View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps
Question 181. Which FortiGate feature can apply different NAT behavior by using a pool of public IP addresses?
- Static routing
2. DHCP relay
3. IP pool
4. DNS forwarding
Answer: 3. IP pool
Explanation:
An IP pool allows FortiGate to use a defined range of public or translated IP addresses for source NAT. Instead of translating all sessions to the outgoing interface address, the firewall can select addresses from the configured pool. This is useful when an organization owns multiple public addresses and wants outbound connections to use those addresses. Depending on the configuration, IP pools can provide one-to-one, overload, or other translation behaviors. The pool is referenced by firewall policies that permit the relevant traffic. Proper sizing and address assignment are important because insufficient available addresses can affect how new sessions are translated.
Question 182. What is the primary purpose of a PAC file when using an explicit web proxy?
- Encrypt firewall configuration backups
2. Define which proxy server a client should use
3. Configure IPsec encryption parameters
4. Create antivirus signatures
Answer: 2. Define which proxy server a client should use
Explanation:
A Proxy Auto-Configuration (PAC. file provides browser or client-side instructions for selecting a proxy server. It can specify conditions that determine whether traffic should go through a particular proxy or connect directly. In environments using FortiGate explicit proxy services, a PAC file can simplify client configuration by distributing proxy settings without manually configuring every workstation. PAC files can also support different proxy choices based on destination or network conditions. They do not perform encryption or antivirus inspection themselves. The actual traffic inspection and policy enforcement are performed by the configured proxy and security controls on FortiGate.
Question 183. Which FortiGate capability allows administrators to authenticate users against a certificate-based identity?
- DHCP snooping
2. Static routing
3. Certificate-based authentication
4. Traffic shaping
Answer: 3. Certificate-based authentication
Explanation:
Certificate-based authentication uses digital certificates to verify an identity instead of relying only on a username and password. FortiGate can use certificates as part of authentication mechanisms when a suitable PKI infrastructure is available. The client presents a certificate, and FortiGate validates the certificate according to the configured trust relationship and authentication requirements. This approach can provide strong identity verification and is particularly useful for controlled enterprise environments. Administrators must ensure that trusted certificate authorities, certificate validity, revocation considerations, and appropriate identity mappings are correctly configured. Certificate-based authentication is different from ordinary password authentication and requires suitable certificate infrastructure.
Question 184. What should FortiGate verify when validating a client certificate chain?
- The certificate is issued by a trusted CA
2. The client has the correct DHCP lease
3. The firewall has an active SD-WAN rule
4. The destination uses a VIP
Answer: 1. The certificate is issued by a trusted CA
Explanation:
Certificate chain validation confirms that a presented certificate can be traced to a trusted certificate authority. FortiGate checks the certificate relationship and relevant validity information before accepting the certificate for authentication or another certificate-based function. A trusted CA certificate must therefore be available in the appropriate trust store. Other checks can include expiration, subject information, and certificate usage depending on the authentication scenario. DHCP leases, SD-WAN rules, and VIP configurations are unrelated to certificate-chain trust. Proper certificate management helps prevent unauthorized certificates from being accepted and supports a stronger authentication framework.
Question 185. Which IPsec VPN type is commonly used when remote clients have dynamic or unknown public IP addresses?
- Site-to-site static VPN
2. GRE tunnel
3. Dial-up VPN
4. Dedicated VLAN
Answer: 3. Dial-up VPN
Explanation:
A dial-up IPsec VPN is designed for peers whose public IP addresses are not known in advance or may change over time. This makes it suitable for remote users, branch devices, or other clients connecting from dynamic Internet addresses. Instead of requiring a predefined static peer address, FortiGate can authenticate the connecting peer using configured identification and authentication methods. Once the tunnel is established, appropriate policies and routing determine what resources the remote client can access. Dial-up VPNs are especially useful for remote-access scenarios where maintaining static public addressing for every endpoint would be impractical.
Question 186. What is the purpose of a peer ID in an IPsec VPN configuration?
- To assign a DHCP address
2. To select an antivirus profile
3. To define a traffic-shaping queue
4. To identify or distinguish the VPN peer
Answer: 4. To identify or distinguish the VPN peer
Explanation:
An IPsec peer ID provides an identity value that can help FortiGate identify a connecting VPN peer. This is especially useful when multiple peers connect to the same VPN gateway but have different identities or authentication requirements. Depending on the configuration, the identity can be associated with authentication and phase 1 settings. Peer identification is separate from the peer’s IP address, which is important when remote endpoints use dynamic addressing. Correct peer-ID configuration helps FortiGate select the appropriate authentication and VPN parameters and can prevent an otherwise valid connection from matching the wrong phase 1 configuration.
Question 187. Which IPv6 mechanism helps hosts discover neighboring devices and routers on the local network?
- NAT
2. Neighbor Discovery Protocol
3. DHCP relay
4. OSPFv2
Answer: 2. Neighbor Discovery Protocol
Explanation:
IPv6 Neighbor Discovery Protocol (NDP. is used for several important local-network functions, including discovering neighboring devices and routers. It operates through ICMPv6 messages and supports functions such as neighbor discovery, router discovery, address resolution, and reachability detection. Unlike IPv4 ARP, IPv6 does not use ARP for resolving neighboring addresses. NDP therefore plays an important role in normal IPv6 communication. Security policies and network controls should account for required ICMPv6 traffic because blocking essential messages can interfere with IPv6 connectivity. NDP is distinct from DHCP and traditional IPv4 routing protocols.
Question 188. Which feature can provide IPv6 address configuration through a DHCPv6 service?
- DHCPv6
2. NAT64 only
3. VLAN trunking
4. IP pool
Answer: 1. DHCPv6
Explanation:
DHCPv6 provides dynamic IPv6 configuration services to clients. Depending on the deployment, it can provide IPv6 addressing and additional network configuration information. It is different from traditional IPv4 DHCP because IPv6 hosts can also use mechanisms such as Router Advertisements and Stateless Address Autoconfiguration. FortiGate can participate in IPv6 network configurations involving DHCPv6 where appropriate. Administrators should determine whether the environment requires stateful DHCPv6, stateless configuration assistance, or another IPv6 addressing approach. Correctly configuring IPv6 services ensures clients receive the information necessary to communicate on the network.
Question 189. What can a DNS Filter policy use to enforce safer web-search behavior?
- IPsec peer IDs
2. DHCP reservations
3. Safe Search enforcement
4. Static routes
Answer: 3. Safe Search enforcement
Explanation:
DNS filtering can include controls that help enforce safer search behavior for supported search engines. Safe Search enforcement reduces exposure to certain categories of search results by directing supported queries through safer search configurations. This can be useful in environments such as schools, businesses, and managed networks where administrators want additional control over web content. The feature works alongside DNS-based filtering rather than replacing full web-content inspection. Administrators should understand the limitations of DNS filtering because it primarily controls name resolution and category-based access rather than inspecting every aspect of encrypted web traffic.
Question 190. Which IPS capability can temporarily isolate a source that repeatedly triggers configured security signatures?
- DNS forwarding
2. DHCP relay
3. Route redistribution
4. Quarantine
Answer: 4. Quarantine
Explanation:
An IPS quarantine action can help isolate a source that repeatedly generates suspicious or malicious traffic according to configured security rules. When a quarantine mechanism is triggered, FortiGate can restrict communication from the identified source for a configured period or according to the relevant policy behavior. This can reduce the risk of continued malicious activity while administrators investigate the endpoint. Quarantine should be configured carefully because legitimate systems can sometimes trigger security controls due to unusual traffic patterns. Appropriate thresholds, exception handling, and monitoring help ensure that automated isolation supports security without unnecessarily disrupting valid users or devices.
Question 191. Which DLP capability can identify sensitive information based on configured data patterns?
- IPsec DPD
2. DLP data patterns
3. OSPF adjacency
4. DHCP relay
Answer: 2. DLP data patterns
Explanation:
DLP data patterns allow security policies to identify information that matches defined characteristics of sensitive data. Patterns can be designed around specific formats or recognizable content, depending on the organization’s requirements. FortiGate DLP controls can then use these detections to apply configured actions to matching traffic or files. This can help organizations reduce accidental or unauthorized transmission of sensitive information. Administrators should design patterns carefully to balance detection accuracy and performance. A well-configured DLP policy typically combines appropriate patterns, traffic scope, logging, and actions so that sensitive information can be monitored and controlled consistently.
Question 192. Which traffic-shaping configuration can provide a bandwidth limit specifically for each source IP?
- Per-IP shaper
2. DNS filter
3. Security Fabric connector
4. Address group
Answer: 1. Per-IP shaper
Explanation:
A per-IP traffic shaper applies bandwidth control separately to individual source IP addresses. This is useful when an administrator wants each user or endpoint to receive its own configured bandwidth allowance rather than having all users share one common limit. For example, a network can restrict excessive consumption by individual clients while allowing multiple clients to operate independently within their assigned limits. This differs from a shared traffic shaper, where multiple sessions or users may compete for the same bandwidth allocation. Proper shaping configuration can improve fairness and help prevent one endpoint from consuming disproportionate network capacity.
Question 193. Which DoS policy setting is specifically relevant to detecting excessive TCP SYN requests?
- Web category rating
2. Certificate authority
3. SYN flood threshold
4. DHCP lease duration
Answer: 3. SYN flood threshold
Explanation:
A SYN flood threshold is used to identify unusually high rates of TCP connection initiation attempts. During a normal TCP connection, a client begins the handshake by sending a SYN packet. A large volume of SYN requests can consume server resources and may indicate a denial-of-service attempt. FortiGate DoS policies can use configured thresholds to detect abnormal traffic rates and apply protective actions. Threshold values should be selected based on normal traffic patterns because overly aggressive settings may identify legitimate bursts as attacks. Monitoring and tuning are important to maintain effective protection without unnecessarily affecting valid connections.
Question 194. In an automation stitch, what determines when the configured actions should execute?
- The firewall hostname
2. The trigger condition
3. The administrator password
4. The DNS cache
Answer: 2. The trigger condition
Explanation:
An automation stitch uses a trigger to determine when one or more configured actions should execute. The trigger can be associated with an event or condition recognized by FortiGate. When that condition occurs, FortiGate performs the actions linked to the automation stitch. This allows administrators to automate responses to selected operational or security events instead of handling every event manually. For example, an automation workflow may respond to a detected condition by sending a notification or taking another predefined action. Careful trigger selection is important because an overly broad condition can cause unnecessary automated responses.
Question 195. Which FortiView capability is most useful for investigating why a particular application is consuming bandwidth?
- Changing the administrator password
2. Drilling down into application traffic details
3. Creating a new VDOM
4. Replacing a certificate
Answer: 2. Drilling down into application traffic details
Explanation:
FortiView provides graphical and interactive visibility into network activity. When investigating application bandwidth usage, administrators can drill down into application-related traffic information to identify which applications, users, destinations, or sessions are contributing to consumption. This makes it easier to move from a high-level overview to more specific traffic details. The resulting information can help administrators determine whether traffic is expected, excessive, or potentially unwanted. FortiView is primarily a monitoring and analysis capability; it does not itself replace firewall policies or security profiles. Administrators can use the findings to guide subsequent policy or traffic-management changes.
Question 196. Which administrator setting can require stronger password complexity for local FortiGate accounts?
- Password policy
2. Route monitor
3. DNS database
4. Interface alias
Answer: 1. Password policy
Explanation:
An administrator password policy establishes requirements for passwords used by local administrative accounts. Depending on the configured options, the policy can enforce characteristics such as minimum length and complexity requirements. Strong password rules reduce the likelihood that easily guessed passwords will be accepted for privileged accounts. Administrators should also combine password controls with other protections such as multi-factor authentication, trusted management sources, appropriate administrative profiles, and secure management protocols. Password policy is specifically concerned with credential requirements, while unrelated features such as routing and DNS configuration do not determine whether an administrator’s password satisfies security requirements.
Question 197. Which virtual server load-balancing method distributes connections sequentially among available real servers?
- Source IP persistence
2. Least sessions only
3. Round robin
4. Static routing
Answer: 3. Round robin
Explanation:
Round-robin load balancing distributes incoming connections sequentially across the available real servers. For example, requests can be directed to server A, then server B, then server C, before returning to server A. This method is straightforward and can work well when backend servers have similar capabilities and workloads. It does not necessarily account for the current number of active sessions or differences in server capacity. Other load-balancing methods can use different criteria. The selected method should therefore match the application’s traffic pattern and the characteristics of the backend servers.
Question 198. Why is administrator login timeout useful on FortiGate?
- It increases VPN encryption strength
2. It changes routing metrics
3. It creates additional firewall policies
4. It automatically ends inactive administrative sessions
Answer: 4. It automatically ends inactive administrative sessions
Explanation:
An administrator login timeout automatically terminates an administrative session after the configured period of inactivity. This reduces the risk associated with an unattended management session remaining open on a workstation. A shorter timeout can provide stronger protection in environments where administrative consoles may be exposed to unauthorized physical or local access. The setting does not modify VPN encryption, routing metrics, or firewall policy behavior. Administrators should select a practical timeout that balances security with operational convenience. Combined with strong authentication and restricted management access, session timeout controls provide an additional layer of protection for privileged administration.
Question 199. What is the main purpose of static one-to-one NAT for an internal server?
- To assign multiple DHCP leases
2. To map a public address consistently to an internal address
3. To create an OSPF neighbor
4. To filter DNS categories
Answer: 2. To map a public address consistently to an internal address
Explanation:
Static one-to-one NAT provides a consistent translation between a public IP address and a private internal address. This is commonly useful when an internal server needs to be reachable through a predictable public address. The translation itself does not automatically determine which services are allowed; appropriate firewall policies and service restrictions are still required. One-to-one NAT differs from overload NAT, where many internal hosts can share one public address using different source ports. Administrators should also consider exposure carefully and permit only the services that are actually required for the published server.
Question 200. Which FortiGate behavior occurs when traffic does not match any explicit firewall policy?
- The traffic is denied by the implicit policy
2. The traffic is automatically forwarded
3. The traffic is converted to IPv6
4. The traffic is sent to the DNS server
Answer: 1. The traffic is denied by the implicit policy
Explanation:
FortiGate uses an implicit deny behavior when traffic does not match an applicable explicit firewall policy. This provides a default security boundary by preventing unmatched traffic from being automatically permitted. Administrators can create explicit policies for legitimate traffic and place the appropriate security profiles and logging settings on those policies. When unexpected traffic is denied, policy configuration, source and destination interfaces, addresses, services, schedules, and routing should be reviewed to determine why no intended policy matched. Understanding implicit deny behavior is fundamental to troubleshooting connectivity while maintaining a controlled firewall security posture.