Fortinet FCP_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part 14 Q261-280

View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps

 

Question 261. What is the primary purpose of FortiGate configuration revisions?

  1. To store and restore previous configuration states
    2. To increase VPN bandwidth
    3. To replace firewall policies
    4. To assign IP addresses

Answer: 1. To store and restore previous configuration states

Explanation:

Configuration revisions allow administrators to preserve different versions of the FortiGate configuration. This can be useful before or after major changes because an administrator can compare configurations and, where supported, restore an earlier configuration state. Revision management provides an additional safeguard when modifying firewall policies, routing, interfaces, or security settings. It is particularly valuable during troubleshooting because administrators can determine what changed between configuration versions. Configuration revisions are different from traffic logs because they focus on configuration states rather than network activity. Maintaining appropriate configuration backups and revisions helps reduce the impact of configuration errors.

Question 262. Which FortiGate feature can automatically save configuration changes at scheduled intervals?

  1. Application Control
    2. Automatic configuration backup
    3. Web Filter
    4. IP reputation

Answer: 2. Automatic configuration backup

Explanation:

Automatic configuration backup helps protect the FortiGate configuration by periodically creating copies according to the configured backup process. Regular backups can be important because firewall configurations may contain extensive policy, routing, interface, authentication, and security-profile settings. If a device fails or a configuration change causes unexpected behavior, a recent backup can provide a recovery option. Administrators should store backups securely and protect them because configuration files can contain sensitive information. Automatic backups complement, rather than replace, configuration revisions and manual backup procedures. A documented backup strategy is an important part of reliable firewall administration.

Question 263. Which FortiGate feature provides a logical interface that can be used as a stable endpoint for routing protocols?

  1. VLAN interface
    2. Physical interface
    3. Loopback interface
    4. FortiLink interface

Answer: 3. Loopback interface

Explanation:

A loopback interface is a logical interface that remains independent of a particular physical network port. This makes it useful as a stable endpoint for routing protocols, management, monitoring, or other services that benefit from a consistent IP address. If a physical interface fails while another path remains available, the loopback address can continue to represent the FortiGate. Routing protocols can therefore use the loopback address for identification or peering where appropriate. Because the interface is logical rather than tied directly to a cable or physical port, it can improve the stability of network designs.

Question 264. What is the purpose of DHCP IP reservation on FortiGate?

  1. To encrypt DHCP traffic
    2. To disable dynamic addressing
    3. To create a VPN tunnel
    4. To assign a predictable IP address to a specific DHCP client

Answer: 4. To assign a predictable IP address to a specific DHCP client

Explanation:

DHCP IP reservation allows an administrator to associate a particular client with a specific IP address so that the client receives a predictable address through DHCP. The association is generally based on an identifying attribute such as the client’s MAC address. This is useful for devices that should maintain consistent addressing while still being managed through DHCP. Examples can include printers, monitoring systems, or other infrastructure devices. DHCP reservation differs from manually configuring a static IP on the endpoint because the address assignment remains controlled by the DHCP server. Proper reservation management also helps prevent address conflicts.

Question 265. Which FortiGate feature can store local DNS host records for selected names?

  1. Local DNS database
    2. Traffic shaping
    3. IPS sensor
    4. Session helper

Answer: 1. Local DNS database

Explanation:

A local DNS database can allow FortiGate to provide DNS responses for locally defined host records. This can be useful when internal clients need to resolve specific names to internal IP addresses without relying on an external DNS service for those records. Administrators can use local DNS information for selected internal services or network resources. The feature should be configured carefully to ensure that names and addresses remain accurate. Local DNS functionality is different from DNS filtering, which focuses on controlling or categorizing DNS requests. Both can operate as part of a broader DNS security and network-management design.

Question 266. What is the purpose of DHCP conflict detection?

  1. To encrypt DHCP messages
    2. To help identify whether an address is already in use before assigning it
    3. To create VLANs automatically
    4. To perform antivirus scanning

Answer: 2. To help identify whether an address is already in use before assigning it

Explanation:

DHCP conflict detection helps reduce the possibility of assigning an IP address that is already being used by another device. Detecting address conflicts is important because duplicate IP addresses can cause intermittent connectivity, unreachable hosts, and other difficult-to-diagnose network problems. When conflict detection is available and configured, the DHCP process can check address usage according to the supported mechanism before completing an assignment. This capability does not replace good IP address management, but it provides an additional safeguard. Administrators should also investigate recurring conflicts because they may indicate unauthorized static addressing or incorrect DHCP configurations.

Question 267. What is the purpose of an OSPF router ID?

  1. To identify an OSPF router uniquely within the OSPF domain
    2. To define a firewall policy
    3. To select an antivirus profile
    4. To assign DHCP addresses

Answer: 1. To identify an OSPF router uniquely within the OSPF domain

Explanation:

The OSPF router ID provides a unique identifier for an OSPF router within the routing domain. It is used in OSPF operations such as neighbor relationships and link-state information. Selecting a stable router ID is important because changes to the identifier can affect OSPF behavior and may require the routing process to restart or reconverge. Administrators commonly use a suitable stable address or explicitly configure the router ID according to the network design. The router ID is not a firewall policy identifier and does not control DHCP or antivirus processing. Properly planned OSPF identification supports predictable routing behavior.

Question 268. What is the main purpose of OSPF route summarization?

  1. To increase packet inspection depth
    2. To disable route advertisements
    3. To reduce the number of routes represented in routing information
    4. To replace static NAT

Answer: 3. To reduce the number of routes represented in routing information

Explanation:

OSPF route summarization combines multiple more-specific network routes into a broader summarized route where the network design allows it. Reducing the number of routes can make routing tables more manageable and can reduce the amount of routing information exchanged between areas or routing boundaries. Summarization can also help limit the propagation of individual route changes. However, the address ranges being summarized must be planned carefully so that valid destinations remain reachable and unintended traffic is not attracted toward an incorrect path. Route summarization is therefore primarily a routing scalability and stability technique.

Question 269. What is the purpose of a BGP route filter?

  1. To inspect antivirus signatures
    2. To control which BGP routes are accepted or advertised
    3. To assign DHCP reservations
    4. To create security certificates

Answer: 2. To control which BGP routes are accepted or advertised

Explanation:

BGP route filtering allows administrators to control which routes are accepted from or advertised to BGP neighbors. This is important because uncontrolled route exchange can introduce incorrect, unwanted, or excessive routing information. Filtering can be based on supported route attributes and matching criteria, allowing administrators to define routing policies appropriate to their network design. Proper BGP filtering is particularly important when exchanging routes with external networks or multiple routing domains. Administrators should test filters carefully because an overly restrictive rule can remove legitimate routes, while an overly broad rule can permit unintended advertisements.

Question 270. Which FortiGate feature allows an administrator to define different behavior for traffic entering through different SD-WAN zones?

  1. Certificate authority
    2. Antivirus quarantine
    3. SD-WAN zone
    4. Local DNS database

Answer: 3. SD-WAN zone

Explanation:

An SD-WAN zone provides a logical grouping of SD-WAN members that can be referenced in policies and routing-related configurations. Instead of treating every individual WAN member as a completely separate destination, administrators can use logical zones to simplify configuration and traffic management. The zone concept can be useful when multiple links provide similar connectivity but have different physical interfaces or characteristics. SD-WAN rules and performance measurements can then determine how traffic is handled among available members. Proper zone design helps simplify policies while retaining the ability to manage multiple WAN paths through SD-WAN functionality.

Question 271. What is the primary purpose of an SD-WAN zone?

  1. To logically group SD-WAN members for configuration and policy use
    2. To replace all firewall policies
    3. To encrypt DNS queries
    4. To store antivirus signatures

Answer: 1. To logically group SD-WAN members for configuration and policy use

Explanation:

An SD-WAN zone provides a logical grouping of one or more SD-WAN members. This abstraction can simplify firewall policy and routing configuration because administrators can reference the logical zone rather than repeatedly managing individual member interfaces. The actual SD-WAN members may use different WAN links, gateways, or physical interfaces, while the zone provides a common logical reference. SD-WAN rules and health checks can still determine which member should carry traffic. Zones therefore improve configuration organization without eliminating the underlying member-specific settings that control link availability and path selection.

Question 272. Which HA setting can influence which FortiGate unit becomes the primary unit after an HA event?

  1. Web Filter profile
    2. HA device priority
    3. DNS filter category
    4. IP pool configuration

Answer: 2. HA device priority

Explanation:

In a FortiGate high-availability cluster, device priority can influence the election of the primary unit when the HA conditions require a new election. Administrators can use priority as part of a planned HA design so that a preferred unit can become primary when the relevant election rules are satisfied. HA election behavior also depends on other configuration and operational conditions, so priority should not be considered in isolation. Understanding HA election parameters is important when designing predictable failover behavior. The setting does not affect Web Filter categories, DNS filtering, or NAT IP pools.

Question 273. What is the purpose of monitored interfaces in a FortiGate HA configuration?

  1. To automatically create firewall policies
    2. To increase the number of VDOMs
    3. To detect important interface failures that may influence HA behavior
    4. To perform DNS filtering

Answer: 3. To detect important interface failures that may influence HA behavior

Explanation:

HA interface monitoring allows the cluster to consider the operational state of selected network interfaces when determining whether a unit remains suitable to perform its role. If a monitored interface fails, the HA system can respond according to its configured failover behavior and election rules. This is useful because a FortiGate might still be powered on and communicating through heartbeat links while an important production interface is unavailable. Monitoring critical interfaces therefore provides additional awareness of actual network availability. Administrators should select interfaces carefully so that temporary or noncritical failures do not cause unnecessary failovers.

Question 274. Which FortiGate feature can restrict administrative access based on the source IP address?

  1. Trusted hosts
    2. Application Control
    3. IP pool
    4. Traffic shaping

Answer: 1. Trusted hosts

Explanation:

Trusted hosts allow administrators to restrict where an administrative account can log in from by specifying permitted source IP addresses or networks. This provides an additional security layer for management access because possession of valid credentials alone may not be sufficient when the connection originates outside the defined trusted range. Trusted hosts should be configured carefully to include legitimate management networks while avoiding unnecessarily broad ranges. They work alongside other protections such as strong authentication, HTTPS administration, and appropriate administrator profiles. This feature controls management access rather than ordinary transit traffic passing through the firewall.

Question 275. What is the purpose of an administrator profile on FortiGate?

  1. To define the permissions available to an administrator account
    2. To assign client DHCP addresses
    3. To select an IPsec peer
    4. To define a DNS server

Answer: 1. To define the permissions available to an administrator account

Explanation:

An administrator profile determines what functions and configuration areas an administrator account can access. This supports role-based administration and the principle of least privilege. For example, one administrator may require broad system access, while another may only need monitoring or limited configuration permissions. Restricting privileges reduces the potential impact of accidental or unauthorized changes. Administrator profiles should be designed according to actual job responsibilities rather than granting full access to every account. Profiles work together with trusted hosts, authentication methods, and other administrative controls to provide a layered approach to secure FortiGate management.

Question 276. What is the purpose of an administrative authentication lockout mechanism?

  1. To improve WAN bandwidth
    2. To temporarily restrict login attempts after repeated authentication failures
    3. To create routing entries
    4. To increase VPN encryption

Answer: 2. To temporarily restrict login attempts after repeated authentication failures

Explanation:

Administrative authentication lockout mechanisms help protect FortiGate management accounts against repeated unsuccessful login attempts. When configured, repeated failures can trigger a temporary restriction, making automated password-guessing attempts more difficult. The exact behavior depends on the configured administrative security settings. Lockout should be balanced with operational requirements so that legitimate administrators are not unnecessarily prevented from accessing the system. Strong passwords, multi-factor authentication, trusted hosts, and restricted management interfaces provide additional protection. Lockout is therefore one component of a broader administrative security strategy rather than a replacement for secure authentication practices.

Question 277. Which log type is primarily used to record firewall traffic sessions and their associated actions?

  1. Traffic log
    2. Certificate log
    3. Firmware log
    4. DHCP reservation log

Answer: 1. Traffic log

Explanation:

Traffic logs provide information about network sessions processed by the FortiGate firewall. Depending on the configured logging settings, they can contain details such as source and destination addresses, services, interfaces, policy identifiers, actions, and traffic volumes. These records are useful for investigating connectivity, verifying policy behavior, analyzing network usage, and identifying suspicious traffic patterns. Traffic logging is distinct from event logging, which focuses more on system or administrative events. Administrators should configure appropriate logging levels and destinations according to operational and storage requirements so that important information remains available for troubleshooting and analysis.

Question 278. What is the purpose of event logs on FortiGate?

  1. To provide NAT translations for every packet
    2. To store DHCP addresses permanently
    3. To record system, administrative, and other significant events
    4. To replace IPS signatures

Answer: 3. To record system, administrative, and other significant events

Explanation:

Event logs record significant activities and conditions related to the FortiGate system. Depending on the event category, they can help administrators investigate configuration changes, authentication events, system status changes, and other operational activities. Event logs complement traffic logs, which primarily describe network sessions. Reviewing event logs can help determine what happened on the device and when a particular administrative or system event occurred. Centralized logging through FortiAnalyzer or another supported logging destination can make these records easier to retain and analyze. Proper event logging is valuable during troubleshooting and security investigations.

Question 279. What is the primary purpose of FortiGate system resource monitoring?

  1. To configure BGP advertisements
    2. To observe CPU, memory, sessions, and other resource usage
    3. To create certificate authorities
    4. To assign firewall addresses

Answer: 2. To observe CPU, memory, sessions, and other resource usage

Explanation:

System resource monitoring provides visibility into how the FortiGate is using available processing and memory resources. Administrators can use this information to identify unusual resource consumption, capacity concerns, or conditions that may affect performance. Monitoring can include CPU utilization, memory usage, session counts, and other supported indicators. Resource information is particularly useful when investigating slow response times, conserve-mode conditions, or unexpectedly high traffic processing. Monitoring alone does not change routing or security policies. Instead, it gives administrators operational information that can be combined with logs and diagnostic commands when investigating system behavior.

Question 280. Which action is most appropriate when a FortiGate configuration change unexpectedly disrupts connectivity?

  1. Immediately delete all firewall policies
    2. Disable all security profiles permanently
    3. Reboot the FortiGate without checking the configuration
    4. Review the recent configuration change, policy matching, routing, and relevant logs

Answer: 4. Review the recent configuration change, policy matching, routing, and relevant logs

Explanation:

A systematic troubleshooting approach is preferable when a configuration change unexpectedly affects connectivity. The administrator should first identify what changed and determine whether the affected traffic is matching the intended firewall policy. Routing information, interface status, session details, and relevant logs can then help identify where the traffic is being interrupted. If configuration revisions or backups are available, they can also help compare the current state with an earlier known-good configuration. Randomly deleting policies or rebooting the device can remove useful evidence and potentially create additional problems. Structured troubleshooting makes it easier to isolate the actual cause and restore service safely.