-latency internal inspection requirement and the rapid perimeter blocking requirement.
Which solution best meets all of GlobalShip's requirements?
Show answer & explanation
Correct answer: D
This hybrid approach meets both requirements perfectly. Using Sniffer Mode for internal traffic inspection fulfills the zero-latency/no point of failure requirement as it is out-of-band. Simultaneously, connecting the FortiSandbox's management port to the Security Fabric allows it to automatically share threat intelligence (malware hashes) with the edge FortiGates. The FortiGates can then use this intelligence to block newly discovered threats in real-time, satisfying the rapid perimeter blocking requirement.
Ready for the real thing?
The full FORTISANDBOX simulator has every exam-style question, timed mode, and instant scoring.