FORTINET CERTIFIED FUNDAMENTALS IN
CYBERSECURITY EXAM WITH QUESTIONS
AND VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. Which statement best describes the primary goal of cybersecurity?
A. To eliminate all computer hardware failures
B. To protect information systems, networks, applications, and data from
unauthorized access, disruption, alteration, or destruction
C. To increase internet bandwidth
D. To replace all manual business processes
Answer: B. To protect information systems, networks, applications,
and data from unauthorized access, disruption, alteration, or
destruction
Rationale: Cybersecurity is concerned with protecting the
confidentiality, integrity, and availability of information and
technology resources. It encompasses preventive, detective, and
corrective controls designed to reduce cyber risk.
2. An organization discovers that an attacker accessed confidential
customer records without authorization but did not modify or
delete them. Which cybersecurity objective was primarily
violated?
A. Availability
B. Integrity
1
,C. Confidentiality
D. Redundancy
Answer: C. Confidentiality
Rationale: Confidentiality ensures that information is accessible only
to authorized individuals, systems, or processes. Unauthorized
disclosure or access to customer records is a direct confidentiality
violation.
3. A ransomware attack encrypts a company's files so employees can
no longer access critical business documents. Which element of the
CIA triad is primarily affected?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: C. Availability
Rationale: Availability means that authorized users can access systems
and information when needed. Ransomware prevents legitimate access
to data, making availability the primary affected security objective,
although ransomware can also affect integrity.
4. A threat actor modifies the contents of a company's financial
database without authorization. Which security principle has been
directly compromised?
A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
2
,Answer: A. Integrity
Rationale: Integrity protects information from unauthorized
modification, deletion, or manipulation. Altering financial records
without authorization is therefore an integrity breach.
5. Which scenario is the best example of a phishing attack?
A. An attacker physically steals a server
B. An attacker sends a fraudulent email pretending to be a bank and asks
the recipient to enter login credentials
C. An administrator installs a software update
D. A firewall blocks an unauthorized connection
Answer: B. An attacker sends a fraudulent email pretending to be a
bank and asks the recipient to enter login credentials
Rationale: Phishing is a social-engineering technique in which
attackers use deceptive communications to trick victims into revealing
information, opening malicious content, transferring money, or
performing another attacker-controlled action.
6. A user receives an email claiming to be from the company's IT
department. The message says the user's account will be disabled
unless they immediately click a link and verify their password.
What is the strongest indication that this could be phishing?
A. The email contains the company's logo
B. The message creates urgency and requests sensitive credentials
through a link
C. The email contains a greeting
D. The email was received during working hours
3
, Answer: B. The message creates urgency and requests sensitive
credentials through a link
Rationale: Urgency, threats of account suspension, unexpected
credential requests, and suspicious links are classic phishing
indicators. Attackers commonly exploit fear and urgency to bypass
careful decision-making.
7. Which type of malware is specifically designed to encrypt a
victim's files and demand payment for restoration?
A. Spyware
B. Ransomware
C. Adware
D. Rootkit
Answer: B. Ransomware
Rationale: Ransomware encrypts or otherwise locks access to data and
typically demands payment from the victim. Modern ransomware
campaigns may also steal data before encryption and threaten to
publish it.
8. What is the primary characteristic of a Trojan?
A. It automatically replicates itself across networks without user
interaction
B. It disguises itself as legitimate or useful software to trick users into
executing it
C. It only affects network cables
D. It exclusively encrypts databases
Answer: B. It disguises itself as legitimate or useful software to trick
users into executing it
4
CYBERSECURITY EXAM WITH QUESTIONS
AND VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. Which statement best describes the primary goal of cybersecurity?
A. To eliminate all computer hardware failures
B. To protect information systems, networks, applications, and data from
unauthorized access, disruption, alteration, or destruction
C. To increase internet bandwidth
D. To replace all manual business processes
Answer: B. To protect information systems, networks, applications,
and data from unauthorized access, disruption, alteration, or
destruction
Rationale: Cybersecurity is concerned with protecting the
confidentiality, integrity, and availability of information and
technology resources. It encompasses preventive, detective, and
corrective controls designed to reduce cyber risk.
2. An organization discovers that an attacker accessed confidential
customer records without authorization but did not modify or
delete them. Which cybersecurity objective was primarily
violated?
A. Availability
B. Integrity
1
,C. Confidentiality
D. Redundancy
Answer: C. Confidentiality
Rationale: Confidentiality ensures that information is accessible only
to authorized individuals, systems, or processes. Unauthorized
disclosure or access to customer records is a direct confidentiality
violation.
3. A ransomware attack encrypts a company's files so employees can
no longer access critical business documents. Which element of the
CIA triad is primarily affected?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: C. Availability
Rationale: Availability means that authorized users can access systems
and information when needed. Ransomware prevents legitimate access
to data, making availability the primary affected security objective,
although ransomware can also affect integrity.
4. A threat actor modifies the contents of a company's financial
database without authorization. Which security principle has been
directly compromised?
A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
2
,Answer: A. Integrity
Rationale: Integrity protects information from unauthorized
modification, deletion, or manipulation. Altering financial records
without authorization is therefore an integrity breach.
5. Which scenario is the best example of a phishing attack?
A. An attacker physically steals a server
B. An attacker sends a fraudulent email pretending to be a bank and asks
the recipient to enter login credentials
C. An administrator installs a software update
D. A firewall blocks an unauthorized connection
Answer: B. An attacker sends a fraudulent email pretending to be a
bank and asks the recipient to enter login credentials
Rationale: Phishing is a social-engineering technique in which
attackers use deceptive communications to trick victims into revealing
information, opening malicious content, transferring money, or
performing another attacker-controlled action.
6. A user receives an email claiming to be from the company's IT
department. The message says the user's account will be disabled
unless they immediately click a link and verify their password.
What is the strongest indication that this could be phishing?
A. The email contains the company's logo
B. The message creates urgency and requests sensitive credentials
through a link
C. The email contains a greeting
D. The email was received during working hours
3
, Answer: B. The message creates urgency and requests sensitive
credentials through a link
Rationale: Urgency, threats of account suspension, unexpected
credential requests, and suspicious links are classic phishing
indicators. Attackers commonly exploit fear and urgency to bypass
careful decision-making.
7. Which type of malware is specifically designed to encrypt a
victim's files and demand payment for restoration?
A. Spyware
B. Ransomware
C. Adware
D. Rootkit
Answer: B. Ransomware
Rationale: Ransomware encrypts or otherwise locks access to data and
typically demands payment from the victim. Modern ransomware
campaigns may also steal data before encryption and threaten to
publish it.
8. What is the primary characteristic of a Trojan?
A. It automatically replicates itself across networks without user
interaction
B. It disguises itself as legitimate or useful software to trick users into
executing it
C. It only affects network cables
D. It exclusively encrypts databases
Answer: B. It disguises itself as legitimate or useful software to trick
users into executing it
4