Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 121

Which FortiGate feature can inspect traffic and identify the users generating it?

  1. User identity
  2. IP pool
  3. Static route
  4. Service group

Correct Answer: 1

Explanation

User identity allows FortiGate to associate network traffic with authenticated users and apply policies based on identity. Instead of relying only on IP addresses, administrators can create access rules that determine which users or groups are permitted to reach particular resources. FortiGate can obtain identity information through supported authentication and identity integration methods. Identity-based policies are useful in environments where access requirements differ between departments or user groups. Administrators should ensure that identity information remains accurate so that users receive the intended level of network access.

Question 122

Which FortiGate feature can provide single sign-on information from a Windows Active Directory environment?

  1. DHCP
  2. FSSO
  3. IPsec
  4. SD-WAN

Correct Answer: 2

Explanation

Fortinet Single Sign-On, or FSSO, allows FortiGate to obtain user identity information from supported authentication environments such as Microsoft Active Directory. Users can be identified based on their existing domain authentication rather than being required to authenticate separately to the firewall for every access request. FortiGate can then use the collected identity information in firewall policies and security controls. Proper collector configuration, communication, and directory integration are important for reliable identity information and accurate policy enforcement.

Question 123

Which FortiGate security feature is specifically designed to identify known malicious or suspicious network attacks?

  1. Web Filter
  2. DNS Filter
  3. IPS
  4. DHCP

Correct Answer: 3

Explanation

Intrusion Prevention System, or IPS, is designed to detect and potentially block malicious network activity based on signatures and other inspection mechanisms. FortiGate IPS can identify attempts to exploit vulnerabilities, suspicious protocols, and other recognized attack patterns. Administrators can configure actions such as blocking or logging depending on the signature and security requirements. IPS signatures are updated through FortiGuard services to address newly identified threats. IPS should be combined with patching, endpoint protection, access controls, and other security measures for broader protection.

Question 124

A security administrator wants FortiGate to block websites classified as phishing. Which security profile should be configured?

  1. Traffic Shaping
  2. Antivirus
  3. Application Control
  4. Web Filter

Correct Answer: 4

Explanation

Web Filter can use FortiGuard web categorization and reputation information to identify websites associated with phishing and other undesirable categories. Administrators can configure actions for specific categories, including blocking access or logging the activity. When HTTPS traffic must be inspected more deeply, suitable SSL inspection may also be required so that FortiGate can obtain sufficient information about the requested content. Web Filter is therefore an important control for reducing exposure to malicious and inappropriate websites, especially when combined with DNS filtering and endpoint security.

Question 125

Which FortiGate feature can apply different security policies to separate virtual firewall environments on the same physical device?

  1. IP pool
  2. VDOM
  3. Service object
  4. Traffic shaping

Correct Answer: 2

Explanation

Virtual Domains, or VDOMs, allow a FortiGate device to be divided into multiple logical firewall environments. Each VDOM can have its own interfaces, policies, routing configuration, administrators, and other resources depending on the deployment. This can be useful for service providers, organizations with separate departments, or environments requiring administrative and security separation. VDOMs help isolate configurations while allowing multiple logical firewall instances to operate on shared hardware. Administrators must plan resource allocation and inter-VDOM communication carefully when implementing this architecture.

Question 126

Which FortiGate feature can limit the amount of bandwidth consumed by a particular traffic class?

  1. Traffic shaping
  2. DNS Filter
  3. VIP
  4. FortiAnalyzer

Correct Answer: 1

Explanation

Traffic shaping controls bandwidth consumption for selected traffic. Administrators can use shaping policies to limit or prioritize network traffic according to organizational requirements. This is useful when high-bandwidth applications could otherwise consume resources needed by business-critical services. FortiGate can apply traffic-shaping settings through firewall policies and related configuration options. Proper configuration requires understanding available bandwidth and application requirements. Traffic shaping does not replace security inspection; instead, it complements security policies by controlling how network resources are allocated among different types of traffic.

Question 127

Which FortiGate feature provides graphical visibility into traffic, applications, and security activity?

  1. FortiToken
  2. FortiView
  3. FortiWeb
  4. FortiSwitch

Correct Answer: 2

Explanation

FortiView provides graphical and interactive visibility into network traffic, applications, users, destinations, and security-related activity on FortiGate. It helps administrators identify traffic patterns and investigate unusual behavior without manually reviewing every individual log entry. Different FortiView views can provide information about current and historical activity depending on the available data. FortiView is primarily a visibility and analysis feature rather than a replacement for security policies. Administrators can use its information alongside logs, reports, and diagnostic tools when investigating network events.

Question 128

Which FortiGate component provides centralized security event logging and analysis?

  1. FortiManager
  2. FortiAuthenticator
  3. FortiAnalyzer
  4. FortiToken

Correct Answer: 3

Explanation

FortiAnalyzer is designed for centralized log collection, analysis, event investigation, and reporting across supported Fortinet devices. It can receive logs from FortiGate and other systems, allowing security teams to investigate activity from a centralized location. Historical data can help identify trends and support incident investigations. FortiAnalyzer also provides dashboards and reporting capabilities that can make large volumes of security information easier to interpret. Proper log forwarding and storage configuration are important to ensure that relevant events are available when investigation is required.

Question 129

What is the purpose of FortiGuard services on FortiGate?

  1. Provide threat intelligence and security updates
  2. Replace all firewall policies
  3. Assign VLAN IDs
  4. Create physical interfaces

Correct Answer: 1

Explanation

FortiGuard services provide security intelligence and updates used by Fortinet security technologies. Depending on the service, FortiGuard can provide information such as antivirus signatures, IPS signatures, web categories, application signatures, and reputation data. Keeping these services updated helps FortiGate recognize newly identified threats and categories. FortiGuard services complement the firewall’s locally configured policies rather than replacing them. Administrators should verify licensing, connectivity, update status, and configuration to ensure that the FortiGate device can receive the security intelligence required by enabled security features.

Question 130

Which FortiGate feature can detect devices connected to the network and provide information about them?

  1. IPsec
  2. Device detection
  3. NAT
  4. Traffic shaping

Correct Answer: 2

Explanation

Device detection provides visibility into devices connected through FortiGate interfaces. Depending on the configured detection methods and available information, FortiGate can identify device characteristics such as operating system or device type. This information can help administrators understand what is present on the network and support segmentation and access-control decisions. Device detection is particularly useful in environments with many endpoints or unmanaged devices. Detection results should be treated as visibility information and validated when making important security decisions.

Question 131

Which protocol is commonly used to securely administer a FortiGate through a command-line interface?

  1. FTP
  2. Telnet
  3. SSH
  4. HTTP

Correct Answer: 3

Explanation

Secure Shell, or SSH, provides encrypted command-line access to FortiGate for administrative tasks. It protects management communication from simple network interception compared with unencrypted protocols such as Telnet. Administrators can enable SSH on appropriate interfaces and restrict access using trusted hosts, firewall controls, administrator permissions, and other security mechanisms. SSH should not be exposed unnecessarily to untrusted networks. Strong authentication and appropriate administrative profiles should also be used to reduce the risk associated with compromised management credentials.

Question 132

Which service is commonly used for secure browser-based FortiGate administration?

  1. HTTPS
  2. TFTP
  3. FTP
  4. Telnet

Correct Answer: 1

Explanation

HTTPS provides encrypted browser-based access to the FortiGate administrative interface. It protects management communication between the administrator’s browser and the firewall and is commonly used for GUI administration. Administrators can control which interfaces allow HTTPS management and can further restrict access through trusted hosts and network security policies. Using secure management protocols helps reduce the risk of credentials and administrative information being exposed. Unnecessary management services should be disabled, and administrative access should be limited to authorized users and trusted networks.

Question 133

Which FortiGate diagnostic tool can show the path packets take toward a destination?

  1. Packet capture
  2. Traceroute
  3. FortiView
  4. Antivirus

Correct Answer: 2

Explanation

Traceroute helps administrators identify the network path packets take toward a destination. It can show intermediate routing hops and help determine where connectivity may be failing or experiencing unexpected behavior. On FortiGate, traceroute can be useful when investigating routing problems, unreachable destinations, or unusual network paths. The results should be interpreted carefully because firewalls and routers may block or deprioritize traceroute-related traffic. Administrators can combine traceroute results with routing-table information, packet captures, and firewall logs for more complete troubleshooting.

Question 134

Which command or diagnostic approach is useful for checking whether a destination responds to basic IP connectivity tests?

  1. Policy lookup
  2. Debug flow
  3. Ping
  4. Packet capture

Correct Answer: 3

Explanation

Ping uses ICMP echo requests and replies to test basic IP connectivity between a source and destination. On FortiGate, administrators can use ping as an initial troubleshooting step to determine whether a destination is reachable at the network layer. A successful ping does not prove that a specific application or TCP/UDP service is functioning, because those services may use different protocols or ports. Likewise, a failed ping may result from ICMP filtering rather than complete network failure. Ping should therefore be combined with additional diagnostics when necessary.

Question 135

Which FortiGate feature can define a reusable collection of network addresses, services, and other matching objects for policy configuration?

  1. Security profile
  2. Policy object
  3. Firewall object
  4. Address and service objects

Correct Answer: 4

Explanation

FortiGate uses configurable objects such as address objects and service objects to represent network destinations, sources, protocols, and ports in firewall policies. These objects can be reused across multiple policies, which improves consistency and simplifies configuration changes. For example, an administrator can modify an address object rather than manually editing every policy that references the same network. Related objects can also be grouped where appropriate. A structured object-based configuration makes large FortiGate deployments easier to manage and reduces unnecessary duplication.

Question 136

A FortiGate administrator needs to permit HTTPS access only to a specific internal server from the Internet. Which combination is most appropriate?

  1. VIP and a restricted firewall policy
  2. DNS Filter and DHCP
  3. SD-WAN and FortiView
  4. Traffic shaping and NTP

Correct Answer: 1

Explanation

A VIP can map an external address or port to the internal server, while a firewall policy controls which external traffic is allowed to reach that mapped service. The policy should restrict the source addresses, destination, and HTTPS service as appropriate rather than allowing unnecessary access. This combination provides both destination translation and security enforcement. Administrators should expose only the required service and consider additional protections such as IPS, appropriate inspection, logging, and secure server configuration when publishing an internal service to the Internet.

Question 137

Which FortiGate feature can synchronize time with a reliable external time source?

  1. DNS Filter
  2. NTP
  3. DHCP relay
  4. Web Filter

Correct Answer: 2

Explanation

Network Time Protocol, or NTP, synchronizes the FortiGate system clock with a configured time source. Accurate system time is important for log timestamps, security investigations, certificate validation, scheduled operations, and coordination with other network devices. If different systems use significantly different clocks, correlating security events can become difficult. Administrators should configure reliable NTP sources and verify synchronization status. Accurate timekeeping is a basic but important component of network security because many monitoring and troubleshooting activities depend on trustworthy timestamps.

Question 138

Which FortiGate feature can provide IP address assignment to clients on a local network?

  1. DHCP server
  2. FortiAnalyzer
  3. IPS
  4. Web Filter

Correct Answer: 1

Explanation

The FortiGate DHCP server can dynamically provide clients with network configuration information such as IP addresses, subnet masks, gateways, and DNS server details. This simplifies endpoint configuration on networks where static addressing is not required. Administrators can define address ranges and other DHCP parameters according to the requirements of each interface or network segment. DHCP configuration should avoid overlapping address ranges and should be coordinated with any external DHCP servers. Proper configuration helps ensure that clients receive valid network settings and can communicate as intended.

Question 139

Which FortiGate feature can restrict administrative access to specific trusted source IP addresses?

  1. Address group
  2. Trusted hosts
  3. Service group
  4. IP pool

Correct Answer: 2

Explanation

Trusted hosts can restrict an administrator account so that management access is accepted only from specified source IP addresses or networks. This provides an additional layer of protection for FortiGate administrative accounts. Even if valid credentials are obtained, an attacker connecting from an unauthorized source may be unable to use that administrator account. Trusted hosts should be configured carefully so legitimate administrators retain access. They work best alongside strong passwords, MFA, secure management protocols, appropriate administrator profiles, and restricted management interfaces.

Question 140

Which FortiGate security principle is best represented by granting an administrator only the permissions required for their job?

  1. Network Address Translation
  2. High availability
  3. Least privilege
  4. Load balancing

Correct Answer: 3

Explanation

Least privilege means providing users and administrators only the permissions necessary to perform their assigned responsibilities. In FortiGate environments, administrator profiles can be configured to limit access to specific functions and configuration areas. This reduces the potential impact of compromised credentials or accidental administrative changes. For example, an administrator responsible for monitoring may not require full configuration privileges. Applying least privilege should be combined with MFA, trusted hosts, secure management access, logging, and regular review of administrative accounts to maintain strong access control.