View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 181
Which FortiGate feature can distribute traffic across multiple servers providing the same service?
- DNS Filter
- Virtual Server
- FortiAnalyzer
- FortiToken
Correct Answer: 2
Explanation
A virtual server can provide a front-end address for services hosted by multiple backend servers. FortiGate can use virtual server and load-balancing capabilities to distribute incoming connections among available servers according to the configured method. This can improve service availability and help prevent one backend server from receiving all incoming traffic. Administrators should configure appropriate health checks and backend members so unavailable servers are not selected unnecessarily. Load balancing should also be combined with suitable firewall policies and security controls to protect the published service.
Question 182
Which FortiGate feature can verify whether a backend server is still available before sending it client traffic?
- Health check
- Address group
- Schedule
- IP pool
Correct Answer: 1
Explanation
A health check monitors the availability or responsiveness of a backend server so FortiGate can make informed load-balancing decisions. If a server fails the configured health-check criteria, FortiGate can avoid directing new connections to that server until it becomes healthy again. Health checks can use appropriate protocols or service tests depending on the configuration. Correct thresholds and intervals are important because overly aggressive settings can mark healthy servers unavailable, while weak checks may fail to detect service problems promptly.
Question 183
Which FortiGate feature can use a single public address to represent a group of backend servers?
- VLAN interface
- Virtual Server
- NTP
- Service group
Correct Answer: 2
Explanation
A virtual server can provide a public-facing address through which clients access services hosted by backend servers. FortiGate receives the incoming connection and can distribute it among configured real servers according to the selected load-balancing behavior. This architecture allows organizations to expose one service address while maintaining multiple backend systems. It can improve availability and scalability when several servers provide the same application. Administrators should configure the virtual server, backend members, service ports, health checks, and related firewall policies consistently.
Question 184
An administrator wants to prevent users from accessing a specific website while allowing other sites in the same category. Which FortiGate capability can provide a targeted exception?
- Web Filter override or URL filter
- NTP
- SD-WAN SLA
- DHCP relay
Correct Answer: 1
Explanation
Web filtering can use URL-specific rules or overrides to create more targeted decisions than broad category blocking. An administrator can configure a specific website or URL according to the organization’s access requirements while leaving other sites within the broader category unaffected. This is useful when a category contains both permitted and restricted destinations. Administrators should carefully define the matching pattern and action and test the result with the actual client traffic. HTTPS inspection requirements should also be considered when deeper URL visibility is needed.
Question 185
Which FortiGate capability can identify websites using FortiGuard category information?
- Web Filter
- Traffic Shaping
- IPsec
- DHCP
Correct Answer: 1
Explanation
Web Filter can use FortiGuard category information to classify requested websites and apply configured access decisions. Categories help administrators create broader web-access policies without maintaining a manual list of every website. For example, an organization can block categories associated with malicious or inappropriate content while allowing business-related categories. Administrators can also configure specific exceptions where necessary. Category-based filtering depends on current classification information and suitable traffic visibility, so FortiGuard updates and appropriate inspection settings are important for reliable policy enforcement.
Question 186
Which FortiGate feature can control access to network resources based on endpoint compliance information?
- Network Access Control
- Static route
- IP pool
- Service group
Correct Answer: 1
Explanation
Network Access Control can use information about endpoints and their security or identity characteristics when making network-access decisions. Depending on the Fortinet deployment, endpoints can be identified and assigned appropriate access based on configured policies. Noncompliant or unknown devices can be restricted or placed into controlled network segments, while trusted devices can receive normal access. NAC is particularly useful for environments containing managed and unmanaged endpoints. Administrators should integrate endpoint visibility, authentication, segmentation, and enforcement carefully to achieve predictable access behavior.
Question 187
Which FortiGate capability can place traffic into a separate virtual routing and forwarding context?
- VDOM
- Web Filter
- FortiToken
- Antivirus
Correct Answer: 1
Explanation
VDOMs provide separate logical firewall environments within a FortiGate. Each VDOM can maintain its own routing and security configuration, allowing organizations to isolate different networks or administrative environments on shared hardware. This separation can be useful for multi-tenant deployments, departmental environments, or situations requiring independent security policies. Administrators should understand resource allocation and communication requirements before creating VDOMs. Inter-VDOM communication, interface assignments, routing, and administrative permissions must be designed carefully to maintain the intended separation.
Question 188
Which FortiGate feature can use a dedicated interface for management traffic rather than normal production traffic?
- Dedicated management interface
- Service group
- DNS Filter
- IP pool
Correct Answer: 1
Explanation
A dedicated management interface provides a separate network path for administrative access to FortiGate. Keeping management traffic separate from production traffic can reduce exposure and make administrative access easier to control. Administrators can combine a dedicated management interface with trusted hosts, secure protocols, MFA, and restrictive network policies. This architecture can also simplify monitoring and access-control requirements because management traffic is handled through a defined administrative network. The exact management-interface capabilities depend on the FortiGate model and deployment configuration.
Question 189
Which FortiGate feature can protect administrative access by limiting the protocols enabled on an interface?
- Administrative access settings
- Application Control
- Traffic shaping
- DNS Filter
Correct Answer: 1
Explanation
Administrative access settings determine which management services are available through a FortiGate interface. Administrators can enable only the protocols required for management, such as HTTPS or SSH, while disabling unnecessary services. Restricting management protocols reduces the number of exposed services and therefore limits opportunities for unauthorized access. This control should be combined with trusted hosts, strong authentication, MFA, and appropriate network segmentation. Management access should generally be provided only through interfaces and networks specifically intended for administration.
Question 190
Which FortiGate feature can provide a centralized view of security events generated by multiple Fortinet devices?
- FortiAnalyzer
- FortiToken
- FortiWeb
- FortiSwitch
Correct Answer: 1
Explanation
FortiAnalyzer provides centralized collection and analysis of logs and security events from supported Fortinet devices. By consolidating information from multiple FortiGate systems, it allows administrators to investigate events across a broader environment rather than examining each firewall separately. It can also support dashboards, reports, and historical analysis. Centralized event visibility is valuable for incident investigation and operational monitoring. Administrators should configure appropriate log forwarding and retention settings so important events are available for analysis when required.
Question 191
Which FortiGate feature can limit access to a service by specifying the permitted source and destination addresses?
- Firewall policy
- NTP
- FortiView
- FortiToken
Correct Answer: 1
Explanation
A firewall policy can define the source and destination addresses that are permitted to communicate through FortiGate. It can also include interfaces, services, schedules, users, and security profiles to create more detailed access rules. Restricting source and destination addresses helps enforce least-privilege network access by allowing communication only between required systems. Administrators should avoid unnecessarily broad address objects because they can expand the scope of permitted traffic. Policy order must also be considered because an earlier matching rule may handle the traffic.
Question 192
Which FortiGate feature can apply a security profile to traffic after it matches a firewall policy?
- Firewall policy security profile
- DHCP server
- NTP server
- IP pool
Correct Answer: 1
Explanation
Security profiles can be attached to firewall policies to apply additional inspection and protection to permitted traffic. Depending on the policy and configuration, profiles can provide functions such as antivirus scanning, web filtering, application control, IPS, and other security services. This allows administrators to combine basic traffic control with deeper security inspection. The exact profiles used should match the traffic type and organizational requirements. Administrators should also verify that inspection settings provide the necessary visibility, particularly when traffic is encrypted.
Question 193
Which FortiGate feature can enforce different security inspection requirements for different types of traffic?
- Firewall policies with security profiles
- DHCP reservations
- Static DNS entries
- NTP configuration
Correct Answer: 1
Explanation
FortiGate firewall policies can apply different security profiles and inspection settings to different traffic flows. For example, Internet browsing traffic may require web filtering and antivirus inspection, while another application may require IPS protection or application control. Creating policies according to traffic requirements allows administrators to apply appropriate security controls without treating every connection identically. Policy matching conditions such as interfaces, addresses, services, users, and schedules can help separate traffic types. Careful policy design reduces unnecessary inspection while maintaining the required security coverage.
Question 194
Which FortiGate capability can provide detailed records of actions taken by administrators?
- Administrative event logging
- Traffic shaping
- DNS Filter
- IP pool
Correct Answer: 1
Explanation
Administrative event logging records management activities and configuration-related events on FortiGate. These logs can help identify who performed an administrative action, what type of activity occurred, and when it happened. Such information is valuable for troubleshooting, accountability, and security investigations. Administrators should ensure that relevant event logging is enabled and that logs are retained appropriately. Centralized logging through FortiAnalyzer can provide additional visibility when multiple FortiGate devices are involved and can help correlate administrative actions with other security events.
Question 195
Which FortiGate feature can provide a temporary access period without requiring a policy to remain active permanently?
- Policy schedule
- Address group
- Service group
- VLAN interface
Correct Answer: 1
Explanation
A policy schedule can limit when a firewall policy is active, making it useful for temporary or recurring access requirements. For example, administrators can permit access during a defined maintenance window and automatically disable the policy outside that period. This reduces the need to manually modify or remove the rule after the approved access period ends. Schedules can also support recurring business-hour requirements. Administrators should verify system time and timezone configuration so the policy activates and expires at the intended times.
Question 196
Which FortiGate feature can help identify whether a firewall policy is being used by active sessions?
- Session monitoring
- NTP
- FortiToken
- DNS Filter
Correct Answer: 1
Explanation
Session monitoring provides information about active network sessions handled by FortiGate. Administrators can use session information to examine current connections, including relevant source and destination details and associated traffic. This can help determine whether a policy is actively handling traffic and can support troubleshooting when a connection behaves unexpectedly. Session monitoring is different from historical logging because it focuses on active or current session information. Administrators can combine session information with policy lookup, logs, routing data, and debug tools for more complete analysis.
Question 197
Which FortiGate capability can help protect against unauthorized configuration changes by limiting administrator permissions?
- Role-based administrator profiles
- DNS Filter
- SD-WAN
- IPsec
Correct Answer: 1
Explanation
Role-based administrator profiles allow FortiGate administrators to receive only the permissions necessary for their assigned responsibilities. Restricting configuration access reduces the chance that a compromised or misused account can make unauthorized changes to critical security settings. Different profiles can provide read-only, monitoring, or specific configuration privileges depending on the administrative role. Administrators should periodically review accounts and profiles and remove unnecessary permissions. Combining role-based access with MFA, trusted hosts, and administrative logging provides stronger protection for the firewall management plane.
Question 198
Which FortiGate feature can identify suspicious communication patterns that match known attack signatures?
- IPS
- DHCP
- NTP
- IP pool
Correct Answer: 1
Explanation
IPS uses security signatures and inspection mechanisms to identify network activity associated with known attacks and suspicious patterns. When traffic matches a configured IPS signature, FortiGate can take an action such as blocking or logging the event according to the profile configuration. IPS signature updates help maintain protection against newly identified threats. Administrators should tune IPS policies to the environment and investigate significant detections rather than relying only on automatic blocking. Combining IPS with endpoint security, segmentation, patching, and access controls provides broader defense.
Question 199
Which FortiGate feature can make Internet access decisions based on the category or reputation of a requested domain?
- DNS Filter
- Traffic Shaping
- IPsec
- NTP
Correct Answer: 1
Explanation
DNS Filter can evaluate DNS requests using category and reputation information and apply configured actions to requested domains. This can prevent users from resolving known malicious or restricted domains before they establish a connection to those destinations. It provides an early filtering layer that can complement web filtering and endpoint protection. Administrators should ensure that clients use the intended DNS path so requests can be inspected by the configured control. DNS filtering alone does not replace deeper inspection of application content or encrypted traffic.
Question 200
Which FortiGate feature can help administrators investigate why traffic is being denied by a firewall policy?
- Policy lookup and traffic logs
- NTP synchronization
- DHCP reservations
- FortiToken enrollment
Correct Answer: 1
Explanation
Policy lookup and traffic logs provide complementary information when investigating denied traffic. Policy lookup can help determine which configured rule should match a particular traffic flow, while traffic logs can show actual sessions, actions, source and destination information, and other details depending on logging configuration. Administrators can use these tools to identify incorrect addresses, services, interfaces, schedules, or policy ordering. If the cause remains unclear, packet capture and debug flow can provide deeper information about packet processing and forwarding decisions.