View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps
Question 21. Which FortiGate feature allows administrators to authenticate users through an external LDAP directory?
- DHCP Server
2. LDAP authentication
3. Traffic shaping
4. Static routing
Answer: 2. LDAP authentication
Explanation:
LDAP authentication allows FortiGate to validate user credentials against an external directory service. This can centralize user account management and reduce the need to maintain separate credentials locally on the firewall. After configuring the LDAP server and appropriate authentication settings, FortiGate can use directory-based identities in supported authentication scenarios and security policies. Administrators should ensure that the LDAP connection, server address, credentials, and security settings are correctly configured. Using centralized authentication can also simplify account administration when an organization has many users.
Question 22. Which FortiGate feature can identify users and use their identities in security policies?
- Static routing
2. VLAN trunking
3. Identity-based authentication
4. Link aggregation
Answer: 3. Identity-based authentication
Explanation:
Identity-based security allows FortiGate to associate network traffic with authenticated users and apply security controls based on user identity. Instead of relying only on IP addresses, administrators can use authenticated users or groups when defining appropriate policies. This can be particularly useful in environments where users move between devices or networks. User authentication may be integrated with supported directory and authentication services. Correct identity configuration is important because FortiGate must be able to reliably determine which authenticated user is associated with the traffic before applying identity-based controls.
Question 23. What is the primary purpose of a FortiGate address object?
- To represent an IP address, subnet, or other network destination in configuration
2. To encrypt VPN traffic
3. To update antivirus signatures
4. To monitor CPU temperature
Answer: 1. To represent an IP address, subnet, or other network destination in configuration
Explanation:
Address objects provide reusable definitions for network addresses and destinations within FortiGate configuration. An object can represent an individual IP address, subnet, address range, or other supported address type. Administrators can reference these objects in firewall policies and other configurations instead of repeatedly entering the same network information. This improves consistency and simplifies administration. When network requirements change, updating an appropriate address object can reduce the need to modify multiple policies individually. Clear naming conventions also make larger FortiGate configurations easier to understand.
Question 24. Which FortiGate feature can limit access to websites based on their reputation or category?
- Web Filter
2. Static Route
3. DHCP Relay
4. SNMP
Answer: 1. Web Filter
Explanation:
The Web Filter security profile can control access to websites according to configured categories, ratings, or filtering rules. Administrators can use this capability to restrict access to websites that do not meet organizational requirements or that present increased security risks. Web filtering is normally associated with appropriate firewall policies so traffic is inspected according to the intended security profile. The effectiveness of category-based filtering depends on the availability and accuracy of classification information. Administrators should periodically review filtering policies to ensure they continue to match organizational requirements.
Question 25. What is the purpose of a FortiGate service object?
- To define administrator permissions
2. To specify protocols and ports used by network services
3. To create backup files
4. To configure disk encryption
Answer: 2. To specify protocols and ports used by network services
Explanation:
A service object identifies network protocols and ports that can be referenced in FortiGate firewall policies. For example, services can represent common protocols such as HTTP, HTTPS, SSH, or other TCP and UDP ports. Administrators can use service definitions to control which types of traffic a policy permits. Using appropriate service objects helps keep firewall policies specific rather than allowing unnecessary ports or protocols. Custom services can also be created when applications require ports that are not adequately represented by existing predefined service definitions.
Question 26. Which FortiGate capability is used to inspect encrypted HTTPS traffic when properly configured?
- Static routing
2. SSL/SSH inspection
3. DHCP
4. VLAN tagging
Answer: 2. SSL/SSH inspection
Explanation:
SSL/SSH inspection provides FortiGate with mechanisms for inspecting encrypted traffic according to the configured inspection method. This can allow security controls to examine traffic that would otherwise be hidden by encryption. The exact inspection approach depends on the configuration and traffic requirements. Administrators must consider certificate deployment, privacy requirements, application compatibility, and performance when implementing deep inspection. Incorrectly configured inspection can cause certificate warnings or application problems. Therefore, encrypted-traffic inspection should be introduced carefully and tested with the applications and users affected.
Question 27. Which FortiGate feature provides centralized analysis and reporting of logs from security devices?
- FortiAnalyzer
2. FortiToken
3. FortiSwitch
4. FortiAP
Answer: 1. FortiAnalyzer
Explanation:
FortiAnalyzer provides centralized collection, analysis, reporting, and management of logs and security information from supported Fortinet devices. It can help administrators investigate events, identify security trends, and generate reports based on collected information. Centralized log analysis is especially useful when an organization operates multiple security devices because reviewing each device individually can be inefficient. FortiAnalyzer complements FortiGate logging rather than replacing the firewall’s local security functions. Proper log forwarding, storage, access control, and retention settings are important for reliable analysis.
Question 28. What is the main function of a VIP configuration on FortiGate?
- To define a virtual IP mapping for traffic reaching an internal resource
2. To create a user password
3. To configure a DHCP scope
4. To update IPS signatures
Answer: 1. To define a virtual IP mapping for traffic reaching an internal resource
Explanation:
A Virtual IP (VIP. can map an externally reachable address and port to an internal server or service. This is commonly used when an internal resource needs to be accessed from an external network through a FortiGate. The VIP is normally referenced by a firewall policy that controls whether the incoming traffic is permitted. Proper configuration requires careful consideration of the external address, mapped internal address, ports, and security policy. Administrators should expose only the services that are actually required and protect them with appropriate controls.
Question 29. Which FortiGate feature helps detect devices attempting to access the network without meeting defined access requirements?
- Network Access Control
2. Web caching
3. Static routing
4. DNS forwarding
Answer: 1. Network Access Control
Explanation:
Network Access Control (NAC. helps organizations control network access according to device identity, authentication, or compliance-related requirements. Depending on the deployment, devices can be evaluated and assigned appropriate access based on defined policies. This can reduce the risk associated with unmanaged or unauthorized endpoints connecting to protected network segments. NAC works as part of a broader access-control architecture and may interact with other Fortinet components. Administrators should define appropriate access requirements and ensure that legitimate devices are not unnecessarily prevented from obtaining required connectivity.
Question 30. Which FortiGate routing protocol is designed to exchange routing information dynamically between routers?
- HTTP
2. SMTP
3. OSPF
4. FTP
Answer: 3. OSPF
Explanation:
Open Shortest Path First (OSPF. is a dynamic routing protocol that allows routers to exchange information about reachable networks and calculate suitable paths. On FortiGate, OSPF can be used in network environments where manually maintaining static routes would become inefficient. Dynamic routing can automatically respond to certain topology changes by updating routing information. Proper configuration includes considerations such as interfaces, areas, neighbors, authentication where required, and route filtering. Administrators should verify routing behavior carefully because incorrect routing configuration can affect connectivity across multiple network segments.
Question 31. What is the purpose of a firewall policy sequence on FortiGate?
- It determines how matching policies are evaluated
2. It controls disk formatting
3. It assigns administrator passwords
4. It encrypts configuration backups
Answer: 1. It determines how matching policies are evaluated
Explanation:
The ordering of firewall policies is important because FortiGate evaluates policies according to its policy-processing logic. A more specific rule generally needs to be positioned appropriately so that intended traffic does not match a broader rule first. If a broad allow policy is placed incorrectly, it may permit traffic that a later restrictive policy was intended to control. Administrators should therefore review policy order when troubleshooting unexpected access. Clear policy organization and regular policy reviews help reduce accidental exposure and make firewall configurations easier to maintain.
Question 32. Which FortiGate feature can restrict applications such as peer-to-peer file-sharing services?
- Application Control
2. DHCP
3. Static routing
4. Network Address Translation
Answer: 1. Application Control
Explanation:
Application Control allows FortiGate to identify supported applications and apply configured actions to their traffic. Administrators can use application signatures and categories to control applications that may consume excessive bandwidth, violate organizational policies, or introduce security concerns. The feature can be attached to appropriate firewall policies so that only traffic matching those policies receives application inspection. Application Control should be configured based on the organization’s actual requirements because blocking an application can affect legitimate business activity. Regular review helps ensure that controls remain appropriate as applications change.
Question 33. What is the purpose of a FortiGate local-in policy?
- To control traffic destined for the FortiGate itself
2. To configure external DNS servers
3. To create VLANs automatically
4. To distribute firmware updates
Answer: 1. To control traffic destined for the FortiGate itself
Explanation:
Local-in policies are used to control traffic directed to the FortiGate device rather than traffic being forwarded through it. This distinction is important because normal firewall policies primarily regulate traffic passing through the firewall. Local-in controls can help restrict access to management services or other services hosted directly on the FortiGate. Administrators can use them to reduce unnecessary exposure of the device’s own services. Careful configuration is required because an overly restrictive local-in policy can prevent legitimate administrative or operational access to the FortiGate.
Question 34. Which protocol is commonly used for secure remote command-line administration of FortiGate?
- Telnet
2. FTP
3. SSH
4. HTTP
Answer: 3. SSH
Explanation:
Secure Shell (SSH. provides encrypted command-line communication between an administrator and the FortiGate device. It is commonly used when administrators need CLI access without relying on the graphical management interface. Encryption helps protect authentication information and command traffic while it travels across the network. SSH access should be restricted to authorized administrators and appropriate management sources. Unencrypted protocols such as Telnet provide weaker protection because credentials and session information can potentially be exposed. Combining SSH with strong authentication and access restrictions improves administrative security.
Question 35. What is the purpose of FortiGate DNS filtering?
- To configure routing protocols
2. To control access based on DNS queries and domain information
3. To increase physical interface speed
4. To create IPsec encryption keys
Answer: 2. To control access based on DNS queries and domain information
Explanation:
DNS filtering allows FortiGate to apply security controls based on domain-name information obtained through DNS activity. Depending on the configured service and policy, domains can be allowed, blocked, or handled according to security classifications. DNS filtering can help prevent users from reaching known malicious or unwanted domains before a connection is established. It is one layer of protection and should be combined with other controls such as firewall policies, web filtering, and endpoint protection. Administrators should monitor results to identify false positives and adjust policies appropriately.
Question 36. Which FortiGate feature can automatically block or quarantine endpoints associated with detected threats?
- Security Fabric automation
2. Static routing
3. DHCP relay
4. Link aggregation
Answer: 1. Security Fabric automation
Explanation:
Fortinet Security Fabric capabilities can coordinate security information and automated responses across supported Fortinet products. Depending on the environment and configured automation rules, detected security events can trigger actions intended to contain or respond to threats. Automated response can reduce the time between detection and containment, particularly when rapid action is required. However, automation should be carefully designed and tested because an overly aggressive response could disrupt legitimate users or services. Administrators should define clear event conditions and response actions before enabling automated remediation.
Question 37. What is the primary benefit of using configuration backups for a FortiGate?
- They increase Internet bandwidth
2. They provide a way to restore configuration after loss or failure
3. They replace firewall policies
4. They prevent all malware infections
Answer: 2. They provide a way to restore configuration after loss or failure
Explanation:
A FortiGate configuration backup preserves important device settings so they can be restored if the configuration is accidentally changed, corrupted, or lost. Backups can support recovery after hardware replacement or other operational incidents. Administrators should protect backup files because they may contain sensitive configuration information. It is also important to maintain appropriate backup versions and periodically verify that restoration procedures work as expected. A configuration backup does not automatically protect against every security threat, so it should be part of a broader operational resilience strategy.
Question 38. Which FortiGate feature can prioritize important traffic when network bandwidth is limited?
- Traffic shaping
2. Antivirus
3. Web filtering
4. Certificate inspection
Answer: 1. Traffic shaping
Explanation:
Traffic shaping can be configured to manage bandwidth consumption and prioritize selected traffic. This is useful when network capacity is limited and certain applications or services require preferential treatment. Administrators can define limits or priorities based on traffic characteristics supported by the FortiGate configuration. For example, business-critical services may receive higher priority than less important traffic. Traffic shaping does not increase the physical capacity of a network link; instead, it manages available capacity more effectively according to defined policies and service requirements.
Question 39. What should an administrator review first when a FortiGate interface cannot reach its intended gateway?
- Antivirus signatures
2. Interface addressing and routing configuration
3. Web-filter categories
4. Administrator profile names
Answer: 2. Interface addressing and routing configuration
Explanation:
When an interface cannot communicate with its intended gateway, the administrator should first verify the basic Layer 3 configuration. This includes checking the interface IP address, subnet mask or prefix, VLAN configuration where applicable, and routing information. A mismatch in addressing or an incorrect gateway can prevent connectivity before higher-level security features become relevant. Physical or link status should also be checked as part of basic troubleshooting. Starting with foundational connectivity helps isolate the problem before investigating more complex security-policy or application-level issues.
Question 40. Which practice helps reduce the risk of unauthorized FortiGate administrative access?
- Allowing management access from every interface
2. Using shared administrator accounts
3. Restricting management access and applying strong authentication
4. Disabling all logging
Answer: 3. Restricting management access and applying strong authentication
Explanation:
Restricting administrative access to authorized management interfaces and trusted sources reduces the number of locations from which attackers could attempt to reach the FortiGate management plane. Strong authentication further protects administrator accounts if credentials are exposed. Individual administrator accounts should be preferred because they provide better accountability than shared accounts. Additional controls such as MFA, appropriate administrative profiles, and logging can strengthen protection further. Management access should be reviewed periodically to ensure that obsolete sources, accounts, and services are removed when they are no longer required.