View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 241
Which FortiGate feature can identify malicious or suspicious domain names before a user connects to them?
- Traffic shaping
- DNS Filter
- IP pool
- OSPF
Correct Answer: 2
Explanation
DNS Filter evaluates DNS requests and can use domain reputation and configured filtering rules to control access to domains. It can help prevent users from resolving or reaching known malicious, phishing, or otherwise restricted domains. FortiGate can use FortiGuard DNS filtering information together with locally configured rules. DNS filtering is different from Web Filter because it operates at the DNS request level rather than primarily categorizing web URLs. Administrators should ensure DNS traffic is handled through the intended FortiGate security policy and that required FortiGuard services are available.
Question 242
A company wants to inspect encrypted HTTPS traffic so that FortiGate can apply security controls to the contents. Which feature is required?
- Deep inspection
- DHCP
- Static routing
- Traffic shaping
Correct Answer: 1
Explanation
Deep inspection allows FortiGate to decrypt and inspect supported encrypted traffic so that security profiles can examine its contents. This provides deeper visibility into HTTPS traffic than simply inspecting the certificate information. Because the traffic is decrypted and re-encrypted, client devices generally need to trust the appropriate FortiGate inspection certificate to avoid certificate warnings. Administrators should consider privacy, application compatibility, and certificate deployment before enabling deep inspection broadly. Proper exemptions may also be required for applications or destinations that cannot operate correctly under deep inspection.
Question 243
Which inspection method examines the server certificate without decrypting the actual encrypted content?
- Deep inspection
- Application Control
- Certificate inspection
- Antivirus
Correct Answer: 3
Explanation
Certificate inspection examines information contained in the SSL/TLS certificate and connection without decrypting the complete encrypted payload. It can provide visibility into certificate details and support certain security decisions while avoiding the full interception performed by deep inspection. This makes certificate inspection less intrusive, although it provides less visibility into the actual contents of encrypted sessions. Administrators should select the inspection method according to the security requirements of the traffic. Deep inspection may be necessary when security profiles must inspect the encrypted payload itself.
Question 244
Which FortiGate setting determines the time period during which a firewall policy is active?
- Service object
- Policy schedule
- Address group
- VLAN
Correct Answer: 2
Explanation
A policy schedule determines when a firewall policy is active. Administrators can configure schedules for specific periods, allowing access to be permitted or denied only during defined times. This can be useful for restricting Internet access after business hours, allowing temporary services, or implementing time-based security requirements. Schedules can be reused by appropriate policies and should be reviewed carefully when troubleshooting traffic that is unexpectedly allowed or denied. If the current time falls outside the configured schedule, the associated firewall policy may not handle the traffic as expected.
Question 245
Which FortiGate object groups multiple services so they can be referenced together in policies?
- Service group
- IPsec tunnel
- VDOM
- Performance SLA
Correct Answer: 1
Explanation
A service group combines multiple service objects into one logical collection that can be referenced by firewall policies. For example, an administrator may group HTTP, HTTPS, and other required services instead of adding each service separately to multiple policies. This can simplify policy configuration and improve consistency when the same collection of services is needed in several rules. Changes to the underlying service definitions or group membership should be reviewed carefully because they can affect every policy that references the group. Service groups are useful for organizing repetitive policy requirements.
Question 246
What is the main purpose of an IP pool on FortiGate?
- Define OSPF areas
- Provide a range of addresses for source NAT
- Store DNS records
- Configure administrator permissions
Correct Answer: 2
Explanation
An IP pool provides a configured set or range of IP addresses that FortiGate can use for source NAT. Instead of translating multiple internal clients to only the outgoing interface address, administrators can configure a pool of external addresses for translation according to network requirements. This can be useful when an organization owns multiple public addresses and needs predictable source addresses for certain outbound traffic. The IP pool must be appropriately configured and associated with the relevant firewall policy or NAT behavior. Routing and return traffic must also be considered.
Question 247
Which feature allows FortiGate to create separate virtual security domains on a single physical device?
- VDOM
- VIP
- DHCP
- DNS Filter
Correct Answer: 1
Explanation
Virtual Domains, or VDOMs, allow a FortiGate device to be divided into multiple independent virtual security domains. Each VDOM can maintain its own policies, interfaces, routing configuration, and other resources according to the deployment model. This can help organizations separate departments, customers, or network environments on the same physical appliance. Administrators must understand the relationship between global settings and VDOM-specific settings when managing a multi-VDOM environment. Proper resource allocation and administrative permissions are also important to prevent configuration conflicts.
Question 248
Which feature can group several FortiGate interfaces so that a firewall policy can reference them as one logical interface group?
- Service group
- Interface zone
- IP pool
- Traffic selector
Correct Answer: 2
Explanation
An interface zone allows multiple interfaces to be treated as a logical group for policy configuration. Instead of creating separate policies for every interface when the same security requirements apply, administrators can use a zone to simplify policy management. This can be useful when several interfaces represent the same security trust level or operational function. Careful design is required because grouping interfaces together can broaden the scope of policies that reference the zone. Administrators should ensure that all included interfaces genuinely require the same access controls.
Question 249
Which FortiGate feature can detect and block applications according to application signatures and categories?
- Application Control
- NTP
- DHCP
- VIP
Correct Answer: 1
Explanation
Application Control identifies network applications and allows administrators to apply actions based on application signatures or categories. Policies can be configured to block, monitor, or otherwise control applications according to organizational requirements. This differs from simple service filtering because application identification can determine the application generating traffic even when port numbers alone are insufficient. Application Control should be applied through appropriate firewall policies, and administrators should review application detection results when troubleshooting unexpected behavior. Current FortiGuard application intelligence can improve identification of supported applications.
Question 250
A FortiGate administrator needs to determine which firewall policy is expected to handle a specific source and destination. Which feature is useful?
- Policy lookup
- NTP
- FortiToken
- DHCP
Correct Answer: 1
Explanation
Policy lookup helps administrators determine which firewall policy would match particular traffic characteristics. It can be useful when several policies contain overlapping addresses, interfaces, services, or other criteria and the administrator needs to understand which rule is relevant. Since FortiGate evaluates policies according to their configured order, an earlier matching rule can prevent a later rule from being reached. Policy lookup can therefore simplify troubleshooting and policy validation. Administrators should also consider routing and NAT because identifying the matching policy does not by itself guarantee successful end-to-end connectivity.
Question 251
Which routing protocol uses a link-state database to calculate paths within an autonomous system?
- BGP
- OSPF
- DHCP
- RADIUS
Correct Answer: 2
Explanation
OSPF is a link-state routing protocol that maintains information about the network topology and uses that information to calculate routes. Routers exchange link-state information with OSPF neighbors and build a link-state database for their relevant area. OSPF then uses the shortest-path algorithm to determine suitable routes. FortiGate can participate in OSPF routing and exchange route information with other routers. Correct neighbor formation, interface configuration, area assignment, and network reachability are important when diagnosing OSPF problems.
Question 252
Which BGP mechanism can influence route selection by applying attributes to routes?
- Route policy
- DNS Filter
- Web Filter
- VLAN
Correct Answer: 1
Explanation
BGP route policies can influence which routes are accepted, preferred, advertised, or modified by applying routing conditions and attributes. Administrators can use policy mechanisms to control how FortiGate interacts with BGP peers and to influence route-selection behavior. This is important in environments with multiple connections or complex routing requirements. BGP policy configuration must be carefully validated because incorrect filtering or attribute manipulation can cause routes to be unexpectedly accepted, rejected, or preferred. Administrators should review advertised and received prefixes when troubleshooting BGP behavior.
Question 253
Which FortiGate security control is designed specifically to inspect network traffic for intrusion signatures?
- Web Filter
- Antivirus
- IPS
- DNS Filter
Correct Answer: 3
Explanation
Intrusion Prevention System, or IPS, examines network traffic for patterns associated with known attacks, exploits, and suspicious activity. FortiGate IPS uses signatures and other detection mechanisms to identify potentially harmful traffic and can take configured actions such as blocking or logging. IPS is commonly applied through firewall policies to protect traffic crossing the FortiGate. Administrators should maintain current security intelligence and select appropriate IPS settings for the environment. Reviewing IPS logs can help determine which signature detected an event and whether further investigation is required.
Question 254
Which feature can restrict access to a specific website even when the site’s IP address is known?
- Web Filter
- NTP
- OSPF
- IP pool
Correct Answer: 1
Explanation
Web Filter can control access to websites using URL filtering, categories, and other supported web-filtering mechanisms. This provides a higher-level control than simply permitting or denying an IP address because websites and hosted services may use shared infrastructure or changing addresses. Administrators can combine category-based filtering with specific URL filtering rules to meet organizational requirements. The Web Filter profile must be attached to the firewall policy handling the relevant traffic. Appropriate inspection settings and FortiGuard connectivity may be necessary for certain filtering functions.
Question 255
Which FortiGate security feature is used to inspect downloaded files for malware?
- Antivirus
- OSPF
- SD-WAN
- RADIUS
Correct Answer: 1
Explanation
FortiGate Antivirus inspects supported traffic and files for malware and other known malicious content. When a threat is identified, the configured profile can take an action such as blocking or logging the event. Antivirus protection can complement other controls such as IPS, Web Filter, and Application Control because each addresses different aspects of network security. Administrators should ensure that appropriate inspection is enabled for the traffic being protected and that security intelligence remains current. Logs can provide useful details about detected files and corresponding security actions.
Question 256
Which FortiGate feature can measure packet loss on a WAN path for SD-WAN decisions?
- Performance SLA
- Address group
- Service group
- Administrator profile
Correct Answer: 1
Explanation
A Performance SLA can monitor characteristics of SD-WAN members, including packet loss, latency, and jitter, depending on the configured health checks. Packet loss represents packets that fail to reach the expected destination and can significantly affect application performance. FortiGate can use SLA results when determining whether a path meets the requirements of an SD-WAN rule. Administrators should select realistic thresholds based on application needs and WAN characteristics. If a link repeatedly fails the SLA, SD-WAN can favor another suitable member when the configured rule permits such behavior.
Question 257
Which FortiGate feature provides centralized management of multiple FortiGate configurations and policy packages?
- FortiAnalyzer
- FortiManager
- FortiWeb
- FortiEDR
Correct Answer: 2
Explanation
FortiManager provides centralized management capabilities for multiple FortiGate devices. Administrators can organize managed devices, maintain policy packages, manage configuration changes, and deploy policies from a central platform. This can improve consistency across large deployments and reduce the need to configure every FortiGate independently. FortiManager and FortiAnalyzer have different primary roles: FortiManager focuses on management and configuration, while FortiAnalyzer focuses on log collection, analysis, and reporting. Change control is important because centralized deployments can affect many devices simultaneously.
Question 258
Which Fortinet solution is primarily associated with endpoint detection and response?
- FortiEDR
- FortiWeb
- FortiManager
- FortiAnalyzer
Correct Answer: 1
Explanation
FortiEDR is designed for endpoint detection and response capabilities. It provides security visibility and response functions at the endpoint level, helping organizations investigate suspicious endpoint activity and respond to threats. This differs from FortiGate, which primarily provides network security and firewall functions, and FortiWeb, which focuses on web application protection. Endpoint security can complement network controls by providing visibility into activity occurring directly on user or server systems. Effective deployment requires appropriate endpoint agents, policies, monitoring, and response procedures.
Question 259
Which firewall policy action prevents matching traffic from being allowed through FortiGate?
- Accept
- Deny
- Monitor
- Shape
Correct Answer: 2
Explanation
A deny action prevents matching traffic from being permitted by that firewall policy. FortiGate evaluates traffic against firewall policies according to their order and matching conditions. When a matching deny policy is reached, the traffic is not allowed through that policy. Administrators can use deny rules to restrict specific destinations, services, sources, or other traffic categories. Logging denied traffic can also help with troubleshooting and security monitoring. When investigating an unexpected denial, administrators should verify policy order, addresses, interfaces, services, schedules, and any other matching criteria.
Question 260
Which FortiGate function can provide a detailed historical record of security and traffic events when logs are sent to a centralized system?
- FortiAnalyzer
- DHCP
- VLAN
- IPsec Phase 2
Correct Answer: 1
Explanation
FortiAnalyzer can collect and analyze logs from supported Fortinet devices, providing centralized visibility into historical traffic and security events. Centralized logging allows administrators to investigate incidents, correlate activity, generate reports, and review events beyond the limited operational view available directly on an individual firewall. The usefulness of historical analysis depends on appropriate logging configuration, storage, and retention. Administrators should ensure that required FortiGate logs are generated and forwarded correctly. Access to centralized logs should also be restricted because they may contain sensitive network and security information.