View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 161
Which FortiGate feature can identify applications even when they use ports that are not normally associated with those applications?
- Application Control
- DHCP
- NTP
- IP pool
Correct Answer: 1
Explanation
Application Control identifies applications using application signatures and inspection rather than relying only on traditional port numbers. This allows FortiGate to recognize applications that may use dynamic ports, shared ports, or protocols that do not clearly identify the application by port alone. Administrators can then create policies to allow, monitor, or block specific applications or categories. Application Control provides more granular visibility and control than basic port filtering. Proper inspection settings and current FortiGuard application signatures are important for accurate identification.
Question 162
Which FortiGate feature can block access to domains based on their reputation before the client establishes a full connection?
- Traffic shaping
- DNS Filter
- IPsec
- FortiView
Correct Answer: 2
Explanation
DNS Filter can evaluate DNS requests and apply actions based on domain categories, reputation, and configured filtering rules. If a requested domain is identified as malicious or prohibited, FortiGate can prevent the DNS request from resolving normally according to the configured policy. This can stop users from reaching known malicious destinations at an early stage. DNS filtering does not provide the same content-level inspection as other security profiles, so it is best used as one layer within a broader security architecture that includes web filtering, antivirus, IPS, and endpoint controls.
Question 163
What is the purpose of an IP pool on FortiGate?
- Provide a range of addresses for source NAT
- Define a VPN encryption algorithm
- Store DNS records
- Create administrator profiles
Correct Answer: 1
Explanation
An IP pool provides one or more IP addresses that FortiGate can use for source NAT. Instead of translating outbound traffic to only the interface address, administrators can configure a pool of public addresses and associate it with appropriate firewall policies. This can be useful when specific public source addresses are required for outbound services or when multiple translated addresses are needed. The pool must be correctly sized and routed so that translated traffic can return successfully. IP pools are different from destination NAT objects such as VIPs.
Question 164
A company wants outbound traffic from a specific internal server to always use one particular public IP address. Which feature can support this requirement?
- Web Filter
- IP pool with source NAT
- FortiAnalyzer
- DNS Filter
Correct Answer: 2
Explanation
An IP pool combined with source NAT can provide a specific translated public address for outbound traffic. A firewall policy can use the appropriate source address or other matching conditions and apply the configured IP pool for translation. This is useful when an external service requires traffic from a known public IP address for allowlisting or other access controls. Administrators must also ensure that return routing and policy configuration are correct. Source NAT changes the source address, while destination NAT is used for publishing internal services.
Question 165
Which FortiGate feature can use a username or group membership as a condition in a firewall policy?
- Identity-based policy
- IP pool
- Service group
- Static route
Correct Answer: 1
Explanation
Identity-based policies allow FortiGate to use authenticated user or group information when deciding whether traffic should be permitted. This enables organizations to apply different access rules to different departments, roles, or user groups even when users share the same network infrastructure. Identity information can come from supported authentication and identity sources. Administrators should ensure that authentication and identity mappings are accurate and available when policies are evaluated. Identity-based access can provide more granular control than policies based only on source IP addresses.
Question 166
Which FortiGate feature can restrict management access to an administrator based on the administrator’s source network?
- Trusted hosts
- Web Filter
- Application Control
- SD-WAN
Correct Answer: 1
Explanation
Trusted hosts allow administrators to specify the IP addresses or networks from which a particular administrator account can access FortiGate management services. This provides an additional access-control layer beyond the administrator’s username and password. For example, management access can be restricted to an internal administration network or a dedicated management workstation. If an administrator attempts to log in from an unauthorized source, access can be denied even when valid credentials are supplied. Trusted hosts should be combined with MFA, strong authentication, and secure management protocols.
Question 167
Which FortiGate feature allows an administrator to assign different permissions to different administrative accounts?
- Administrator profiles
- Address groups
- Service objects
- IPsec selectors
Correct Answer: 1
Explanation
Administrator profiles define the permissions available to FortiGate administrative accounts. Different administrators can receive different levels of access depending on their responsibilities. For example, an administrator may receive read-only access for monitoring while another may receive permission to modify firewall policies. Role-based administrative permissions reduce the risk of unnecessary configuration access and support the principle of least privilege. Administrators should regularly review profiles and account assignments to ensure that permissions remain appropriate as job responsibilities change.
Question 168
Which FortiGate feature can provide a second authentication factor using a token or verification code?
- FortiToken-based MFA
- Traffic shaping
- Address group
- Policy schedule
Correct Answer: 1
Explanation
FortiToken-based multi-factor authentication can provide an additional verification factor during supported authentication workflows. A user may provide a password and then enter a time-based verification code generated by an authentication token or supported application. This reduces dependence on passwords alone because possession of the additional authentication factor is also required. FortiGate can integrate MFA into administrator and user authentication scenarios according to the configured deployment. Administrators should plan token enrollment, recovery procedures, and backup authentication methods to avoid unnecessary account lockouts.
Question 169
Which FortiGate feature can record information about firewall traffic for later investigation?
- Traffic logging
- DHCP
- NTP
- VLAN
Correct Answer: 1
Explanation
Traffic logging records information about sessions and traffic handled by FortiGate policies. Depending on configuration, logs can contain details such as source and destination addresses, ports, interfaces, actions, users, applications, and timestamps. These records help administrators troubleshoot connectivity, investigate security events, and understand how policies are being used. Logs can also be forwarded to FortiAnalyzer or other supported logging systems for centralized analysis. Administrators should configure appropriate logging levels while considering storage requirements, privacy, and the operational value of collected information.
Question 170
A firewall policy is denying legitimate traffic. Which information should an administrator examine first to determine which rule is responsible?
- Policy matching and traffic logs
- NTP configuration only
- FortiToken enrollment
- DNS server software
Correct Answer: 1
Explanation
Policy matching information and traffic logs can help identify which firewall rule is handling the connection and why the traffic is being denied. Administrators should review the source and destination interfaces, addresses, services, users, schedules, and policy order associated with the session. Policy lookup can help determine the expected matching rule, while logs can show actual traffic and policy actions. Once the responsible rule is identified, the administrator can determine whether the policy conditions or action need adjustment without unnecessarily changing unrelated firewall rules.
Question 171
Which FortiGate feature provides logical separation of traffic by using IEEE 802.1Q VLAN tagging?
- VLAN interface
- IP pool
- VIP
- FortiAnalyzer
Correct Answer: 1
Explanation
A VLAN interface allows FortiGate to participate in networks that use IEEE 802.1Q VLAN tagging. VLANs provide logical separation over shared physical infrastructure, allowing different departments, services, or security zones to use separate Layer 2 segments. FortiGate can apply routing and firewall policies between these VLAN interfaces. Administrators must configure matching VLAN IDs and appropriate switch trunk settings so tagged traffic reaches the correct interface. VLAN segmentation can improve security and organization but should be combined with suitable firewall policies to enforce communication boundaries.
Question 172
Which network service automatically provides clients with an IP address and other network parameters?
- DNS
- DHCP
- NTP
- LDAP
Correct Answer: 2
Explanation
Dynamic Host Configuration Protocol, or DHCP, automatically provides network configuration information to clients. A DHCP server can assign IP addresses and provide settings such as subnet masks, default gateways, and DNS servers. FortiGate can operate as a DHCP server on supported interfaces, making it possible to centrally manage client addressing for local networks. Administrators should define appropriate address ranges and ensure that another DHCP server is not unintentionally serving the same segment. Proper DHCP configuration helps clients join the network without manual IP configuration.
Question 173
Which service translates domain names such as example.com into IP addresses?
- DNS
- DHCP
- NTP
- RADIUS
Correct Answer: 1
Explanation
Domain Name System, or DNS, translates human-readable domain names into IP addresses and supports other name-resolution functions. Network clients depend on DNS to locate many Internet and internal services without requiring users to remember numerical addresses. FortiGate can provide DNS-related services and can also apply DNS filtering policies depending on the deployment. DNS availability and correct configuration are important for application connectivity. Administrators should distinguish DNS resolution problems from routing or firewall problems when troubleshooting because a working network path may still fail if names cannot be resolved.
Question 174
Which protocol is commonly used to synchronize the system clocks of network devices?
- NTP
- LDAP
- RADIUS
- BGP
Correct Answer: 1
Explanation
Network Time Protocol, or NTP, synchronizes system clocks across networked devices. Accurate time is essential for security logging, event correlation, certificate validation, scheduled tasks, and troubleshooting. FortiGate can use configured NTP servers to maintain accurate system time. When investigating security incidents, consistent timestamps across firewalls, authentication servers, endpoints, and logging systems make it easier to reconstruct the sequence of events. Administrators should use reliable time sources and verify that the FortiGate device remains synchronized after configuration changes or connectivity interruptions.
Question 175
Which FortiGate feature can use VLANs to separate guest traffic from internal corporate traffic?
- Network segmentation
- Source NAT
- FortiToken
- Traffic shaping
Correct Answer: 1
Explanation
Network segmentation can separate guest users from internal corporate resources by placing them into different VLANs or network zones and controlling communication through FortiGate policies. Guest traffic can be provided with Internet access while access to sensitive internal networks is denied. Segmentation limits the potential impact of compromised or untrusted devices and helps enforce different security requirements for different groups. Administrators should define clear firewall policies between segments and avoid broad allow rules that could unintentionally permit guests to access internal services.
Question 176
Which FortiGate feature can detect the operating system or device type of connected endpoints?
- Device detection
- IPsec
- Schedule
- Service group
Correct Answer: 1
Explanation
Device detection provides information about endpoints connected to FortiGate interfaces. Depending on the available detection methods and traffic information, FortiGate may identify characteristics such as device type or operating system. This visibility can help administrators understand which devices are present and support network access decisions. Device detection is particularly useful for discovering unmanaged or unexpected devices. However, detection results should be validated when used for important security controls because identification accuracy can depend on the available network information and detection configuration.
Question 177
Which FortiGate diagnostic tool captures packets so an administrator can inspect their headers and traffic flow?
- Packet capture
- Policy schedule
- FortiToken
- Application Control
Correct Answer: 1
Explanation
Packet capture records network packets observed by FortiGate so administrators can inspect traffic details such as source and destination addresses, protocols, ports, and packet direction. It is useful for determining whether traffic reaches an interface and whether expected packets are being transmitted or received. Packet capture can help diagnose routing, application, and connectivity problems that are difficult to understand from logs alone. Because captured packets may contain sensitive information, administrators should limit captures to the required traffic and handle captured data according to organizational security policies.
Question 178
Which FortiGate troubleshooting feature can help identify the policy and route used by a specific packet flow?
- Debug flow
- DNS Filter
- Web Filter
- FortiToken
Correct Answer: 1
Explanation
Debug flow provides detailed information about how FortiGate processes traffic through routing and firewall policy decisions. Administrators can apply filters to focus the diagnostic output on specific source or destination addresses and then observe how matching and forwarding occur. This makes debug flow useful when traffic is unexpectedly denied, accepted, or sent through an incorrect path. Because the output can be extensive, filters should be used carefully and debugging should be stopped when sufficient information has been collected. It is a powerful troubleshooting tool for complex traffic-flow problems.
Question 179
Which FortiGate feature provides a visual summary of current network activity and top traffic sources?
- FortiView
- LDAP
- IP pool
- DHCP
Correct Answer: 1
Explanation
FortiView provides visual information about network activity, including traffic sources, destinations, applications, users, and security-related events. It can help administrators quickly identify high-volume traffic, unusual activity, and important communication patterns without manually reviewing every individual log. FortiView is useful for operational monitoring and initial investigation, while detailed logs and diagnostic tools can provide additional information when deeper analysis is required. Administrators should understand the available data sources and time ranges when interpreting FortiView information to avoid drawing conclusions from incomplete visibility.
Question 180
Which Fortinet product is designed to manage configurations and policies across multiple FortiGate devices?
- FortiManager
- FortiWeb
- FortiEDR
- FortiToken
Correct Answer: 1
Explanation
FortiManager provides centralized management of multiple FortiGate devices and supports centralized configuration and policy administration. Administrators can organize devices, manage policy packages, maintain configuration revisions, and coordinate changes from a central platform. This can improve consistency across distributed firewall deployments and reduce repetitive administrative work. Because a centralized change can affect multiple devices, administrators should use appropriate change-control procedures and verify configurations before deployment. FortiManager is focused on centralized management, while FortiAnalyzer is primarily focused on centralized logging, analysis, and reporting.