FCP_FSA_AD-5.0 Exam Preparation Material | Fortinet NSE 5 - FortiSandbox 5.0 Administrator

Prepare for the FCP_FSA_AD-5.0 with reliable study materials, practice questions, and key exam insights.

Prepare for the FCP_FSA_AD-5.0 Fortinet NSE 5 - FortiSandbox 5.0 Administrator exam with CertQueen's independently developed study resources. Review important concepts, practice scenario-based questions, and use clear explanations to identify areas that require further study.

Question#1

You are asked to configure a FortiSandbox HA cluster. Port 4 on the primary and secondary nodes is dedicated for HA-specific communication.
Which command must you use to configure the primary node? (Choose one answer)

A. hc-settings -sc -tN -nPrimaryNode -cFSAGrp -p -iport4
B. hc-settings -sc -tR -nPrimaryNode -cFSAGrp -p -iport4
C. hc-settings -sc -tF -nPrimaryNode -cFSAGrp -p -iport4
D. hc-settings -sc -tM -nPrimaryNode -cFSAGrp -p -iport4

Explanation:
The Study Guide states that HA is configured from the CLI and that “the main HA cluster CLI commands are hc-settings, hc-slave, and hc-status”. It also explains that “You use the hc-settings command and options to configure the main HA settings… node alias, group name, group password, and the HA interface.” The same HA section further says that the primary and secondary nodes must have a dedicated HA communication interface, and specifically notes that “port4 in this example” is the HA interface between them.
On the primary-node example configuration shown on page 137 of the uploaded study guide, the command uses -tM for the primary node with -iport4 for the HA interface. That directly matches option
D. The other options use different node-type flags and do not correspond to the primary-node example. Therefore, the correct command is hc-settings -sc -tM -nPrimaryNode -cFSAGrp - p<password> -iport4.

Question#2

You notice a recent file downloaded by some end stations is exhibiting malware behavior, however, on the sandbox the file is rated clean. After further investigation you determine that only end stations using the Opera browser are being affected.
What must you do to prevent these infections? (Choose one answer)

A. Enable the STIX/TAXII Integration setting on FortiSandbox.
B. Configure a custom VM to use the same browser as the exploited end stations.
C. Modify the scan profile to include the malware file type.
D. Change the job queue priority to process web-based files first.

Explanation:
The best answer is B. The Study Guide explains that under VM settings, “FortiSandbox has a Browser selection that allows you to choose which internet browser the VM instance will use. This helps to customize the test using an internet browser that more closely resembles the user’s environment or just monitor if the test delivers different results.” It also states that the default browser choices are Internet Explorer, Firefox, Chrome, and Edge. In addition, the guide says that “The VM images provided by Fortinet might not suit your needs… You can generate a custom VM that fits your organization’s needs and upload it to FortiSandbox.”
Because only endpoints using Opera are affected, the clean verdict likely occurred because the sandbox environment does not accurately reproduce the exploited browser environment. The most effective fix is to make the sandbox environment match the real target environment more closely by using a custom VM with the same browser behavior as the affected endpoints. The other answers do not address the root cause. STIX/TAXII is unrelated, changing the scan profile file type does not solve a browser-specific exploit path, and job queue priority affects order, not analysis fidelity. Therefore, the required action is to configure a custom VM to use the same browser as the exploited end stations.

Question#3

Review the exhibits.






A FortiMail device is integrated with a FortiSandbox device.
What is the expected behavior on FortiMail for emails that require FortiSandbox inspection? (Choose one answer)

A. FortiMail will queue emails for up to 5 minutes during URL rating errors before submitting URLs to FortiSandbox
B. FortiMail will queue emails for up to 30 minutes to allow FortiSandbox to finish scanning all attachments and URLs.
C. FortiMail will not send attachments and URLs to FortiSandbox if their rating exists in the local cache.
D. FortiMail will deliver all emails to the destination after the emails pass all local security checks.

Explanation:
From the FortiMail Integration lesson, the Study Guide explicitly states:
"The Scan timeout value determines how long FortiMail will wait for a response from FortiSandbox. The default is 30 minutes. So, if after 30 minutes FortiSandbox is unable to generate a verdict, FortiMail will release the email to the end user."
"SMTP is a store-and-forward protocol. This allows FortiMail to queue the email while FortiSandbox inspects all submitted samples. FortiMail will release the email only if there is a scan timeout event, or FortiSandbox returns a clean verdict."
The Integration Settings exhibit clearly confirms Scan timeout = 30 minutes, and the AV Profile shows both Attachment analysis and URL analysis are enabled ― meaning FortiMail will hold/queue emails for up to 30 minutes while FortiSandbox completes inspection of all attachments and URLs before taking action.

Question#4

You are asked to create some custom VMs to better represent your security environment. In which two FortiSandbox deployments is this supported? (Choose two answers)

A. Private cloud
B. Azure non-nested mode
C. Device-based
D. FortiSandbox Cloud

Explanation:
From the Scanning and Rating Components lesson, the Study Guide explicitly states:
"FortiSandbox allows you to modify the number of CPUs and memory assigned to a custom VM. This feature is supported on hardware models and private cloud VMs."
Hardware models = Device-based (Option C)
Private cloud VMs = Private cloud (Option A)
Azure non-nested mode and FortiSandbox Cloud do not support custom VM creation as per the Study Guide.

Question#5

There is a connectivity problem between FortiSandbox and the FortiGuard distribution servers. You observe that a firewall located between FortiSandbox and the internet allows traffic on ports TCP/4443, UDP/8888, and UDP/53.
What is the cause of the issue? (Choose one answer)

A. They must allow TCP 443 out
B. They must allow TCP 8890 out
C. They must allow UDP 514 out
D. They must allow UDP 443 out

Explanation:
From the Deployment and System Settings lesson, the Study Guide states:
"The test-network command checks FortiGuard services as its last set of validation tests. These include the FortiGuard distribution network (FDN) accessibility, FDN contract expiration, web filtering service, and the community cloud service. All these FortiGuard services should be reachable and valid for FortiSandbox to be effective."
"The diagnose-debug fdn command provides details around FortiSandbox and the FortiGuard Distribution Network (FDN) communication and updates."
FortiGuard Distribution Network (FDN) communication requires TCP/443 for HTTPS-based update and licensing communication. The current firewall rules allow TCP/4443 (API/management), UDP/8888 (FortiGuard queries), and UDP/53 (DNS), but TCP/443 is missing ― which is the standard port required for FortiGuard FDN connectivity and license validation

Exam CodeFCP_FSA_AD-5.0
Q & A: 42 Q&As         Updated:  Sep 22,2026

 

 Access Complete FCP_FSA_AD-5.0 Preparation Material

What This FCP_FSA_AD-5.0 Study Resource Helps You Do

Review Key Concepts

Review the technologies, products, processes, and practical skills covered by the current FCP_FSA_AD-5.0 exam objectives.

Practice Scenario-Based Questions

Work through independently developed questions designed to strengthen your understanding of technical scenarios and decision-making.

Identify Knowledge Gaps

Use your results and the provided explanations to find weaker areas and focus your study more effectively.

How to Use This FCP_FSA_AD-5.0 Preparation Material

Review the Exam Scope

Start by reviewing the topics covered by the FCP_FSA_AD-5.0 exam. Compare them with the official exam objectives to understand the required technologies, operational tasks, and practical skills, then identify the areas that deserve the most attention.

Practice Independently

Complete a focused set of practice questions for each topic. On your first attempt, avoid referring to notes, answers, or other study resources so that you can evaluate your current understanding more accurately.

Study the Explanations

Review the answers and explanations after completing each practice session. Understand why the correct option is appropriate for the given scenario and why the other options may be incorrect or less suitable.

Close Knowledge Gaps

Keep track of incorrect answers, unfamiliar concepts, and weaker knowledge areas. Review these topics using official documentation and practical experience, then answer the related questions again to reinforce your understanding and monitor your progress.

Independent FCP_FSA_AD-5.0 Preparation Resource

CertQueen independently develops its certification study materials for educational purposes. The practice questions are not copied from, recalled from, or presented as live or official exam questions.

CertQueen is not affiliated with, endorsed by, sponsored by, or authorized by any certification provider. Certification names, exam codes, product names, and related trademarks are the property of their respective owners and are referenced only for identification and educational purposes.

Exam Code: FCP_FSA_AD-5.0
Q & A: 42 Q&As
Updated:  Sep 22,2026

 

 Access Complete FCP_FSA_AD-5.0 Preparation Material