Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 341

Which FortiGate feature can control traffic based on the destination application or service while also applying security inspection?

  1. Application Control
  2. NTP
  3. VLAN
  4. RADIUS

Correct Answer: 1

Explanation

Application Control identifies applications from network traffic and allows FortiGate to apply configured actions to them. Administrators can use application signatures and categories to monitor or restrict applications, even when traditional port-based identification is insufficient. Application Control can be combined with other security profiles on a firewall policy to provide layered inspection. When an application is not detected as expected, administrators should verify the inspection configuration, traffic flow, and available application signatures. This provides more granular application visibility than relying solely on TCP or UDP service definitions.

Question 342

Which setting determines the IP address range assigned by a FortiGate DHCP server to clients?

  1. DNS Filter
  2. DHCP address range
  3. Security profile
  4. SD-WAN rule

Correct Answer: 2

Explanation

The DHCP address range defines the pool of IP addresses that FortiGate can lease to DHCP clients. When configuring a DHCP server, administrators specify the appropriate address range along with other parameters such as the default gateway, DNS information, and lease settings. The range should belong to the correct subnet and must not overlap with statically assigned addresses or another DHCP server. If clients receive unexpected or duplicate addresses, administrators should review the DHCP configuration and network topology. Proper address planning prevents conflicts and improves reliable client connectivity.

Question 343

Which feature can determine whether a FortiGate interface should accept administrative HTTPS connections?

  1. Performance SLA
  2. Service group
  3. Administrative access settings
  4. IP pool

Correct Answer: 3

Explanation

Administrative access settings determine which management services are enabled on FortiGate interfaces. HTTPS can be enabled on an appropriate management interface so administrators can access the FortiGate graphical interface securely. Organizations should avoid enabling management services on interfaces where they are unnecessary, especially interfaces exposed to untrusted networks. Administrative access settings work together with trusted hosts, administrator authentication, and administrator profiles. If an administrator cannot connect through HTTPS, the interface’s administrative access configuration should be checked along with network reachability and any local-in restrictions.

Question 344

Which security control can restrict management access to the FortiGate itself rather than forwarded traffic?

  1. Local-in policy
  2. Web Filter
  3. Application Control
  4. IP pool

Correct Answer: 1

Explanation

A local-in policy controls traffic destined for the FortiGate itself. This differs from ordinary firewall policies, which primarily control traffic passing through FortiGate toward another network destination. Local-in policies can be used to restrict access to services exposed on FortiGate interfaces, including management services. Administrators can define permitted sources, interfaces, and services to reduce exposure. Because these policies directly affect access to the firewall, they should be configured carefully and tested before deployment to avoid unintentionally blocking legitimate administrative connections.

Question 345

A FortiGate administrator needs to determine whether a route exists for a remote subnet. What should be checked?

  1. Web Filter categories
  2. Routing table
  3. FortiToken status
  4. Antivirus profile

Correct Answer: 2

Explanation

The routing table shows the routes currently available to FortiGate and helps determine how traffic toward a destination will be forwarded. When a remote subnet cannot be reached, administrators should verify that an appropriate route exists and points toward the correct next hop or interface. They should also consider route preference when multiple routes are available. If policy-based routing is configured, it should be reviewed as well because it can influence forwarding decisions. Routing should be confirmed before investigating higher-level security controls when basic connectivity is failing.

Question 346

Which feature can collect security logs from FortiGate devices for centralized investigation?

  1. FortiManager
  2. FortiWeb
  3. FortiAnalyzer
  4. FortiAuthenticator

Correct Answer: 3

Explanation

FortiAnalyzer provides centralized collection and analysis of logs generated by supported Fortinet devices. Security teams can use it to investigate historical events, correlate activity, review traffic information, and generate reports. Centralized logging is especially useful when an organization operates multiple FortiGate devices because events can be reviewed from a common platform. FortiManager has a different primary role focused on configuration and policy management. Administrators should configure appropriate log forwarding, retention, and access controls to ensure that important security information remains available for investigation.

Question 347

Which FortiGate feature allows different firewall policies to use different inspection profiles?

  1. Security profiles
  2. NTP
  3. VLAN interface
  4. BGP

Correct Answer: 1

Explanation

Security profiles can be attached to individual firewall policies, allowing administrators to apply different inspection controls to different traffic flows. One policy might use Antivirus and IPS, while another could additionally use Web Filter or Application Control according to its traffic requirements. This provides flexibility because not all traffic requires identical inspection. Administrators should ensure that the selected profiles are appropriate for the policy and inspection mode. Reviewing security-profile logs can help determine whether traffic was blocked by a specific inspection feature after being permitted by the firewall policy.

Question 348

Which feature can authenticate a user with a one-time password generated by a token?

  1. VLAN
  2. FortiToken MFA
  3. OSPF
  4. Traffic shaping

Correct Answer: 2

Explanation

FortiToken-based multi-factor authentication can provide a one-time password as an additional authentication factor. The token can be used alongside a normal password to strengthen authentication for supported FortiGate access scenarios. This reduces reliance on a password alone because an attacker who obtains the password would still need the additional authentication factor. Administrators must correctly enroll tokens, associate them with users, and configure the relevant authentication method. Token synchronization, enrollment status, and user configuration should be checked when one-time-password authentication fails.

Question 349

Which FortiGate capability can inspect the contents of encrypted HTTPS sessions when configured appropriately?

  1. Certificate inspection
  2. Deep inspection
  3. Traffic shaping
  4. Policy schedule

Correct Answer: 2

Explanation

Deep inspection allows FortiGate to decrypt and inspect supported encrypted traffic so that security profiles can analyze the application payload. This provides substantially more visibility than certificate inspection, which examines certificate and connection information without full payload decryption. Deep inspection requires careful certificate deployment because clients generally need to trust the inspection certificate. Administrators should also consider privacy, application compatibility, and appropriate exemptions. When deep inspection is enabled, security profiles such as Antivirus, IPS, Web Filter, or Application Control can gain greater visibility into protected traffic.

Question 350

Which FortiGate feature can determine whether a WAN member is meeting configured performance thresholds?

  1. Performance SLA
  2. Address group
  3. Administrator profile
  4. Service object

Correct Answer: 1

Explanation

A Performance SLA evaluates the condition of an SD-WAN member using configured health checks and performance thresholds. Depending on the configuration, measurements can include latency, jitter, packet loss, and availability. The results can be used by SD-WAN rules when selecting an appropriate path for traffic. Administrators should configure targets that reflect the requirements of the applications being protected. If an SLA frequently fails, the underlying WAN connection should also be investigated rather than simply increasing thresholds without understanding the cause of poor performance.

Question 351

Which protocol is primarily responsible for resolving hostnames into IP addresses?

  1. DNS
  2. NTP
  3. LDAP
  4. RADIUS

Correct Answer: 1

Explanation

The Domain Name System, or DNS, translates hostnames into IP addresses and supports other types of name-resolution information. Network devices and clients use DNS to locate services and destinations by name rather than requiring users to remember numerical addresses. FortiGate can use configured DNS servers for its own resolution and can also provide DNS-related security functions through features such as DNS Filter. When name-based connections fail while direct IP connectivity works, administrators should investigate DNS configuration, reachability, and filtering policies.

Question 352

Which FortiGate feature can group multiple interfaces into a common logical policy object?

  1. VLAN
  2. Interface zone
  3. IP pool
  4. Traffic selector

Correct Answer: 2

Explanation

An interface zone allows multiple interfaces to be grouped for policy configuration. This can simplify firewall policies when several interfaces have similar security requirements and should be treated as a common logical group. Instead of creating separate policies for every interface, administrators can reference the zone where appropriate. However, grouping interfaces can broaden the scope of a policy, so all interfaces within the zone should have compatible security requirements. Careful interface organization and clear naming help prevent accidental access between networks that should remain separated.

Question 353

What does administrative distance help FortiGate determine?

  1. Which security profile scans a file
  2. Which route source is preferred
  3. Which DNS category is blocked
  4. Which administrator can log in

Correct Answer: 2

Explanation

Administrative distance indicates the preference of routes learned from different routing sources. When multiple routing sources provide routes toward the same destination, administrative distance helps determine which source should be preferred before protocol-specific route-selection factors are considered. This allows administrators to establish relationships between static and dynamic routing information. It should not be confused with a routing protocol’s internal metric. When FortiGate selects an unexpected route, administrators should review available routes, their sources, administrative distances, and any policy-based routing configuration that may affect forwarding.

Question 354

Which FortiGate feature can identify a website category using FortiGuard information?

  1. Web Filter
  2. DHCP
  3. BGP
  4. IPsec Phase 2

Correct Answer: 1

Explanation

Web Filter can use FortiGuard web-category information to classify websites and enforce configured access policies. Administrators can allow, block, monitor, or otherwise handle categories according to organizational requirements. This provides broad web-access control without requiring administrators to manually maintain every website address. The Web Filter profile must be applied to the appropriate firewall policy, and required FortiGuard connectivity should be available. If categorization appears incorrect or unavailable, administrators should review the filtering configuration, inspection method, and FortiGuard service status.

Question 355

Which IPsec setting controls the encryption and authentication proposals negotiated for protected traffic?

  1. DHCP options
  2. Phase 2 proposal
  3. Web Filter category
  4. Administrator profile

Correct Answer: 2

Explanation

The IPsec Phase 2 proposal defines the cryptographic parameters used to protect data traffic within the VPN security association. Depending on the configuration, it can specify supported encryption and authentication algorithms. The VPN peers must have compatible proposals for successful Phase 2 negotiation. If Phase 1 is established but the tunnel does not successfully negotiate protected traffic, administrators should compare Phase 2 proposals along with traffic selectors and other settings. Strong and compatible cryptographic settings should be selected according to the organization’s security requirements and supported FortiOS configuration.

Question 356

Which FortiGate feature can provide a public-to-private port mapping for a specific service?

  1. FortiView
  2. VIP with port forwarding
  3. NTP
  4. OSPF

Correct Answer: 2

Explanation

A VIP with port forwarding can map a public destination address and port to a specific private server address and port. This is commonly used to publish selected internal services such as web applications to external clients. Administrators should create a corresponding firewall policy that permits only the required traffic and should avoid exposing unnecessary services. Security profiles can provide additional inspection where appropriate. When troubleshooting port-forwarding problems, administrators should verify the VIP mapping, external and internal ports, firewall policy, routing, and whether the internal server is actually listening on the expected service.

Question 357

Which FortiGate function can display information about traffic currently passing through the firewall?

  1. FortiView
  2. LDAP
  3. IP pool
  4. Policy schedule

Correct Answer: 1

Explanation

FortiView provides interactive visibility into traffic and security activity on FortiGate. It can display information about sources, destinations, applications, sessions, bandwidth, and other traffic characteristics depending on the available data and view. This helps administrators quickly identify traffic patterns and investigate unusual activity. FortiView is primarily a monitoring and visualization capability rather than a replacement for detailed packet diagnostics. When deeper analysis is required, administrators can combine FortiView information with session monitoring, traffic logs, policy lookup, packet capture, or debug flow.

Question 358

Which FortiGate feature can limit bandwidth consumed by a particular class of traffic?

  1. Traffic shaping
  2. DNS Filter
  3. FortiToken
  4. LDAP

Correct Answer: 1

Explanation

Traffic shaping controls how bandwidth is allocated to selected network traffic. Administrators can use shaping policies or profiles to limit bandwidth consumption or prioritize important traffic according to business requirements. This can prevent bandwidth-intensive applications from consuming resources needed by critical services. Traffic shaping should be configured according to the actual capacity of the WAN or network link. Administrators should monitor traffic before and after applying shaping rules to verify that the configured limits produce the expected result without unnecessarily degrading legitimate business applications.

Question 359

Which FortiGate feature can provide centralized authentication services and identity integration for network users?

  1. FortiManager
  2. FortiAuthenticator
  3. FortiAnalyzer
  4. FortiWeb

Correct Answer: 2

Explanation

FortiAuthenticator provides centralized identity and authentication services for Fortinet environments. It can integrate with supported identity sources and authentication mechanisms, allowing organizations to centralize user authentication rather than maintaining separate authentication systems on individual network devices. It can also support token-based authentication and related identity functions depending on the deployment. When integrated with FortiGate, administrators need appropriate connectivity and authentication configuration. Centralized identity services can simplify access management while supporting more consistent authentication and authorization policies across the network.

Question 360

Which FortiGate diagnostic command can help administrators inspect the routing table from the CLI?

  1. get router info routing-table all
  2. diagnose debug application ssl
  3. execute backup config
  4. get system status

Correct Answer: 1

Explanation

The get router info routing-table all command displays routing-table information from the FortiGate CLI. Administrators can use it to examine routes, their associated interfaces, gateways, and other routing information when troubleshooting connectivity. It is particularly useful when determining whether FortiGate has a valid path toward a destination. If routing appears correct but traffic still fails, administrators can continue with policy lookup, debug flow, packet capture, and security-profile logs. Understanding the routing table is an important part of systematic FortiGate connectivity troubleshooting.