View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 161. Which prerequisites are required for FortiClient Video Filter to operate on a managed endpoint?
- Application Firewall and FortiSandbox only
- Vulnerability Scan and Remote Access profiles
- FortiAnalyzer logging and SSL VPN
- Web Filter plus the web browser plug-in for web filtering
Correct Answer: 4. Web Filter plus the web browser plug-in for web filtering
Explanation:
FortiClient Video Filter depends on the Web Filter functionality. Fortinet states that the Web Filter profile must be enabled and Enable Web Browser Plugin for Web Filtering must also be enabled. In addition, the endpoint must be able to reach the appropriate Fortinet video-query service. macOS and Linux endpoints have an additional HTTPS deep-inspection requirement. Video Filter is therefore not a completely independent endpoint feature; it builds on browser and web-filtering components to identify and enforce YouTube video policies. Administrators should verify these prerequisites before troubleshooting category or override behavior.
Question 162. What additional requirement applies to FortiClient Video Filter on macOS and Linux endpoints?
- FortiClient must operate in standalone mode
- Enable HTTPS Deep Inspection
- Disable the browser plug-in
- Configure an IPsec VPN
Correct Answer: 2. Enable HTTPS Deep Inspection
Explanation:
Fortinet documents an additional requirement for Video Filter on macOS and Linux: Enable HTTPS Deep Inspection must be enabled. The feature also requires Web Filter and the web browser plug-in used for web filtering. This platform-specific requirement is important in mixed operating-system environments because a configuration that works on Windows may not produce the expected filtering results on macOS or Linux without the additional HTTPS inspection setting. When Video Filter appears properly assigned through EMS but fails only on certain platforms, administrators should compare platform-specific prerequisites before modifying category or override policies.
Question 163. Which set lists valid FortiClient Video Filter category actions?
- Block, Warn, Allow, and Monitor
- Route, NAT, Drop, and Proxy
- Encrypt, Decrypt, Archive, and Restore
- Install, Upgrade, Repair, and Delete
Correct Answer: 1. Block, Warn, Allow, and Monitor
Explanation:
FortiClient Video Filter allows administrators to configure an action for YouTube video categories. Supported category actions include Block, Warn, Allow, and Monitor. This gives organizations flexibility beyond a simple allow-or-deny model. For example, Monitor can provide visibility without interrupting access, while Warn can inform the user before permitting access. Categories include areas such as Knowledge, Business, Entertainment, Music, Sports, Games, and News. Administrators can supplement category filtering with channel and individual-video overrides when more granular exceptions are required.
Question 164. An administrator blocks a YouTube channel but creates an Allow override for one video belonging to that channel. What happens?
- The individual video override always takes priority
- FortiClient displays the video but disables audio
- The channel-level Block takes precedence, so the video remains blocked
- The video is sent to FortiSandbox for a verdict
Correct Answer: 3. The channel-level Block takes precedence, so the video remains blocked
Explanation:
FortiClient Video Filter supports both channel and specific-video override lists, but their precedence is important. Fortinet states that when a YouTube channel is blocked and an administrator separately allows a specific video from that blocked channel, FortiClient still blocks the video. The action configured for the channel overrides the action configured for the individual video. This prevents administrators from assuming that a more specific video rule always wins. Understanding precedence is especially important when troubleshooting why a supposedly allowed video remains inaccessible even though its individual URL appears in the Video Override List.
Question 165. What happens when YouTube Safe Search is configured in both the Web Filter profile and the Video Filter profile?
- Safe Search is disabled because the profiles conflict
- The more restrictive setting is applied
- Only the Web Filter setting is used
- Only the Video Filter setting is used
Correct Answer: 2. The more restrictive setting is applied
Explanation:
YouTube Safe Search can be enabled in both Web Filter and Video Filter configurations. When both profiles contain Safe Search settings, Fortinet states that the more restrictive setting is applied. Safe Search can be configured with restriction levels such as Strict or Moderate and helps limit the YouTube content available to endpoint users. This behavior prevents a less restrictive configuration in one profile from weakening a stronger setting in another. Administrators managing overlapping profiles should therefore review both configurations when users report that YouTube restrictions are stricter than expected.
Question 166. What can FortiClient Video Filter do when it cannot reach the FortiGuard server for a YouTube rating?
- It must always allow the video
- It automatically disables Video Filter
- It shuts down the browser
- Apply the administrator-selected unreachable-server action, such as Block, Warn, Allow, or Monitor
Correct Answer: 4. Apply the administrator-selected unreachable-server action, such as Block, Warn, Allow, or Monitor
Explanation:
Video Filter includes a configurable Traffic Action When FortiGuard Server is Unreachable for Rating setting. Administrators can choose Block, Warn, Allow, or Monitor. This lets the organization decide whether video access should fail closed, remain available, or generate monitoring information when FortiGuard rating services cannot be reached. The best choice depends on the organization’s risk tolerance and availability requirements. A strict environment may select Block, while an environment prioritizing uninterrupted user access might choose another action. FortiGuard connectivity should still be investigated if unreachable events occur frequently.
Question 167. What information does FortiClient send to EMS for Software Inventory?
- Installed application information, including details such as vendor and version
- Only Windows Event Viewer security logs
- Only VPN connection history
- Only antivirus signature versions
Correct Answer: 3. Installed application information, including details such as vendor and version
Explanation:
FortiClient Software Inventory gives EMS centralized visibility into applications installed on managed endpoints. Inventory information includes application names and details such as vendor and version. Administrators can analyze the information from application-oriented or host-oriented views. This capability is useful for software auditing, identifying outdated applications, investigating unauthorized software, and understanding application distribution across the endpoint population. FortiClient initially sends inventory when it registers to EMS and later reports changes when applications are installed, updated, or removed. The Software Inventory capability requires an EPP license.
Question 168. When does FortiClient initially send Software Inventory information to EMS?
- When FortiClient first registers to EMS
- Only after the first vulnerability scan
- Only after FortiAnalyzer requests it
- Once every calendar year
Correct Answer: 1. When FortiClient first registers to EMS
Explanation:
FortiClient sends its installed-application information to EMS when the endpoint first registers. This provides EMS with an initial software baseline for the newly managed endpoint. After that, FortiClient sends updated inventory when relevant application changes occur, including software installation, update, or removal. EMS can also forward Software Inventory logs to FortiAnalyzer for real-time and historical reporting. Because inventory begins at registration, administrators should verify successful FortiClient-to-EMS onboarding when a new endpoint appears in management but its expected Software Inventory is missing.
Question 169. Which event causes FortiClient to update its Software Inventory information in EMS?
- Only an EMS server reboot
- Only a user VPN login
- Only a FortiGate firmware upgrade
- Installing, updating, or removing software on the endpoint
Correct Answer: 4. Installing, updating, or removing software on the endpoint
Explanation:
Software Inventory is not limited to the endpoint’s initial registration. FortiClient monitors application changes and sends updated inventory information to EMS when software is installed, updated, or removed. EMS can then forward those changes to FortiAnalyzer for historical and real-time reporting if that integration is configured. This helps administrators maintain a more current view of endpoint software instead of relying on a one-time snapshot. Inventory updates can support software auditing, license review, compliance checks, and investigation of newly introduced potentially unwanted applications.
Question 170. Where should an EMS administrator go to view software installed on one specific managed endpoint?
- Security Posture Tag Monitor
- Software Inventory > Hosts
- Deployment & Installers only
- Administration > Admin Roles
Correct Answer: 1. Software Inventory > Hosts
Explanation:
The Software Inventory > Hosts view organizes application information by managed endpoint. Administrators can select a host and use View Details to see the applications installed on that particular device. The Hosts view can display information including hostname, user, operating system, IP address, application count, and the date of the most recent software installation. Administrators can also filter hosts using attributes such as hostname, username, OS, and IP address. This view is therefore appropriate when the investigation begins with a particular endpoint rather than with a specific application.
Question 171. Which information can the Software Inventory Applications view provide for an installed application?
- Only its executable file size
- Application name, vendor, version, installation count, and potentially its PUA category
- Only its FortiGate policy ID
- Only the endpoint’s VPN username
Correct Answer: 2. Application name, vendor, version, installation count, and potentially its PUA category
Explanation:
The Software Inventory Applications view provides centralized information about software detected across managed endpoints. Fields can include the application name, vendor, version, first detected date, last installed date, installation count, and potentially unwanted application category. EMS can identify PUA categories such as cryptomining, hacking, phishing, malicious, or other classifications when applicable. Administrators can display applications alphabetically or by vendor and filter the inventory using application name, vendor, and version. Inventory information can also be exported as CSV data for software audits or compliance activities.
Question 172. How does FortiOS receive EMS dynamic endpoint groups for use in dynamic firewall policies?
- Through a FortiClient EMS Fabric connector
- Through DHCP option 43
- Through an email connector
- Through a local FortiClient installer file
Correct Answer: 3. Through a FortiClient EMS Fabric connector
Explanation:
After security posture tagging rules are defined in EMS, FortiOS can receive resulting dynamic endpoint groups through the FortiClient EMS Fabric connector. The connector supports SSL and imports trusted certificates. When endpoint membership in a dynamic group changes, EMS sends the updated information to FortiOS, allowing FortiOS to update corresponding dynamic policies. This supports context-aware network access based on endpoint status rather than relying only on static IP addresses or user-defined firewall objects. It is a key integration point between EMS endpoint posture assessment and FortiGate network enforcement.
Question 173. What happens on FortiOS when EMS reports that an endpoint has entered or left a dynamic endpoint group?
- FortiOS can update its dynamic policies based on the changed group membership
- FortiOS automatically upgrades its firmware
- EMS deletes the FortiClient deployment package
- FortiAnalyzer disables endpoint logging
Correct Answer: 1. FortiOS can update its dynamic policies based on the changed group membership
Explanation:
EMS security posture rules create dynamic endpoint group membership based on endpoint condition. When an endpoint is added to or removed from a group, EMS sends the change to connected FortiOS devices. FortiOS then updates applicable dynamic firewall policies, allowing network access to respond to endpoint posture changes. For example, a compliant endpoint could receive access that is later removed when the device no longer meets required security conditions. This design allows automated enforcement without manually editing firewall objects each time an endpoint’s security state changes.
Question 174. For FortiOS dynamic policy enforcement using EMS endpoint information, what defines a directly connected endpoint?
- Any endpoint located in the same country as FortiGate
- An endpoint that has FortiGate as its default gateway
- Any endpoint that has FortiClient installed
- An endpoint connected only to FortiAnalyzer
Correct Answer: 3. An endpoint that has FortiGate as its default gateway
Explanation:
Fortinet states that, for the described dynamic endpoint group enforcement, FortiOS receives endpoint information and enforces compliance for directly connected endpoints. A directly connected endpoint is one that uses the FortiGate as its default gateway. This distinction matters because simply running FortiClient does not automatically mean an endpoint is directly attached to a FortiGate for this enforcement workflow. The feature can also operate for compatible VPN-connected endpoints provided they can access EMS and meet compatibility requirements. Administrators should understand the endpoint’s traffic path when diagnosing dynamic-policy enforcement.
Question 175. Which statement correctly describes FortiClient EMS standalone deployment mode?
- It requires FortiGate HA
- FortiClient cannot receive security posture tagging rules
- It supports only unmanaged FortiClient endpoints
- EMS can deploy, configure, monitor, and dynamically group FortiClient endpoints without requiring a FortiGate
Correct Answer: 4. EMS can deploy, configure, monitor, and dynamically group FortiClient endpoints without requiring a FortiGate
Explanation:
FortiClient EMS supports both Security Fabric and standalone deployment models. In standalone mode, a FortiGate is not required. FortiClient endpoints connect to EMS through Telemetry, receive configuration from EMS, and can receive security posture tagging rules. EMS uses the resulting posture information to dynamically organize endpoints and continues to provide deployment, configuration, and monitoring functions. Security Fabric deployment adds FortiGate integration, dynamic firewall policy enforcement, and NAC-related functionality, but FortiClient EMS itself remains fully useful as a centralized endpoint-management platform in standalone environments.
Question 176. What does enabling “Sign Software Packages” in EMS do?
- Encrypts all FortiClient network traffic
- Digitally signs Windows FortiClient installers created by or uploaded to EMS using a configured code-signing certificate
- Automatically licenses every endpoint
- Signs FortiGate firmware images
Correct Answer: 2. Digitally signs Windows FortiClient installers created by or uploaded to EMS using a configured code-signing certificate
Explanation:
The Sign Software Packages setting allows EMS to digitally sign Windows FortiClient installers that EMS creates or receives. Administrators configure a code-signing certificate and its password, and can also specify a timestamp server. Signed installers can display the configured publisher identity to Windows, helping users and operating systems verify that the installer came from the expected source and has not been modified after signing. This setting applies to Windows FortiClient software installers; it does not replace endpoint licensing, EMS certificates used for HTTPS, or FortiClient Telemetry encryption.
Question 177. In EMS 7.4 documentation, which certificate format is specified for the code-signing certificate used by “Sign Software Packages”?
- .pfx
- .txt
- .csv
- .iso
Correct Answer: 3. .pfx
Explanation:
Fortinet’s EMS 7.4 documentation specifies a .pfx certificate file for software-package code signing. The administrator uploads the certificate and provides the associated certificate password so EMS can digitally sign Windows FortiClient installers. EMS also displays the certificate’s expiration date, which administrators should monitor to avoid signing problems caused by an expired certificate. This code-signing certificate serves a different purpose from the EMS HTTPS server certificate or the EMS CA used in ZTNA workflows, so administrators should avoid confusing these separate certificate functions.
Question 178. What is the purpose of configuring a timestamp server when EMS signs FortiClient software packages?
- To assign endpoint IP addresses
- To provide timestamping for digitally signed software installers
- To synchronize Web Filter schedules
- To control FortiClient Telemetry keep-alive timers
Correct Answer: 1. To provide timestamping for digitally signed software installers
Explanation:
The Timestamp server field belongs to EMS software-package signing configuration. It provides a timestamp for digitally signed Windows FortiClient installers. Timestamping helps establish when the package was signed and is a normal component of code-signing workflows. It is unrelated to endpoint IP addressing, Telemetry keep-alives, or Web Filter scheduling. Administrators enabling package signing must configure the signing certificate, its password, and, where desired, the timestamp service correctly. Problems with any of these elements can prevent the expected publisher and signature information from appearing on generated or uploaded Windows deployment packages.
Question 179. In a multisite EMS configuration, which item is managed separately at the site level?
- Only the Linux kernel version
- Endpoint profiles, endpoint policies, deployment packages, security posture rules, and Software Inventory
- Only the FortiGate hardware serial number
- Only FortiAnalyzer reports
Correct Answer: 2. Endpoint profiles, endpoint policies, deployment packages, security posture rules, and Software Inventory
Explanation:
FortiClient EMS multisite deployments maintain many configurations at the individual site level. Fortinet lists endpoint management, endpoint policies, endpoint profiles, deployment packages, security posture tagging rules, Software Inventory, administrator permissions, and several System Settings elements among the items configured separately for each site. An endpoint that installs FortiClient through a deployment package associated with a particular site automatically registers to that site. Administrators should therefore understand site boundaries when troubleshooting why a policy, installer, inventory entry, or profile created in one site is not visible or applicable in another.
Question 180. An organization wants to restrict YouTube content, identify unauthorized installed applications, dynamically restrict network access for noncompliant endpoints, and ensure its Windows FortiClient installers show a trusted publisher. Which design BEST meets these requirements?
- Use only a Remote Access profile
- Use only FortiAnalyzer reporting
- Use standalone FortiClient installations with no EMS
- Use EMS Video Filter and Software Inventory, integrate EMS dynamic endpoint groups with FortiGate, and enable software-package signing with a valid code-signing certificate
Correct Answer: 4. Use EMS Video Filter and Software Inventory, integrate EMS dynamic endpoint groups with FortiGate, and enable software-package signing with a valid code-signing certificate
Explanation:
Each requirement maps to a distinct EMS or Security Fabric capability. Video Filter provides YouTube category, Safe Search, channel, and video controls. Software Inventory gives administrators visibility into installed applications and can identify potentially unwanted software. Security posture tags and EMS dynamic endpoint groups can be shared with FortiGate so network policies respond to endpoint compliance changes. Finally, Sign Software Packages allows Windows FortiClient installers to be digitally signed with the organization’s configured code-signing certificate. Combining these functions provides centralized endpoint visibility, content control, posture-based network enforcement, and trustworthy deployment packages.