View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 261
Which FortiGate feature can identify traffic based on the authenticated user rather than only the source IP address?
- Traffic shaping
- User identity
- IP pool
- VLAN
Correct Answer: 2
Explanation
User identity allows FortiGate to associate network traffic with authenticated users and apply policies based on that identity. This provides more granular access control than relying only on source IP addresses, particularly in environments where users move between devices or share network segments. FortiGate can obtain identity information through supported authentication mechanisms and integrations. Administrators can then create identity-based policies that permit or restrict access according to users or groups. Accurate identity information is important because incorrect mappings can result in unexpected policy decisions.
Question 262
Which feature can limit the number of concurrent sessions or control connection resources for selected traffic?
- FortiView
- DNS Filter
- Session-related traffic controls
- NTP
Correct Answer: 3
Explanation
FortiGate provides traffic and session controls that can help administrators manage connection resources and prevent particular traffic patterns from consuming excessive firewall capacity. Session-related controls can be useful when protecting services from excessive connection attempts or when managing resource-intensive applications. Administrators should understand the difference between session controls and bandwidth-based traffic shaping. The correct configuration depends on whether the concern involves connection counts, throughput, or application behavior. Monitoring session activity before and after configuration can help confirm that the intended traffic is being controlled.
Question 263
Which FortiGate feature allows administrators to define a reusable group of IP addresses?
- Address group
- Service group
- Policy schedule
- Performance SLA
Correct Answer: 1
Explanation
An address group combines multiple address objects into a logical collection that can be referenced by firewall policies and other supported configurations. Instead of repeatedly selecting individual addresses, administrators can reference the group when the same collection of sources or destinations is required. This simplifies policy administration and can improve consistency across multiple rules. When membership changes, every policy using that group may be affected, so administrators should review the impact before making modifications. Address groups are especially useful for organizing servers, departments, subnets, or trusted destinations.
Question 264
An administrator wants to allow HTTPS administration only from the internal management network. Which combination provides this restriction?
- DNS Filter and Web Filter
- HTTPS administrative access and trusted hosts
- Traffic shaping and IP pool
- Application Control and IPS
Correct Answer: 2
Explanation
HTTPS administrative access controls whether the HTTPS management service is available on an interface, while trusted hosts can restrict the source addresses allowed to authenticate to an administrator account. Together, these controls can significantly limit management access to approved management networks. Administrators should avoid exposing management services unnecessarily on untrusted interfaces. Additional controls such as strong authentication and appropriate administrator profiles can provide further protection. When troubleshooting access, both interface administrative-access settings and administrator trusted-host configuration should be checked because either can prevent a legitimate management connection.
Question 265
Which feature can automatically select an available WAN member when the preferred path fails an SLA requirement?
- Application Control
- VIP
- SD-WAN
- DHCP
Correct Answer: 3
Explanation
FortiGate SD-WAN can use configured performance requirements to select suitable WAN members for traffic. When an SD-WAN member fails the conditions defined by a Performance SLA, an SD-WAN rule can select another eligible path according to its configured strategy. This helps maintain connectivity when a preferred WAN link becomes degraded or unavailable. Administrators should configure meaningful health checks and ensure alternative members have appropriate routing and connectivity. SD-WAN decisions depend on the configured rules and performance criteria, so troubleshooting should include both the rule and SLA configuration.
Question 266
What does a FortiGate local-in policy primarily control?
- Traffic destined for the FortiGate itself
- Traffic between two Internet clients
- DHCP leases only
- Outbound source NAT
Correct Answer: 1
Explanation
A local-in policy controls traffic destined for services running on the FortiGate itself rather than traffic being forwarded through the firewall to another destination. This can include management access and other traffic addressed to FortiGate interfaces. Local-in policies provide an additional control layer for protecting services exposed on the FortiGate. Administrators can use them to restrict access based on sources, interfaces, services, or other supported conditions. These policies should be designed carefully because an overly restrictive configuration can unintentionally block legitimate administrative or operational access.
Question 267
Which protocol is commonly used when FortiGate needs to authenticate users against an LDAP directory?
- OSPF
- LDAP
- NTP
- BGP
Correct Answer: 2
Explanation
LDAP is a directory access protocol that FortiGate can use to communicate with supported directory services for user authentication and identity-related functions. An LDAP configuration typically includes information such as the server address, distinguished names, bind credentials when required, and authentication settings. Correct connectivity and directory permissions are necessary for successful authentication. Administrators should also verify that users and groups are located where expected in the directory structure. LDAP differs from RADIUS because LDAP directly accesses directory information, while RADIUS commonly acts as an authentication service.
Question 268
Which FortiGate feature can apply different security controls to traffic based on the firewall policy it matches?
- Security profiles
- DHCP server
- NTP
- OSPF
Correct Answer: 1
Explanation
Security profiles can be attached to firewall policies to apply specific inspection and protection functions to matching traffic. Depending on the policy and requirements, profiles can include Antivirus, IPS, Web Filter, Application Control, DNS Filter, and other security controls. Different policies can use different profile combinations based on the type of traffic being protected. This allows administrators to tailor security inspection instead of applying identical controls everywhere. The profiles must be appropriate for the traffic and inspection mode, and administrators should review logs to verify that the expected security actions are occurring.
Question 269
Which feature allows FortiGate to translate an internal server’s private address to a publicly reachable address?
- FortiView
- Traffic shaping
- VIP
- RADIUS
Correct Answer: 3
Explanation
A Virtual IP, or VIP, can provide destination address translation for services hosted on internal servers. A public-facing address and port can be mapped to the corresponding private server address and service. This allows external clients to access selected internal services without exposing the server’s private address directly. A VIP normally needs an appropriate firewall policy to permit the incoming traffic. Administrators should restrict the published service to only the required ports and sources where possible and apply suitable security inspection to reduce exposure.
Question 270
Which FortiGate function helps determine why a packet is being denied or forwarded unexpectedly?
- Packet capture
- Debug flow
- NTP
- DHCP
Correct Answer: 2
Explanation
Debug flow provides detailed information about how FortiGate processes selected traffic. It can help administrators identify policy matching, routing decisions, and other processing behavior when traffic does not behave as expected. This makes it useful for troubleshooting cases where ordinary logs do not clearly explain the problem. Administrators should filter debug flow to the relevant traffic rather than collecting unrestricted output. After obtaining the required information, debugging should be stopped. Packet capture can complement debug flow by showing the actual packets observed on an interface.
Question 271
Which feature can provide centralized visibility into logs generated by multiple FortiGate devices?
- FortiWeb
- FortiAuthenticator
- FortiManager
- FortiAnalyzer
Correct Answer: 4
Explanation
FortiAnalyzer provides centralized log collection, analysis, reporting, and event visibility for supported Fortinet devices, including FortiGate deployments. Centralizing logs makes it easier for administrators and security teams to investigate events across multiple firewalls rather than reviewing each device independently. FortiAnalyzer can also support historical analysis and reporting based on retained logs. FortiManager serves a different primary purpose by focusing on centralized device and configuration management. Proper log forwarding, storage, retention, and access controls are important for maintaining useful centralized visibility.
Question 272
Which feature is most appropriate for restricting access to a category of websites rather than a specific IP address?
- Web Filter
- BGP
- IP pool
- VLAN
Correct Answer: 1
Explanation
Web Filter is designed to control web access using URL categories and filtering rules. This makes it suitable when administrators want to restrict broad categories of websites rather than managing individual IP addresses. Category-based filtering can use FortiGuard classification services along with locally configured filtering rules. The Web Filter profile must be associated with the firewall policy handling the relevant web traffic. Administrators should verify inspection settings and FortiGuard connectivity when category filtering does not behave as expected. Logging can also help identify which filtering decision was applied.
Question 273
Which FortiGate feature can inspect DNS requests and block domains according to configured policies?
- Application Control
- DNS Filter
- Traffic shaping
- Session monitor
Correct Answer: 2
Explanation
DNS Filter examines DNS queries and can control domain access based on configured filtering policies and reputation information. It can help prevent users from reaching malicious, phishing, or otherwise restricted domains before normal application communication begins. FortiGate can use FortiGuard domain intelligence and locally configured rules to make filtering decisions. DNS Filter is particularly useful as an additional security layer alongside Web Filter and other inspection technologies. Administrators should ensure that client DNS requests are actually passing through the intended FortiGate-controlled DNS path.
Question 274
Which feature allows FortiGate to inspect encrypted traffic without fully decrypting the application payload?
- Certificate inspection
- Deep inspection
- Antivirus
- Traffic shaping
Correct Answer: 1
Explanation
Certificate inspection examines SSL/TLS certificate information and related connection details without performing full payload decryption. It can provide useful visibility into encrypted sessions while avoiding the more extensive interception performed by deep inspection. However, because the encrypted payload is not fully inspected, certificate inspection cannot provide the same level of content visibility as deep inspection. Administrators should select the inspection mode according to the required security controls and application compatibility. Certificate inspection can be useful where full decryption is unnecessary or unsuitable for specific traffic.
Question 275
Which FortiGate feature can identify the actual application generating traffic instead of relying only on TCP or UDP port numbers?
- DHCP
- Application Control
- NTP
- IP pool
Correct Answer: 2
Explanation
Application Control identifies applications by analyzing traffic characteristics and using application signatures rather than relying solely on port numbers. This is useful because applications can use dynamic, shared, or nonstandard ports that make traditional service-based filtering less effective. Administrators can use Application Control profiles to monitor or control identified applications. The feature can be combined with firewall policies and other security profiles for more granular traffic management. When application identification is unexpected, administrators should verify inspection settings and review application detection information in FortiGate monitoring tools.
Question 276
A remote employee needs secure access to internal resources through the Internet. Which solution is designed for this purpose?
- Remote-access VPN
- Web Filter
- VLAN
- Service group
Correct Answer: 1
Explanation
A remote-access VPN provides an encrypted connection between a remote user’s device and the organization’s network through an untrusted network such as the Internet. FortiGate can support remote-access VPN deployments using supported VPN technologies and authentication methods. Administrators can control which internal resources remote users may access through appropriate firewall policies and identity controls. Strong authentication is important because remote access exposes an entry point outside the organization’s physical network. VPN configuration should also consider address assignment, routing, authentication, and security policies.
Question 277
Which setting determines whether a firewall policy can perform source NAT for matching traffic?
- Policy NAT configuration
- OSPF area
- DNS Filter category
- Administrator profile
Correct Answer: 1
Explanation
Firewall policy NAT configuration determines whether matching traffic is translated as it leaves the FortiGate. When source NAT is enabled according to the policy configuration, FortiGate can translate internal source addresses using the configured NAT method. This is commonly required for private clients accessing external networks. Administrators should verify the outgoing interface, NAT configuration, and available translated addresses when troubleshooting connectivity. Source NAT changes addressing but does not encrypt traffic, so VPN technologies are required when confidentiality across an untrusted network is necessary.
Question 278
Which feature can apply a time-based restriction to a firewall policy?
- Service group
- Policy schedule
- Address group
- IPsec Phase 1
Correct Answer: 2
Explanation
A policy schedule defines when a firewall policy is active. Administrators can configure schedules that allow a policy to operate during specified times and days, supporting time-based access requirements. For example, a policy can be enabled only during business hours or during a planned maintenance window. When traffic does not match an active schedule, that policy may not be selected. Administrators troubleshooting time-dependent access should verify the configured schedule, FortiGate system time, and the order of related policies because another rule may handle the traffic.
Question 279
Which FortiGate feature can collect information about devices connected to the network for visibility and identification?
- Device detection
- NTP
- RADIUS
- VIP
Correct Answer: 1
Explanation
Device detection provides visibility into endpoints observed by FortiGate and can identify characteristics associated with connected devices. This can help administrators discover devices on network segments, investigate unexpected endpoints, and improve awareness of the environment. Detection may use available traffic information and device characteristics, so results should be interpreted appropriately rather than treated as an absolute identity guarantee. Device detection can complement network access controls and monitoring. Administrators should review detected devices regularly, particularly on networks where endpoints frequently change.
Question 280
Which FortiGate capability can provide a visual overview of top applications, sources, destinations, and traffic activity?
- FortiManager
- FortiAnalyzer
- FortiView
- FortiAuthenticator
Correct Answer: 3
Explanation
FortiView provides interactive visibility into network activity and can display information such as top applications, sources, destinations, sessions, and traffic volumes. It helps administrators quickly identify traffic patterns and investigate unusual activity directly from the FortiGate management interface. FortiView is primarily focused on operational visibility rather than centralized long-term log management. FortiAnalyzer provides broader centralized logging and reporting capabilities when historical information from multiple devices is required. Administrators can use FortiView alongside logs, session information, and diagnostic tools during network investigations.