01. During a severe attack an operator notices that attack log entries, which had been appearing at five-minute intervals, begin arriving every minute.
What has happened?
a) The local log filled, so the appliance began flushing partial records more frequently
b) The event is interrupt-driven and its drop count exceeded the system thresholds
c) The appliance switched from periodic to interrupt-driven reporting when the policy entered Prevention Mode
d) An administrator changed the logging interval while the attack was under way
02. What does Cloud Signaling do when an attack exceeds the configured rate for a service protection policy?
a) It signals a Fortinet cloud DDoS partner that a large attack is under way and sends attack log detail
b) It moves the affected policy into Prevention Mode automatically for the duration of the attack
c) It redirects the traffic through the appliance's second interface pair for scrubbing
d) It raises the local thresholds temporarily so the appliance can absorb the additional volume
03. An operator is considering the ACK Cookie method rather than SYN Cookie for a protected zone.
What condition makes ACK Cookie a reasonable choice?
a) Sufficient reverse path bandwidth to carry the additional packets it generates
b) A deployment configured for asymmetric operation where the return path is not visible
c) A protected service that uses long-lived connections rather than many short ones
d) A policy that has completed its learning period and moved to Prevention Mode
04. FortiDDoS models traffic using a historical baseline that weights recent data more heavily, a trend or slope component, and a seasonality component.
What does the seasonality component contribute that the other two cannot?
a) Recognition that traffic grows steadily over months as users are added
b) Recognition that the most recent observations describe current conditions better than older ones do
c) Recognition that an attack in progress should be excluded from the statistics being gathered
d) Recognition that traffic repeats a pattern by time of day and day of week
05. Which deployment arrangement places FortiDDoS outside the traffic path, so that it observes a copy of the traffic and cannot drop any of it?
a) LACP port channel
b) Tap Mode
c) Built-in fail-open bypass
d) External bypass
06. Traffic to a protected server is being dropped even though the Layer 3 rate for that policy is well under its threshold.
What does this indicate about how the limits are applied?
a) The Layer 3 threshold is advisory and only the Layer 7 limits are actually enforced on traffic
b) The lowest configured threshold across all layers is the only one that ever takes effect
c) The layers are evaluated in order, stopping at the first one satisfied
d) A packet must satisfy the applicable threshold at every layer
07. How is configuration kept consistent between the two nodes of a FortiDDoS HA cluster?
a) Each node writes its own changes independently and the pair reconciles by keeping whichever version carries the newer timestamp
b) The primary pushes its configuration to the secondary at initialization and periodically afterwards
c) Both nodes pull their configuration, and their thresholds, from a management station on a schedule
d) An administrator exports the configuration from one node and imports it on the other after every change is made
08. Why is service degradation treated as a DDoS outcome in its own right, rather than only as a step on the way to an outage?
a) Degradation indicates an application-layer attack
b) Only during degradation can mitigation still be applied
c) Only degradation leaves traffic for the appliance to measure
d) A slow service is already costing the business
09. By default, how far above the configured minimum threshold may the adaptive limit allow a value to rise?
a) There is no ceiling on the estimate
b) To 100 percent of it, meaning no upward movement is permitted at all
c) To 150 percent of it
d) To 500 percent of it, giving substantial room for seasonal growth over time
10. In a reflected amplification attack, why does the attacker place the victim's address in the source field of the queries it sends?
a) So the responses look like replies to a session already open
b) So the victim's firewall accepts the queries as internally originated traffic
c) So the third-party servers cannot record who issued the queries
d) So the third-party servers send their larger responses to the victim