View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 281
Which FortiGate feature can use multiple WAN connections to improve application availability?
- SD-WAN
- DNS Filter
- FortiToken
- Address group
Correct Answer: 1
Explanation
FortiGate SD-WAN allows multiple WAN links to be managed as a logical set of network paths. Administrators can define rules that select suitable members based on application requirements, link availability, and measured performance. This can improve resilience because traffic can be directed toward another eligible WAN path when a preferred connection becomes unavailable or fails configured performance conditions. SD-WAN is more than simple load balancing because decisions can incorporate application and SLA criteria. Correct member configuration, health checks, and SD-WAN rules are essential for predictable behavior.
Question 282
A business application requires a WAN path with low delay and minimal packet loss. Which configuration should be considered?
- Web Filter
- Performance SLA with an SD-WAN rule
- Administrator profile
- Service group
Correct Answer: 2
Explanation
A Performance SLA can measure WAN characteristics such as latency and packet loss, while an SD-WAN rule can use those measurements when selecting a suitable path. This combination allows administrators to match application traffic with WAN links that meet defined performance requirements. For example, a business application that is sensitive to delay can be directed toward a path with acceptable latency and loss thresholds. Administrators should configure realistic SLA targets and ensure that the SD-WAN rule identifies the intended traffic. Monitoring results helps validate that the expected path is selected.
Question 283
Which protocol provides secure key exchange and peer authentication for an IPsec VPN?
- IKE
- DHCP
- OSPF
- LDAP
Correct Answer: 1
Explanation
Internet Key Exchange, or IKE, negotiates security parameters and authenticates peers during IPsec VPN establishment. IKE Phase 1 establishes a secure management channel between the VPN endpoints, while subsequent negotiation can establish the IPsec security associations used to protect data. FortiGate supports configurable IKE parameters such as authentication methods, encryption proposals, and Diffie-Hellman groups. Both VPN peers need compatible settings for successful negotiation. When troubleshooting an IPsec tunnel that does not establish, administrators should first examine Phase 1 parameters, peer reachability, and authentication configuration.
Question 284
Which IPsec phase establishes the security association used to protect the actual user data?
- Phase 1
- Phase 2
- IKE authentication
- NAT traversal
Correct Answer: 2
Explanation
IPsec Phase 2 negotiates the security association used to protect actual data traffic across the VPN. It establishes parameters such as encryption and authentication algorithms and defines traffic selectors for the protected networks. Phase 2 depends on a successful Phase 1 negotiation, because the secure IKE channel established earlier is used for subsequent negotiation. If Phase 1 is established but traffic still does not pass, administrators should examine Phase 2 settings, selectors, routing, and firewall policies. Compatible configuration between both VPN peers is required.
Question 285
Which FortiGate object is commonly used to represent a specific TCP or UDP service in a firewall policy?
- Address object
- Service object
- Schedule object
- User group
Correct Answer: 2
Explanation
A service object defines a network service, commonly by specifying protocols and associated ports. FortiGate firewall policies use service objects to determine which types of traffic are permitted or denied. Administrators can use predefined services or create custom service objects when applications require specific ports. Service objects can also be combined into service groups when several services need to be referenced together. When troubleshooting a policy that does not match expected traffic, administrators should verify the protocol and port definitions because an incorrect service object can prevent legitimate traffic from matching.
Question 286
Which feature can group several address objects into a single reusable policy reference?
- Service group
- Address group
- Performance SLA
- Policy schedule
Correct Answer: 2
Explanation
An address group combines multiple address objects into one logical group that can be referenced by firewall policies. This reduces repetitive configuration when the same collection of hosts, networks, or destinations is needed in several policies. For example, multiple internal server addresses can be grouped and referenced as a single destination. Administrators should manage group membership carefully because changing the group can affect all policies that reference it. Clear naming and organization of address objects and groups can also make large policy sets easier to review and maintain.
Question 287
Which firewall policy component determines the source interface from which traffic must arrive?
- Incoming interface
- Service
- Schedule
- NAT
Correct Answer: 1
Explanation
The incoming interface specifies the interface or interface group from which traffic must enter FortiGate for a firewall policy to match. This allows administrators to create policies based on the network segment or security zone where traffic originates. The outgoing interface separately identifies where matching traffic is expected to leave. Interface matching works together with addresses, services, schedules, users, and other policy criteria. When troubleshooting a policy that is not matching, administrators should verify that traffic actually enters through the interface specified in the policy.
Question 288
Which firewall policy component specifies where matching traffic is expected to leave FortiGate?
- Source address
- Outgoing interface
- User group
- Security profile
Correct Answer: 2
Explanation
The outgoing interface identifies the interface through which traffic matched by the firewall policy is expected to leave FortiGate. It is an important part of the policy’s traffic definition because the same source and destination addresses may be reachable through different interfaces in a complex network. The outgoing interface is typically associated with the routing decision and expected destination path. If a policy does not match or traffic is forwarded incorrectly, administrators should verify routing as well as the incoming and outgoing interface definitions.
Question 289
Why is firewall policy order important on FortiGate?
- Policies are evaluated according to their configured order
- Policies are selected randomly
- Only the last policy is evaluated
- Policy order affects NTP synchronization only
Correct Answer: 1
Explanation
Firewall policy order is important because FortiGate evaluates policies according to their configured sequence and uses the first applicable matching policy. If a broad policy appears before a more specific policy, traffic may match the broad rule before reaching the intended specific rule. This can result in unexpected access or security behavior. Administrators should place more specific policies appropriately and regularly review rule ordering. Policy lookup and traffic logs can help determine which policy handled a connection when troubleshooting unexpected firewall behavior.
Question 290
A user reports that a permitted connection is being blocked. Which tool can help identify whether the expected firewall policy is matching?
- Policy lookup
- NTP
- DHCP
- FortiToken
Correct Answer: 1
Explanation
Policy lookup can help determine which firewall policy corresponds to specified traffic characteristics. It is useful when administrators suspect that traffic is matching a different rule than expected or when a policy appears to permit traffic but the connection is blocked. The administrator can examine relevant source, destination, interface, and service information to identify the expected policy. Policy lookup does not replace routing or packet-level troubleshooting, so additional investigation may be necessary. Logs and debug flow can provide further information when the cause remains unclear.
Question 291
Which FortiGate diagnostic tool can display the path selected by the routing table for a destination?
- Routing table lookup
- Web Filter
- Application Control
- FortiToken
Correct Answer: 1
Explanation
Routing table lookup allows administrators to examine how FortiGate determines the route toward a destination. The routing table contains learned and configured routes and their associated interfaces or gateways. Reviewing it can help identify missing routes, unexpected next hops, or competing routes with different preferences. Routing information is especially important when a firewall policy permits traffic but the destination remains unreachable. Administrators should also consider policy-based routing because it can influence forwarding decisions beyond the standard routing table. Route verification is a fundamental step in connectivity troubleshooting.
Question 292
Which routing concept determines which route is preferred when multiple routes to the same destination are available from different sources?
- Administrative distance
- DNS reputation
- Security profile
- Service group
Correct Answer: 1
Explanation
Administrative distance is used to determine the relative preference of routes learned from different routing sources. When multiple routes are available for the same destination, the route with the more preferred administrative distance can be selected, subject to the routing system’s complete decision process. This allows administrators to establish preferences between static routes and dynamic routing protocols. Administrative distance should not be confused with routing metrics used within a particular protocol. When troubleshooting unexpected route selection, administrators should review both route sources and their associated preference values.
Question 293
Which feature can apply security inspection to traffic after a firewall policy permits it?
- Security profile
- VLAN
- IP pool
- OSPF area
Correct Answer: 1
Explanation
Security profiles provide additional inspection and security controls for traffic handled by a firewall policy. Depending on the profile and traffic type, FortiGate can apply functions such as Antivirus, IPS, Web Filter, Application Control, and DNS Filter. The firewall policy determines which traffic is handled, while the attached security profiles provide additional inspection or enforcement. Administrators should select profiles according to the security requirements of the traffic and the inspection mode being used. Logs from individual security profiles can help identify why permitted traffic was subsequently blocked.
Question 294
Which feature can prevent unauthorized devices from gaining access to a protected network based on network access control policies?
- NAC
- NTP
- VIP
- Service group
Correct Answer: 1
Explanation
Network Access Control, or NAC, helps organizations control which devices are allowed to access protected network resources. NAC solutions can use information about device identity, status, or network behavior to apply access decisions and may place devices into appropriate network segments or restricted states. In Fortinet environments, NAC capabilities can work with network security and endpoint visibility mechanisms. The exact workflow depends on the deployment and integrated components. NAC is particularly useful for controlling unmanaged, unknown, or potentially compromised devices before they receive normal network access.
Question 295
Which FortiGate interface type can represent a logical connection to a VLAN?
- VLAN interface
- Loopback only
- IP pool
- Service group
Correct Answer: 1
Explanation
A VLAN interface provides a logical Layer 3 interface associated with a specific VLAN identifier. FortiGate can use VLAN interfaces to route traffic between VLAN segments and apply firewall policies to communication between them. The VLAN ID and parent interface must correspond to the connected network design, such as a switch trunk carrying the appropriate tagged traffic. VLAN interfaces are useful for network segmentation because different logical networks can receive separate policies. Administrators should verify tagging, interface configuration, addressing, and routing when troubleshooting VLAN connectivity.
Question 296
Which feature can provide an interface for managing FortiGate separately from normal production traffic?
- Dedicated management interface
- Application Control
- Web Filter
- IPsec Phase 2
Correct Answer: 1
Explanation
A dedicated management interface provides a separate network path for administrative access to FortiGate. Separating management traffic from production traffic can reduce exposure and simplify administrative access control. Organizations can restrict the management interface to approved administrators and management networks while disabling unnecessary administrative services elsewhere. Depending on the FortiGate model and configuration, management interfaces may have specific operational characteristics. Administrators should still apply strong authentication, trusted hosts, and appropriate management-service restrictions because a dedicated interface does not eliminate the need for access controls.
Question 297
Which authentication method requires the user to provide a physical or software-based token in addition to other credentials?
- Password-only authentication
- Multi-factor authentication
- Anonymous authentication
- Guest access
Correct Answer: 2
Explanation
Multi-factor authentication requires multiple authentication factors, commonly combining something the user knows, such as a password, with something the user has, such as a security token. Fortinet environments can integrate FortiToken-based authentication with supported FortiGate authentication workflows. MFA provides additional protection because a compromised password alone may not be sufficient to authenticate successfully. Administrators should configure token enrollment, authentication policies, and recovery procedures carefully. MFA is particularly useful for protecting privileged administrative access and remote-access services exposed beyond the organization’s trusted network.
Question 298
Which FortiGate feature can record administrative actions for later review?
- Administrative event logging
- Traffic shaping
- SD-WAN rule
- Address group
Correct Answer: 1
Explanation
Administrative event logging records actions and events associated with management activity on FortiGate. These logs can help organizations review configuration changes, authentication events, and other administrative activity. Centralized logging can provide additional retention and analysis capabilities when administrative events are forwarded to an appropriate logging platform. Reviewing administrative logs supports accountability and troubleshooting, especially when unexpected configuration changes occur. Organizations should protect log access and retain relevant events according to their operational and security requirements.
Question 299
Which FortiGate monitoring feature provides information about active connections without requiring historical log analysis?
- Session monitor
- FortiAnalyzer
- Web Filter
- FortiAuthenticator
Correct Answer: 1
Explanation
The session monitor provides information about currently active connections handled by FortiGate. It allows administrators to inspect live session details and can help identify active communication between sources and destinations. This is different from FortiAnalyzer, which is primarily used for centralized log storage, analysis, and historical reporting. Session information is particularly useful when troubleshooting a connection that is currently occurring. Administrators can combine session monitoring with policy lookup, routing information, and debug flow to obtain a more complete view of how FortiGate is handling traffic.
Question 300
Which FortiGate feature can identify whether traffic matches a particular security policy before troubleshooting deeper packet-processing details?
- Policy lookup
- Packet capture
- NTP
- DHCP
Correct Answer: 1
Explanation
Policy lookup provides a practical way to determine which firewall policy should match specified traffic characteristics. It can help administrators validate policy configuration before moving to more detailed diagnostic tools such as debug flow or packet capture. By checking interfaces, addresses, services, and other relevant criteria, administrators can identify whether the expected rule is positioned and configured correctly. If policy lookup shows the expected rule but traffic still fails, further investigation should examine routing, NAT, security profiles, and packet processing. This creates a logical troubleshooting sequence.