View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps
Question 41. Which FortiGate feature is used to provide redundancy between two FortiGate devices?
- Web filtering
2. High Availability (HA.
3. Application Control
4. Traffic shaping
Answer: 2. High Availability (HA.
Explanation:
FortiGate High Availability (HA. allows multiple FortiGate devices to operate together as a cluster to improve availability and provide redundancy. In an HA configuration, devices can coordinate their roles and share relevant state information depending on the selected HA mode and configuration. If one device becomes unavailable, another cluster member can continue providing firewall services. HA is particularly useful for environments where uninterrupted network security services are important. Proper heartbeat connectivity, device configuration, and HA parameters are essential for reliable cluster operation.
Question 42. What is the primary purpose of FortiGate session synchronization in an HA cluster?
- To synchronize active session information between cluster members
2. To assign IP addresses to users
3. To classify websites
4. To update antivirus signatures
Answer: 1. To synchronize active session information between cluster members
Explanation:
Session synchronization allows relevant active connection information to be shared between FortiGate devices in an HA environment. Maintaining session information can help reduce disruption when traffic processing moves between cluster members after a failover. The exact information synchronized depends on the HA configuration and supported features. Session synchronization is different from configuration synchronization, although both can be important in an HA deployment. Administrators should verify that HA links and synchronization settings are properly configured so the cluster can operate as intended during normal operation and failover events.
Question 43. Which FortiGate component determines the next hop for traffic based on the destination IP address?
- Antivirus
2. Web Filter
3. Routing table
4. Application Control
Answer: 3. Routing table
Explanation:
The routing table contains information FortiGate uses to determine where packets should be forwarded based on their destination addresses. When traffic arrives, FortiGate evaluates available routes and selects an appropriate matching route according to its routing logic. The selected route identifies the next hop or outgoing interface required to forward the packet. Routing and firewall policy processing are separate functions. A correct route does not automatically permit traffic; a suitable firewall policy may also be required. Troubleshooting should therefore consider both routing and security-policy decisions.
Question 44. Which FortiGate feature can protect users from domains associated with known malicious activity?
- DNS Filter
2. Link aggregation
3. DHCP Server
4. Static routing
Answer: 1. DNS Filter
Explanation:
DNS filtering can help protect users by applying controls to domain-name queries and identifying domains associated with unwanted or malicious activity. Depending on the configured service and policies, FortiGate can block or otherwise handle requests for domains that match defined security categories or filtering rules. DNS filtering provides an additional security layer because it can prevent access attempts before a connection to the destination is established. Administrators should combine DNS filtering with other controls because no single security mechanism provides complete protection against all threats.
Question 45. What is the purpose of a FortiGate firewall policy action set to DENY?
- It creates a VPN tunnel
2. It blocks traffic matching the policy
3. It assigns a DHCP address
4. It enables application inspection
Answer: 2. It blocks traffic matching the policy
Explanation:
A firewall policy configured with a deny action prevents traffic that matches the policy conditions from being allowed through the FortiGate. Matching conditions can include source and destination addresses, interfaces, services, users, schedules, and other supported criteria. Deny policies can be useful for explicitly blocking specific traffic when the security design requires it. Administrators should also consider policy order because an earlier matching policy may process traffic before a later deny rule is evaluated. Regular policy reviews help ensure that intended restrictions remain effective.
Question 46. Which feature allows FortiGate to inspect files for malicious content as traffic passes through the firewall?
- Static routing
2. VLAN configuration
3. Antivirus inspection
4. DHCP relay
Answer: 3. Antivirus inspection
Explanation:
Antivirus inspection examines supported network traffic and files for signs of malicious software according to the configured FortiGate security profile. When malicious content is detected, the configured action can be applied to the traffic or file. Antivirus inspection is normally enabled through a firewall policy that has an appropriate security profile attached. Inspection capabilities can depend on traffic type, protocol, and configuration. Administrators should maintain current security information and review inspection results to ensure the profile provides appropriate protection without unnecessarily disrupting legitimate business traffic.
Question 47. What is the purpose of an administrative profile on FortiGate?
- To define permissions available to an administrator
2. To create VPN encryption keys
3. To assign network addresses
4. To control web categories
Answer: 1. To define permissions available to an administrator
Explanation:
An administrative profile determines what areas and functions of the FortiGate configuration an administrator can access or modify. This supports role-based administration and the principle of least privilege. For example, an administrator may be permitted to view certain configuration areas while another authorized administrator may have broader modification privileges. Using appropriate administrative profiles reduces the risk of unnecessary configuration changes. Organizations should assign permissions according to job responsibilities and periodically review administrator privileges to remove access that is no longer required.
Question 48. Which FortiGate protocol is commonly used to synchronize time with a reliable time source?
- FTP
2. NTP
3. SMTP
4. TFTP
Answer: 2. NTP
Explanation:
Network Time Protocol (NTP. is used to synchronize system clocks with configured time sources. Accurate time is important for FortiGate because timestamps are used in logs, security events, troubleshooting, authentication processes, and other operational functions. Consistent timestamps across network devices also make event correlation easier when investigating incidents. Administrators should configure reliable NTP sources and verify that the FortiGate can reach them. Time synchronization does not replace other security controls, but it provides an important foundation for accurate monitoring and reliable event analysis.
Question 49. Which FortiGate feature can identify suspicious network activity by comparing traffic against known attack signatures?
- IPS
2. DHCP
3. NAT
4. Static routing
Answer: 1. IPS
Explanation:
The Intrusion Prevention System (IPS. uses signatures and inspection techniques to identify traffic patterns associated with known attacks and suspicious activity. When a matching event is detected, FortiGate can apply the action configured in the IPS profile, such as allowing, monitoring, or blocking the traffic depending on the policy. IPS should be configured according to the organization’s security requirements and supported traffic types. Regular updates to security signatures are important because new vulnerabilities and attack techniques continue to emerge. IPS works alongside firewall policies and other security controls.
Question 50. What is the primary purpose of a FortiGate policy-based routing rule?
- To select a route based on additional traffic characteristics
2. To create administrator accounts
3. To scan files for malware
4. To manage web categories
Answer: 1. To select a route based on additional traffic characteristics
Explanation:
Policy-based routing allows routing decisions to consider criteria beyond the destination address used by conventional routing. Depending on configuration, administrators can direct traffic according to characteristics such as source addresses, destination addresses, interfaces, or other supported matching conditions. This can be useful when different types of traffic need to use different paths. Policy-based routing should be designed carefully because incorrect rules can send traffic through an unintended interface or gateway. Administrators should validate routing behavior after changes and monitor the resulting traffic paths.
Question 51. Which FortiGate feature provides protection by identifying malicious URLs and web destinations?
- Web Filter
2. DHCP
3. HA
4. VLAN
Answer: 1. Web Filter
Explanation:
Web Filter helps administrators control access to web destinations based on configured rules, categories, and reputation information. It can be used to prevent users from reaching websites associated with malicious activity, inappropriate content, or other prohibited categories. Web filtering is applied through appropriate firewall policies and can work alongside other inspection features. Administrators should review filtering decisions because websites can change classification and legitimate services may occasionally be affected by broad restrictions. Combining web filtering with DNS security, antivirus, and other controls provides layered protection.
Question 52. What does FortiGate central NAT provide?
- A centralized method for managing NAT rules separately from firewall policies
2. Automatic firmware upgrades
3. User password synchronization
4. Application signature updates
Answer: 1. A centralized method for managing NAT rules separately from firewall policies
Explanation:
Central NAT provides a separate framework for configuring network address translation rules rather than defining source NAT behavior directly within individual firewall policies. This can be useful in environments where administrators need more centralized control over NAT mappings. The exact configuration depends on the FortiGate operating mode and network requirements. Administrators should understand how central NAT interacts with firewall policies and routing before enabling or modifying it. Careful planning is important because incorrect NAT rules can cause unexpected address translation or connectivity problems.
Question 53. Which FortiGate feature can inspect traffic for known vulnerabilities being exploited against systems?
- IPS
2. DHCP Server
3. DNS Forwarding
4. Traffic Shaping
Answer: 1. IPS
Explanation:
FortiGate IPS can inspect network traffic for patterns associated with known exploits and vulnerabilities. IPS signatures are designed to identify malicious traffic that may attempt to exploit weaknesses in applications, operating systems, or network services. When a matching signature is detected, FortiGate can apply the configured response. IPS can therefore provide a layer of protection while systems are being patched or when immediate network-level controls are required. Administrators should keep signatures current and ensure that IPS policies are appropriate for the systems and applications being protected.
Question 54. What is the purpose of a FortiGate address group?
- To combine multiple address objects for use in policies
2. To synchronize device clocks
3. To create VPN certificates
4. To configure administrator authentication
Answer: 1. To combine multiple address objects for use in policies
Explanation:
An address group combines multiple address objects into a single logical group that can be referenced by firewall policies and other supported configurations. This can simplify administration when several networks or hosts require the same security treatment. Instead of repeatedly selecting individual address objects, an administrator can reference the group. Address groups are especially useful in larger configurations where many related destinations or sources must be managed consistently. Administrators should use meaningful names and periodically review group membership to ensure policies continue to represent current network requirements.
Question 55. Which security profile is used to control application behavior on a FortiGate firewall?
- Application Control
2. DHCP
3. Static Route
4. NTP
Answer: 1. Application Control
Explanation:
Application Control identifies supported applications and allows administrators to apply actions based on application signatures and categories. It can be used to permit, monitor, or restrict applications according to organizational security and usage requirements. Application Control is configured as part of a security policy and can work with other security profiles. Because applications may use different protocols and change their communication behavior, administrators should validate application identification and policy results after deployment. Proper configuration can provide more granular control than relying only on destination ports.
Question 56. What is the primary purpose of FortiGate policy logging?
- To document traffic and security events processed by policies
2. To assign IP addresses
3. To create VLAN interfaces
4. To change routing protocols
Answer: 1. To document traffic and security events processed by policies
Explanation:
Policy logging records information about traffic processed by firewall policies according to the configured logging options. Logs can include details such as source and destination information, services, actions, timestamps, and other relevant session data. This information helps administrators troubleshoot connectivity, investigate security events, and verify policy behavior. Logging should be configured according to operational and security requirements because excessive logging can increase storage and processing demands. Administrators should also protect logs from unauthorized access and ensure that important records are retained for the required period.
Question 57. Which FortiGate feature is commonly used to connect remote users securely to an organization’s network?
- Remote-access VPN
2. Static routing only
3. Web caching
4. DHCP relay
Answer: 1. Remote-access VPN
Explanation:
A remote-access VPN provides a secure connection between an authorized remote user and the organization’s network through an untrusted network such as the Internet. Depending on the FortiGate deployment, supported VPN technologies can provide authentication, encryption, and controlled access to internal resources. Administrators should define appropriate authentication methods and limit remote users to the resources they actually require. VPN access should also be monitored and reviewed regularly. Strong authentication and appropriate endpoint security are important because remote access can expand the organization’s external attack surface.
Question 58. What is the purpose of a FortiGate security policy schedule?
- To determine when the policy is active
2. To synchronize administrator passwords
3. To update routing tables automatically
4. To create antivirus signatures
Answer: 1. To determine when the policy is active
Explanation:
A security policy schedule determines the time periods during which a firewall policy can be applied. This allows administrators to create time-based access controls, such as permitting a particular service only during approved business hours. Schedules can help reduce unnecessary exposure when access is not required. Administrators should verify that schedules reflect the organization’s actual operating requirements, including time zones and special working periods. A schedule does not replace other policy controls; source, destination, service, authentication, and security requirements should still be configured appropriately.
Question 59. Which FortiGate feature helps administrators identify the reason a firewall policy did not allow expected traffic?
- Diagnostic and logging tools
2. DHCP server
3. VLAN tagging
4. Link aggregation
Answer: 1. Diagnostic and logging tools
Explanation:
FortiGate diagnostic and logging capabilities provide information that can help determine why traffic was handled differently than expected. Administrators can review policy matches, routing decisions, session information, and relevant log entries to identify where processing did not follow the intended path. Troubleshooting should begin with basic connectivity and configuration before moving to more detailed diagnostics. A structured approach helps avoid unnecessary changes that could create additional problems. Diagnostic information should be interpreted together with the actual network topology and security-policy configuration.
Question 60. Which principle should guide the configuration of FortiGate firewall policies?
- Allow every service by default
2. Use least privilege and allow only required traffic
3. Disable logging to improve performance
4. Use one unrestricted policy for all users
Answer: 2. Use least privilege and allow only required traffic
Explanation:
The principle of least privilege means allowing only the network communication that is necessary for legitimate business requirements. Applying this principle to FortiGate policies helps reduce unnecessary exposure by limiting sources, destinations, services, and users wherever practical. Broad unrestricted policies can increase the potential impact of compromised systems or unauthorized activity. Administrators should regularly review firewall rules, remove obsolete policies, and verify that permitted services are still required. Logging and security inspection should also be used appropriately so policy behavior can be monitored and investigated when necessary.