View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 301. In a FortiClient EMS Vulnerability Scan profile, what does selecting Patch Level = High mean?
- Patch only low-severity vulnerabilities
- Automatically patch high-severity and critical vulnerabilities
- Patch only informational findings
- Disable automatic patching
Correct Answer: 2. Automatically patch high-severity and critical vulnerabilities
Explanation:
The Automatic Patching section of the Vulnerability Scan profile lets an administrator choose the minimum severity level that FortiClient should patch automatically. Selecting High causes FortiClient to patch vulnerabilities rated High as well as more severe Critical vulnerabilities. Other choices include Critical, Medium, Low, and All. Choosing a broader patch level increases automatic remediation coverage but can also create more endpoint changes. Administrators should select the level that matches organizational risk tolerance, testing requirements, and software-change procedures.
Question 302. What operational effect can FortiClient automatic vulnerability patching have on an endpoint?
- It disables EMS Telemetry
- It always logs the user off but never reboots
- It automatically changes the endpoint’s IP address
- It may require the endpoint to reboot**
Correct Answer: 4. It may require the endpoint to reboot
Explanation:
Fortinet warns that automatic vulnerability patching can require an endpoint reboot. This is important when administrators enable remediation of Critical, High, Medium, Low, or all detected vulnerabilities through EMS. Although automatic patching improves security by reducing exposure time, it can affect user productivity if applications or operating-system components require restart. Organizations should therefore combine patching settings with appropriate user communication, maintenance planning, and testing. A reboot requirement is a possible consequence of patch installation rather than evidence that the patching process malfunctioned.
Question 303. What happens when “Exempt Application Vulnerabilities Requiring Manual Update from Vulnerability Compliance Check” is enabled?
- Applications requiring manual updates are excluded from compliance evaluation but are still scanned for vulnerabilities
- Those applications are deleted automatically
- Vulnerability scanning is disabled completely
- EMS removes the applications from Software Inventory
Correct Answer: 1. Applications requiring manual updates are excluded from compliance evaluation but are still scanned for vulnerabilities
Explanation:
This exclusion setting affects compliance, not vulnerability detection. Applications that require the endpoint user to patch them manually can be exempted from the vulnerability compliance check so they do not cause the endpoint to become noncompliant simply because automatic remediation is unavailable. Fortinet explicitly states that the applications remain subject to vulnerability scanning. This distinction is important: excluding something from the compliance decision does not mean EMS stops detecting or reporting its vulnerabilities. Administrators can therefore preserve visibility while avoiding inappropriate compliance penalties.
Question 304. What is true when an administrator places an application in “Exclude Selected Applications from Vulnerability Compliance Check”?
- FortiClient stops detecting the application
- EMS uninstalls the application
- The application remains subject to vulnerability scanning but is exempt from the configured compliance requirement
- The application is removed from all FortiGate policies
Correct Answer: 3. The application remains subject to vulnerability scanning but is exempt from the configured compliance requirement
Explanation:
The selected-application exclusion controls whether a vulnerable application affects endpoint compliance. Fortinet documents that applications placed on this list remain visible to vulnerability scanning; they are simply exempted from needing to install software patches within the compliance timeframe defined by FortiGate rules. This can be useful for business-critical software that cannot be upgraded immediately. Administrators should avoid treating the exclusion as a vulnerability-scanning bypass because the vulnerability continues to exist and should still be assessed and remediated when operationally feasible.
Question 305. What does “Disable Automatic Patching for These Applications” do when used with vulnerability-compliance exclusions?
- Disables all FortiClient scanning
- Makes the endpoint permanently compliant
- Deletes vulnerability signatures for those applications
- Prevents FortiClient from automatically patching the excluded applications**
Correct Answer: 4. Prevents FortiClient from automatically patching the excluded applications
Explanation:
After selected applications have been excluded from the vulnerability compliance check, EMS also provides an option to Disable Automatic Patching for These Applications. This lets administrators separate compliance and remediation behavior. For example, an application can remain visible as vulnerable, be excluded from causing a compliance failure, and also be prevented from receiving an automatic update that could disrupt a critical workflow. Such exclusions should be carefully documented because they intentionally leave identified vulnerabilities unresolved until another remediation process addresses them.
Question 306. When does the “Scan On” day selection apply in a scheduled Vulnerability Scan profile?
- When the schedule type is Weekly or Monthly
- Only when Scan on Registration is enabled
- Only for manually started scans
- Only when Automatic Patching is disabled
Correct Answer: 1. When the schedule type is Weekly or Monthly
Explanation:
The Scan On field is relevant when Vulnerability Scan scheduling uses a Weekly or Monthly schedule. An administrator can select the appropriate day of the week or day of the month and define the scan’s start time. This provides predictable recurring vulnerability assessment without relying entirely on manual scans. It is separate from other scan triggers such as Scan on Registration or Scan on Vulnerability Signature Update. Administrators should understand which trigger caused a scan when analyzing endpoint activity or scheduling resource-intensive vulnerability checks.
Question 307. Which type of information appears as an AV event in the FortiClient Notifications tab?
- Only VPN tunnel establishment messages
- Only software-inventory changes
- Scheduled antivirus scans and detected malware
- Only EMS licensing alerts
Correct Answer: 3. Scheduled antivirus scans and detected malware
Explanation:
The FortiClient Notifications tab provides user-visible information about endpoint events. Fortinet lists antivirus events such as scheduled AV scans and malware detections among the supported notification types. Other categories include Sandbox Detection, Telemetry, Web Filter, and system events. The Notifications tab therefore serves as a useful local endpoint view when troubleshooting whether a security action occurred. It is different from the EMS server’s centralized event and alert interfaces, which aggregate management information across many endpoints.
Question 308. What can a FortiClient user view by selecting “Threat Detected” in the Notifications area?
- EMS database backups
- Quarantined files, site violations, and Real-Time Protection events
- FortiGate routing entries
- Active Directory password changes
Correct Answer: 2. Quarantined files, site violations, and Real-Time Protection events
Explanation:
Fortinet documents that selecting Threat Detected in FortiClient allows the user to view information including quarantined files, site violations, and Real-Time Protection events. This gives the endpoint user or support technician a local view of security incidents affecting that device. It can be useful when investigating why a file disappeared, why access to a site was denied, or whether RTP detected malicious content. These endpoint notifications complement, rather than replace, centralized EMS or FortiAnalyzer logging used by administrators.
Question 309. Which event is categorized as a Telemetry notification in FortiClient?
- Configuration updates received from EMS
- FortiGate hardware failure
- PostgreSQL replication events
- Active Directory schema modifications
Correct Answer: 1. Configuration updates received from EMS
Explanation:
FortiClient Telemetry notifications include events such as configuration updates received from EMS. This gives the endpoint a visible indication that centralized management has supplied new settings. Because endpoint policies and profiles are delivered through the EMS management relationship, these notifications can help confirm that FortiClient received updated configuration. If EMS shows a policy change but FortiClient never indicates a configuration update, administrators should check endpoint status, Telemetry connectivity, policy applicability, and the timing of the endpoint’s latest communication with EMS.
Question 310. Which events are examples of FortiClient System notifications?
- Only blocked YouTube videos
- Only LDAP authentication failures
- Only endpoint quarantine actions
- Signature and engine updates and software upgrades**
Correct Answer: 4. Signature and engine updates and software upgrades
Explanation:
The FortiClient Notifications tab categorizes signature updates, engine updates, and software upgrades as System events. These are distinct from antivirus detections, Web Filter blocks, or Telemetry configuration updates. System notifications can help administrators and users determine whether endpoint security engines and definitions were updated successfully or whether a FortiClient software upgrade occurred. Understanding the notification category can speed troubleshooting because it indicates which FortiClient subsystem generated the event and where administrators should investigate next.
Question 311. What must a custom XML configuration file used for an EMS endpoint profile contain?
- Only settings changed from default
- All configuration settings required by the endpoint at deployment time
- Only VPN-related settings
- Only FortiGuard connection settings
Correct Answer: 2. All configuration settings required by the endpoint at deployment time
Explanation:
Fortinet allows administrators to configure an endpoint profile through XML, but a custom XML file must contain all settings required by the endpoint at the time of deployment. Administrators should not assume EMS will automatically reconstruct missing required settings from an incomplete custom file. XML configuration offers flexibility for advanced settings not easily exposed through standard GUI controls, but it also requires careful configuration management. The FortiClient XML Reference should be used to ensure valid elements and supported values are supplied.
Question 312. How does an EMS administrator expose the XML Configuration tab while editing an endpoint profile?
- By enabling Advanced mode
- By disabling the endpoint policy
- By opening FortiAnalyzer
- By turning off Feature Select
Correct Answer: 3. By enabling Advanced mode
Explanation:
When creating or editing an EMS endpoint profile, the administrator can select Advanced to display the XML Configuration tab. The profile’s configuration can then be viewed and edited as XML. This provides access to configuration elements that may not be available through normal GUI controls. Because XML errors can affect endpoint configuration, administrators should use the FortiClient XML Reference and validation features rather than making unsupported changes blindly. Advanced XML editing is a supplement to standard EMS profiles, not a replacement for careful profile design.
Question 313. Which action should an administrator perform after manually editing XML in an EMS endpoint profile and before relying on it in production?
- Delete all other profiles
- Reboot FortiGate
- Disable EMS licensing
- Use Test XML to validate the edited configuration**
Correct Answer: 4. Use Test XML to validate the edited configuration
Explanation:
Fortinet includes a Test XML function in the endpoint-profile XML editing workflow. After editing XML, the administrator should validate the configuration before saving and deploying it. This helps identify syntax or structure problems that could otherwise prevent FortiClient from applying the intended configuration correctly. XML profiles can contain advanced settings and therefore offer considerable flexibility, but that flexibility also increases the risk of manual errors. Validation should be treated as a standard part of any XML-based profile change process.
Question 314. When an EMS administrator exports an endpoint profile, what is included in the export?
- Only the profile name
- All configured profile components represented in XML
- Only Remote Access settings
- Only licensing information
Correct Answer: 2. All configured profile components represented in XML
Explanation:
Fortinet allows endpoint profiles to be exported from EMS. The export contains all configured components of the profile in XML form. This is useful for configuration review, troubleshooting, documentation, or transferring profile configuration through supported workflows. Because the exported representation includes the complete profile configuration, administrators should protect these files appropriately, particularly if they contain sensitive connection information. Exporting a profile is different from exporting logs or backing up the EMS database; it is specifically a configuration-level representation of the profile.
Question 315. What default filename does the browser use when downloading an exported EMS profile XML configuration?
- profile.conf
- forticlient.msi
- ems.xml.zip
- policy.db
Correct Answer: 1. profile.conf
Explanation:
Fortinet documents that when an administrator exports an endpoint profile, the browser downloads the configuration as a file named profile.conf. Fortinet recommends renaming the file to reflect the actual profile name, which makes stored exports easier to identify and manage. The file contains the profile’s XML configuration and should not be confused with a FortiClient deployment installer or an EMS database backup. Clear naming is especially valuable in environments where administrators maintain exports of multiple production, test, on-fabric, and off-fabric profiles.
Question 316. What does the “Download Profile XML” function in an endpoint policy provide?
- One XML file containing the configuration of the selected endpoint profiles
- A FortiClient installer
- A FortiGate configuration backup
- A list of EMS administrator accounts
Correct Answer: 3. One XML file containing the configuration of the selected endpoint profiles
Explanation:
While editing an endpoint policy, EMS provides a Download Profile XML function. Fortinet states that this produces one XML file containing the configuration for the endpoint profiles selected in that policy. This is useful when administrators need to review the effective configuration components associated with the policy rather than exporting each profile separately. It can also support troubleshooting by showing which profile settings are intended for endpoints governed by that policy. The downloaded XML is configuration data, not an installer or a database backup.
Question 317. If an endpoint policy includes a separate Off-Fabric profile configuration, what additional XML export option is available?
- Off-Fabric Profile XML
- FortiGuard Database XML
- FortiAnalyzer Report XML
- ZTNA Certificate XML
Correct Answer: 2. Off-Fabric Profile XML
Explanation:
When Profile (Off-Fabric) is enabled in an endpoint policy, EMS provides a separate Off-Fabric Profile XML download option. The resulting file contains the configuration of the profiles selected specifically for endpoints classified as off-fabric. This is useful when comparing normal on-fabric and remote endpoint configurations or troubleshooting why security behavior changes when a laptop leaves the corporate network. Because on-fabric and off-fabric profile sets can differ substantially, separate XML exports make it easier to verify exactly what EMS intends to apply in each network context.
Question 318. What is the primary source of FortiGuard Outbreak Alert rules in FortiClient EMS?
- FortiGuard provides predefined outbreak rules to EMS
- Endpoint users create them locally
- FortiAnalyzer generates every outbreak rule
- Active Directory creates them from group policies
Correct Answer: 1. FortiGuard provides predefined outbreak rules to EMS
Explanation:
FortiGuard Outbreak Alerts provide predefined rules designed to help organizations respond quickly to emerging threats. For example, if FortiGuard Labs identifies a new zero-day vulnerability in a widely installed application, Fortinet can create an outbreak alert rule that identifies endpoints with the vulnerable application. EMS receives the rule and can tag affected endpoints dynamically. This gives administrators rapid visibility without requiring them to manually design a posture rule for every newly disclosed threat. The resulting tags can also participate in FortiOS dynamic policy enforcement.
Question 319. What administrative control does EMS provide over FortiGuard Outbreak Alert rules?
- Administrators can rewrite every FortiGuard rule
- Administrators can delete FortiGuard rules permanently
- Administrators can only enable or disable the predefined rules; they cannot modify or delete them
- Administrators can convert them into Installer IDs
Correct Answer: 4. Administrators can only enable or disable the predefined rules; they cannot modify or delete them
Explanation:
FortiGuard Outbreak Alert rules are controlled by FortiGuard rather than created locally by the EMS administrator. Fortinet explicitly states that administrators cannot modify or delete these predefined rules. They can, however, enable or disable individual outbreak rules in the relevant EMS interface. This preserves the integrity of Fortinet-provided threat logic while still allowing organizations to control whether a particular outbreak rule is active in their environment. Administrators needing custom endpoint criteria should create their own security posture tagging rules instead.
Question 320. A newly disclosed zero-day affects a popular application. The organization wants to identify vulnerable endpoints automatically and restrict their network access without manually creating a new endpoint group. Which approach BEST meets the requirement?
- Create one static IP object for every endpoint
- Wait for users to report the vulnerable application
- Use only Software Inventory and make all access changes manually
- Enable the relevant FortiGuard Outbreak Alert rule so EMS dynamically tags affected endpoints and use those dynamic tags in FortiOS policy**
Correct Answer: 3. Enable the relevant FortiGuard Outbreak Alert rule so EMS dynamically tags affected endpoints and use those dynamic tags in FortiOS policy
Explanation:
FortiGuard Outbreak Alert rules are designed specifically for rapidly emerging threats. FortiGuard can provide a predefined rule identifying endpoints affected by a newly discovered vulnerability. EMS receives the rule, dynamically tags matching endpoints, and makes those tags visible in the Tag Monitor. Like security posture tags, outbreak tags can be shared with FortiOS, where dynamic policy rules can restrict access for the affected endpoint population. This approach avoids manually creating or maintaining static device groups whenever a new outbreak appears and enables much faster containment of vulnerable systems.