Fortinet FCP_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps

Question 341. What is the primary purpose of a FortiGate service object?

  1. Define a reusable network service such as TCP or UDP ports
    2. Store administrator credentials
    3. Monitor CPU temperature
    4. Configure an HA heartbeat

Answer: 1. Define a reusable network service such as TCP or UDP ports

Explanation:

A service object defines network services that can be referenced by FortiGate firewall policies. It can represent protocols and port numbers, such as HTTP, HTTPS, SSH, DNS, or custom TCP and UDP services. Using service objects makes policies easier to understand because administrators can reference meaningful names rather than repeatedly entering port information. Custom service objects are useful when applications use nonstandard ports. Service objects can also be grouped into service groups when several services need to be referenced together. They do not create the actual network connection; instead, they provide criteria that firewall policies use when determining whether matching traffic should be allowed or denied.

Question 342. Which FortiGate feature can restrict management access to selected interfaces?

  1. Traffic shaping
    2. Administrative access settings on interfaces
    3. Application Control
    4. DLP

Answer: 2. Administrative access settings on interfaces

Explanation:

FortiGate interfaces can be configured to permit specific administrative access methods, such as HTTPS, SSH, or other supported management protocols. Restricting administrative services to appropriate interfaces reduces the number of locations from which the firewall can be managed. For example, an organization may permit HTTPS and SSH only on a dedicated management interface while disabling unnecessary management services on external interfaces. Interface restrictions should be combined with trusted hosts, strong authentication, and appropriate administrator profiles. This layered approach helps reduce exposure of the FortiGate management plane. Administrative access settings control access to the FortiGate itself rather than ordinary traffic passing through it.

Question 343. What is the purpose of a FortiGate security policy comment?

  1. Enable antivirus scanning
    2. Change the policy’s action automatically
    3. Document the purpose or administrative notes associated with the policy
    4. Assign a public IP address

Answer: 3. Document the purpose or administrative notes associated with the policy

Explanation:

A firewall policy comment provides a place for administrators to document information about a policy. Comments can describe the business purpose of the rule, the application or service it supports, the responsible team, or other useful administrative details. Clear documentation becomes increasingly valuable as the number of firewall policies grows. A comment does not change how traffic is processed and does not act as a security condition. Instead, it improves human understanding and configuration maintenance. Well-documented policies can make audits, troubleshooting, change reviews, and future administrative work easier because another administrator can understand why a particular rule exists.

Question 344. What is the purpose of configuring a FortiGate firewall policy with logging enabled?

  1. Record relevant traffic activity for monitoring and investigation
    2. Increase the physical interface speed
    3. Replace routing protocols
    4. Create an administrator account

Answer: 1. Record relevant traffic activity for monitoring and investigation

Explanation:

Firewall policy logging allows FortiGate to record information about traffic handled by a policy. Depending on the configuration, logs can contain details such as source and destination addresses, services, actions, interfaces, timestamps, and other session information. These records are useful for troubleshooting, security investigations, usage analysis, and operational monitoring. Logs can also be forwarded to FortiAnalyzer or another supported logging destination for centralized analysis. Logging should be configured according to the organization’s requirements because excessive logging can consume resources and storage. Administrators should select appropriate logging options rather than assuming every possible traffic event must always be recorded.

Question 345. Which FortiGate capability allows an administrator to create a network segment using a VLAN interface?

  1. VLAN subinterface
    2. IPS exception
    3. FortiView
    4. Automation Stitch

Answer: 1. VLAN subinterface

Explanation:

A VLAN interface on FortiGate provides Layer 3 connectivity to a specific VLAN. The interface is associated with a VLAN identifier and can be configured with an IP address and other relevant network settings. This allows FortiGate to route traffic between VLAN-based networks while applying firewall policies between them. VLAN interfaces are commonly used for network segmentation, such as separating users, servers, guest devices, and management systems. Correct switch configuration is also necessary so that VLAN-tagged traffic reaches the FortiGate interface. The firewall can then apply appropriate routing and security controls to traffic entering and leaving each VLAN interface.

Question 346. What is the main purpose of DHCP IP reservation on FortiGate?

  1. Encrypt DHCP traffic
    2. Assign a predictable IP address to a specific client
    3. Create an IPsec tunnel
    4. Filter web applications

Answer: 2. Assign a predictable IP address to a specific client

Explanation:

A DHCP reservation associates a particular client identity, commonly based on its MAC address, with a specified IP address. When that client requests a DHCP lease, the FortiGate DHCP server can provide the reserved address rather than selecting an arbitrary address from the available pool. Reservations are useful for devices that should consistently receive the same address while still using DHCP for configuration. Examples include printers, internal servers, cameras, or other managed devices. A reservation does not itself create a firewall rule or guarantee network access. It simply provides predictable address assignment through DHCP and can simplify network administration.

Question 347. Which FortiGate feature can help identify the physical or logical interface through which a route will be forwarded?

  1. Route lookup
    2. Web Filter
    3. DLP
    4. Replacement message

Answer: 1. Route lookup

Explanation:

Route lookup allows administrators to examine how FortiGate determines the forwarding path for a destination. It can help identify the matching route, next hop, and outgoing interface that FortiGate would use for traffic toward a particular destination. This is especially useful when troubleshooting connectivity because an incorrect or unexpected route can cause traffic to leave through the wrong interface or fail to reach its destination. Administrators should consider route specificity, administrative distance, priority, and routing-table contents when analyzing results. Route lookup focuses on forwarding decisions and is separate from firewall policy matching, although both routing and policy processing affect successful communication.

Question 348. What is the primary purpose of FortiLink?

  1. Manage compatible FortiSwitch devices through FortiGate
    2. Provide public DNS resolution
    3. Replace IPsec encryption
    4. Generate antivirus signatures

Answer: 1. Manage compatible FortiSwitch devices through FortiGate

Explanation:

FortiLink enables FortiGate to manage compatible FortiSwitch devices as part of an integrated network architecture. Through FortiLink, administrators can centrally configure and monitor supported switching functions from FortiGate. This integration can simplify deployment because network security and access-layer management can be coordinated from a common management point. Depending on the environment, FortiLink can also support VLAN and switch-related configuration workflows. The exact capabilities depend on the FortiOS and FortiSwitch versions and supported features. FortiLink is therefore primarily a management and integration mechanism rather than a replacement for routing, firewall inspection, or IPsec VPN functionality.

Question 349. What is the purpose of an IPv6 firewall policy on FortiGate?

  1. Control and inspect IPv6 traffic according to defined security rules
    2. Convert IPv6 addresses into usernames
    3. Configure NTP synchronization
    4. Create FortiAnalyzer reports

Answer: 1. Control and inspect IPv6 traffic according to defined security rules

Explanation:

An IPv6 firewall policy allows FortiGate to apply security controls to IPv6 traffic. Like IPv4 firewall policies, IPv6 policies can use source and destination addresses, services, interfaces, schedules, and other supported conditions to determine how traffic should be handled. Security profiles can also be applied where appropriate. Administrators must ensure that IPv6 policies are correctly designed because IPv6 traffic may use different addressing and network-discovery mechanisms than IPv4. A network that supports both protocols may require appropriate policies for each. Reviewing IPv6 routing, interfaces, and policy order together helps ensure that expected IPv6 traffic receives the intended security treatment.

Question 350. Which FortiGate function provides a graphical view of current system resource utilization?

  1. System resource monitoring
    2. Static NAT
    3. Service group
    4. DHCP reservation

Answer: 1. System resource monitoring

Explanation:

System resource monitoring provides visibility into resources such as CPU and memory utilization and, depending on the FortiOS interface, other system statistics. This information helps administrators identify resource pressure and investigate performance-related problems. For example, unusually high memory usage may require investigation of sessions, processes, traffic volume, or other system conditions. Resource monitoring is different from traffic analysis because it focuses on the health and utilization of the FortiGate system itself. Administrators should review resource trends rather than relying only on a single momentary measurement. Persistent abnormal utilization can indicate that additional troubleshooting or capacity planning is required.

Question 351. What is the primary purpose of a FortiGate address group?

  1. Combine multiple address objects for easier policy reference
    2. Store antivirus signatures
    3. Define an administrator’s password
    4. Configure NTP servers

Answer: 1. Combine multiple address objects for easier policy reference

Explanation:

An address group allows several address objects to be referenced collectively. Instead of creating separate firewall policies for every individual network when the same security treatment applies to all of them, administrators can place the relevant address objects into a group and use that group in a policy. This improves organization and can simplify policy maintenance. When a network is added or removed, the group membership can be updated without necessarily changing every policy that references it. Address groups do not perform routing or inspection themselves. They are configuration objects that help administrators express policy matching requirements more efficiently.

Question 352. Which FortiGate capability can identify the device type associated with network traffic?

  1. Device identification
    2. Static routing
    3. DHCP relay
    4. IPsec phase 2

Answer: 1. Device identification

Explanation:

Device identification allows FortiGate to gather information that can help classify endpoints according to device type or characteristics. This can provide additional context beyond an IP address when administrators are reviewing network activity or designing security policies. Depending on the environment and supported detection mechanisms, FortiGate may identify categories such as computers, mobile devices, or other endpoint types. Device information can support more context-aware security controls, but detection is not necessarily perfect and should be interpreted appropriately. Device identification is therefore useful for visibility and policy decisions, while the underlying firewall still relies on configured rules and supported identification information.

Question 353. What is the purpose of a FortiGate external connector?

  1. Connect FortiGate with an external information or security service
    2. Replace all firewall policies
    3. Increase physical interface bandwidth
    4. Disable logging

Answer: 1. Connect FortiGate with an external information or security service

Explanation:

External connectors allow FortiGate to integrate with supported external services or information sources. Depending on the connector type, external information may be used to provide additional context for security decisions, identity information, or threat intelligence. This can help extend FortiGate’s visibility beyond information generated locally on the appliance. Administrators should verify the connector’s purpose, authentication requirements, data source, and supported FortiOS version before deploying it. External connectors do not automatically replace existing security policies. Instead, they provide additional information or integration capabilities that can be incorporated into a broader security architecture.

Question 354. What is the purpose of a FortiGate VIP port-forwarding configuration?

  1. Map traffic arriving on a specific public port to an internal service
    2. Assign DHCP leases
    3. Create an OSPF area
    4. Configure a system administrator profile

Answer: 1. Map traffic arriving on a specific public port to an internal service

Explanation:

VIP port forwarding can map an externally reachable IP address and port to a different internal IP address and service port. This is commonly used when an internal server must provide a service through a FortiGate while using a public-facing address. For example, a public TCP port can be translated to a different TCP port on an internal server. A corresponding firewall policy is normally required to permit the intended inbound traffic. Administrators should expose only the necessary service and apply appropriate security controls. VIP configuration performs the address or port translation, while the firewall policy determines whether matching traffic is allowed.

Question 355. Which FortiGate feature can help verify whether an interface is physically connected and operational?

  1. Interface status information
    2. DLP profile
    3. Web Filter
    4. Automation Stitch

Answer: 1. Interface status information

Explanation:

Interface status information provides visibility into the operational state and configuration of FortiGate interfaces. Administrators can use it to determine whether an interface is up or down and review relevant information such as link state, addressing, speed, or other available interface details. This is one of the first areas to check when troubleshooting connectivity problems. A disconnected cable, disabled interface, incorrect VLAN configuration, or physical-link issue can prevent traffic from reaching the expected firewall policy. Interface status should be reviewed together with routing, ARP, firewall policy matching, and logs when investigating a broader connectivity problem.

Question 356. What is the purpose of configuring a FortiGate DNS server?

  1. Provide or relay DNS name-resolution services for network clients
    2. Replace the firewall policy engine
    3. Create IPS signatures
    4. Synchronize HA members

Answer: 1. Provide or relay DNS name-resolution services for network clients

Explanation:

FortiGate can provide DNS-related services to network clients depending on the configured DNS architecture. Clients may use FortiGate as their DNS resolver, while FortiGate can forward requests to configured upstream DNS servers. This allows the firewall to participate in name resolution and can integrate with other DNS-related security functions where supported. Administrators should configure appropriate upstream servers and ensure clients receive correct DNS settings through static configuration or DHCP. DNS configuration is separate from DNS filtering: the former concerns name-resolution service, while DNS filtering can apply security decisions to requested domains. Correct DNS operation is important for many network applications and services.

Question 357. What is the purpose of a FortiGate firewall policy ID?

  1. Uniquely identify a firewall policy within the configuration
    2. Define the policy’s encryption algorithm
    3. Assign a DHCP address
    4. Create a DNS record

Answer: 1. Uniquely identify a firewall policy within the configuration

Explanation:

A firewall policy ID provides an identifier that allows administrators and management systems to distinguish one policy from another. This is particularly useful when working with CLI commands, automation, logs, configuration reviews, and troubleshooting. Policy IDs help administrators refer to a specific rule even when several policies have similar names or purposes. The ID itself does not determine the security action, source, destination, or service. Those characteristics are defined by the policy configuration. Understanding policy identifiers can make administrative operations more precise and can help correlate configuration entries with troubleshooting information and policy-related activity.

Question 358. Which FortiGate capability can provide a centralized view of connected Fortinet security devices and their relationships?

  1. Security Fabric topology
    2. DHCP reservation
    3. Static route
    4. Service object

Answer: 1. Security Fabric topology

Explanation:

Security Fabric topology provides a visual representation of participating Fortinet devices and their relationships within an integrated Security Fabric environment. This can help administrators understand how FortiGate and other supported Fortinet components are connected and participating in the security architecture. A topology view can be useful when investigating device relationships, identifying connected components, and reviewing the overall structure of a deployment. It does not replace detailed configuration pages or individual device monitoring. Instead, it provides a broader architectural perspective that can help administrators understand how different security components work together within the organization’s environment.

Question 359. What is the purpose of configuring a FortiGate firewall policy with a specific service rather than allowing all services?

  1. Limit the policy to intended protocols or ports
    2. Automatically create an administrator account
    3. Disable routing
    4. Increase memory capacity

Answer: 1. Limit the policy to intended protocols or ports

Explanation:

Selecting specific services in a firewall policy limits matching traffic to the protocols and ports represented by those service objects. This allows administrators to implement more precise access controls instead of permitting every service between the specified source and destination networks. For example, a policy intended for a web server can be limited to the required web service rather than allowing unrelated protocols. Narrow service definitions support least-privilege network access and reduce unnecessary exposure. Administrators should identify the application’s actual communication requirements before restricting services, because overly narrow rules can prevent legitimate functionality. Service restrictions are an important part of precise firewall policy design.

Question 360. What is the main purpose of performing a configuration backup before making major FortiGate changes?

  1. Increase WAN bandwidth
    2. Provide a recovery point if the new configuration causes problems
    3. Automatically update FortiGuard signatures
    4. Create new firewall policies automatically

Answer: 2. Provide a recovery point if the new configuration causes problems

Explanation:

A configuration backup preserves a known configuration state that can be used for recovery if a significant change produces unexpected results. Before modifying routing, firewall policies, interfaces, VPN settings, or other critical functions, administrators can create a backup so the previous configuration remains available. This is especially important for remote devices where an incorrect change could interrupt management connectivity. Backups should be stored securely and clearly associated with the device and configuration version. A backup does not prevent configuration mistakes, but it provides an important recovery option. Administrators should also validate changes carefully and follow appropriate change-management procedures.