Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.


Question 341. What does the Out-Of-Sync indicator in the FortiClient EMS Endpoints quick-status bar represent?

  1. Endpoints whose licenses have expired
  2. Endpoints whose currently applied profile is out of synchronization with the expected EMS configuration
  3. Endpoints that have never installed FortiClient
  4. Endpoints that are currently quarantined

Correct Answer: 2. Endpoints whose currently applied profile is out of synchronization with the expected EMS configuration

Explanation:

The FortiClient EMS Endpoints pane includes a quick-status bar that helps administrators rapidly identify devices requiring attention. Out-Of-Sync represents endpoints whose profile configuration is not synchronized with what EMS currently expects. This can happen when configuration changes have not yet reached the endpoint or when communication problems prevent the latest profile from being applied. Selecting the Out-Of-Sync indicator filters the endpoint list to those affected devices. Administrators should then investigate Telemetry connectivity, policy assignment, profile changes, and the endpoint’s most recent communication with EMS rather than assuming the profile itself is necessarily incorrect.

Question 342. What does the Security Risk counter in the EMS Endpoints quick-status bar allow an administrator to do?

  1. View only endpoints without FortiClient installed
  2. View only endpoints using unsupported operating systems
  3. Display every EMS administrator account
  4. Filter the endpoint list to devices that EMS identifies as security risks

Correct Answer: 4. Filter the endpoint list to devices that EMS identifies as security risks

Explanation:

The EMS Endpoints quick-status bar includes a Security Risk indicator. Selecting it displays endpoints currently identified as security risks, allowing administrators to focus on devices with security-related conditions instead of manually searching through the full managed population. Other quick-status categories separately identify devices that are not installed, not registered, out of sync, or quarantined. These categories help administrators distinguish deployment, connectivity, configuration, and security conditions. The Security Risk counter should therefore be used as a focused monitoring tool rather than interpreted as a general count of all disconnected or outdated endpoints.

Question 343. Which endpoint information appears under Network Status in the EMS endpoint details view?

  1. MAC address, IP address, gateway IP, gateway MAC address, and Wi-Fi SSID when applicable
  2. Only the endpoint hostname
  3. Only FortiClient version and serial number
  4. Only VPN username and tunnel name

Correct Answer: 1. MAC address, IP address, gateway IP, gateway MAC address, and Wi-Fi SSID when applicable

Explanation:

The endpoint details view provides useful network-context information under Network Status. Fortinet documents fields including the endpoint MAC address, IP address, gateway IP address, gateway MAC address, and Wi-Fi SSID when the endpoint is using a wireless connection. This information can help troubleshoot on-fabric detection, incorrect routing assumptions, network-location changes, or endpoint connectivity problems. It also provides context beyond the basic endpoint IP address shown in the main list. The Network Status section is separate from Hardware Details and Configuration, which provide device hardware and FortiClient-management information respectively.

Question 344. Which information is displayed under Hardware Details for an endpoint when that information is available?

  1. FortiGate policy IDs only
  2. Active Directory passwords
  3. Hardware model, vendor, CPU, RAM, and device serial number
  4. FortiAnalyzer report schedules

Correct Answer: 3. Hardware model, vendor, CPU, RAM, and device serial number

Explanation:

EMS provides a Hardware Details section for managed endpoints. When the information is available, administrators can see details such as the hardware model, vendor, processor, installed RAM, and device serial number. These fields are useful for endpoint inventory, troubleshooting, asset identification, and determining whether a device meets hardware requirements. Hardware Details should not be confused with the Configuration section, where EMS displays policy, installer, FortiClient version, FortiClient serial number, FortiClient ID, and ZTNA certificate information. Together, these views provide both physical-device context and FortiClient-management context.

Question 345. Which item can be found in the Configuration section of an endpoint’s EMS details?

  1. Windows product key
  2. FortiAnalyzer SQL password
  3. CPU temperature
  4. The endpoint policy, installer, FortiClient version, FortiClient serial number, FortiClient ID, and ZTNA serial number

Correct Answer: 4. The endpoint policy, installer, FortiClient version, FortiClient serial number, FortiClient ID, and ZTNA serial number

Explanation:

The EMS endpoint Configuration section summarizes management-specific information about a selected device. Fortinet documents fields including the assigned endpoint policy, installer used, installed FortiClient version, FortiClient serial number, FortiClient ID, and the ZTNA certificate serial number. These details are particularly useful when comparing a problematic endpoint with a correctly functioning one. For example, an administrator can determine whether two devices received different installers or policies, whether one runs an unexpected FortiClient version, or whether a ZTNA certificate has been provisioned.

Question 346. What does the Location field in EMS endpoint details indicate?

  1. The physical GPS coordinates of the device
  2. Whether the endpoint is considered on-fabric or off-fabric
  3. The user’s home address
  4. The geographical location of the EMS database

Correct Answer: 2. Whether the endpoint is considered on-fabric or off-fabric

Explanation:

The endpoint Location field identifies whether EMS currently considers the endpoint on-fabric or off-fabric. Administrators can also view the on-fabric detection rules relevant to the endpoint. This status is important because endpoint policies can assign different configurations according to fabric location. For example, a remote endpoint may need stronger remote-access settings than a device operating inside the trusted corporate network. The field does not provide GPS positioning or physical user-location tracking; it represents the endpoint’s logical relationship to the organization’s configured on-fabric detection criteria.

Question 347. What is the PRIMARY purpose of the Endpoints > All Events page introduced in the EMS 7.4 branch?

  1. To configure EMS licenses
  2. To create Active Directory domains
  3. To provide a consolidated view of events from all endpoints and allow administrators to take actions
  4. To build FortiClient deployment packages

Correct Answer: 3. To provide a consolidated view of events from all endpoints and allow administrators to take actions

Explanation:

The Endpoints > All Events page gives administrators a consolidated event-management view across managed endpoints. Rather than opening each endpoint separately, an administrator can filter and examine events centrally and take actions against endpoints associated with selected events. The page includes visual summaries such as an Event Type chart and supports saved views and exports. This capability is especially useful in larger deployments where investigating malware, vulnerability, system, PUA, or other endpoint events individually would be inefficient. It provides operational visibility rather than replacing endpoint profiles or EMS licensing functions.

Question 348. What is required for the All Events feature when FortiClient EMS is deployed on premises?

  1. Integration with an Elasticsearch time-series database
  2. An IPsec VPN to FortiAnalyzer
  3. A second EMS license
  4. A Windows Active Directory forest

Correct Answer: 1. Integration with an Elasticsearch time-series database

Explanation:

For on-premises EMS, Fortinet requires integration with an Elasticsearch time-series database before the Endpoints > All Events capability becomes available. EMS stores the relevant event information in Elasticsearch indexes so administrators can search, filter, visualize, and export consolidated endpoint events. Without Elasticsearch integration, the All Events page is unavailable on on-premises EMS. FortiClient Cloud differs because this feature is available there by default. This distinction is important when an administrator cannot find All Events even though the EMS installation otherwise functions normally.

Question 349. Which Web Filter events appear on the EMS All Events page?

  1. Allow events only
  2. Block and Warn events
  3. Monitor events only
  4. All Allow, Block, Warn, and Monitor events

Correct Answer: 2. Block and Warn events

Explanation:

Fortinet specifically documents that the All Events page displays only Block and Warn categories for Web Filter events. Web Filter events generated with Allow or Monitor actions are not displayed there. This is important when administrators compare the All Events page with other logs and notice that some normal browsing activity is absent. The omission does not necessarily indicate failed logging; it reflects the design of the consolidated event interface. The page emphasizes events that are more likely to require administrative attention rather than presenting all permitted or monitored web activity.

Question 350. Which formats can an administrator use when exporting a list from Endpoints > All Events?

  1. PDF and DOCX only
  2. XLSX only
  3. XML and YAML only
  4. CSV or JSON

Correct Answer: 4. CSV or JSON

Explanation:

The All Events interface supports exporting filtered event information in CSV or JSON format. CSV is useful for spreadsheet-based review, reporting, and manual analysis, while JSON is convenient for structured processing, automation, or importing into other tools. Administrators can first configure relevant filters and then export the resulting event list. This allows EMS event data to be analyzed outside the console without requiring database-level access. The export function is separate from EMS database backup, endpoint diagnostic packages, and Software Inventory exports.

Question 351. What can an administrator do after creating useful filters on the All Events page?

  1. Save the filter configuration as a reusable event view
  2. Convert the filters into an EMS license
  3. Automatically create a FortiGate VDOM
  4. Turn the filter into an Active Directory group

Correct Answer: 1. Save the filter configuration as a reusable event view

Explanation:

The All Events page allows administrators to configure filters and then save those settings as a reusable view. This is useful when administrators repeatedly investigate similar event categories, endpoint populations, or security conditions. Instead of reconstructing filters each time, a saved view can preserve the desired event perspective. For example, a security team could maintain separate views for malware detections, potentially unwanted applications, or endpoint-system events. Saved views improve operational efficiency but do not change endpoint configuration or enforcement; they affect how event information is displayed and investigated.

Question 352. What does the Elasticsearch vulnerability-event index store for EMS?

  1. Only EMS administrator login attempts
  2. Endpoint events related to vulnerability detection and resolution, including vulnerability state
  3. Only Web Filter Allow events
  4. Only FortiClient installer-download logs

Correct Answer: 3. Endpoint events related to vulnerability detection and resolution, including vulnerability state

Explanation:

EMS creates an Elasticsearch index dedicated to vulnerability events. Fortinet documents that it stores endpoint events associated with vulnerability detection and resolution, including the vulnerability’s current state such as open or resolved. This structure allows consolidated event monitoring to track vulnerability lifecycle information instead of treating every observation as unrelated. Other EMS indexes are dedicated to different event types, such as malware alerts, potentially unwanted applications, and system events. Understanding this event separation is useful when troubleshooting Elasticsearch storage or investigating why a particular event appears in one index rather than another.

Question 353. Which type of data is stored in the EMS Elasticsearch PUA index?

  1. Potentially unwanted application events
  2. FortiGate routing updates
  3. LDAP password history
  4. EMS database backup records only

Correct Answer: 1. Potentially unwanted application events

Explanation:

The EMS Elasticsearch PUA index stores events related to potentially unwanted applications. Fortinet documents that EMS records PUA events for endpoints and can retain information about their detection or resolution state depending on the EMS release. PUA monitoring is useful because not every risky application qualifies as traditional malware. Applications such as unwanted toolbars, questionable utilities, or other potentially undesirable software can still represent policy or security concerns. The PUA index is distinct from malware-alert, vulnerability, and endpoint-system-event indexes.

Question 354. Which event would be stored as an endpoint system event in the EMS Elasticsearch system-event index?

  1. Only antivirus malware detections
  2. Only potentially unwanted applications
  3. Only vulnerability remediation
  4. Connecting to or disconnecting from EMS, network-connection changes, or certificate-signing events

Correct Answer: 4. Connecting to or disconnecting from EMS, network-connection changes, or certificate-signing events

Explanation:

The EMS Elasticsearch system-event index stores operational endpoint events rather than malware or vulnerability findings. Examples documented by Fortinet include certificate signing, receiving or acknowledging one-way messages, connecting to or disconnecting from EMS, and network-connection changes such as VPN or Wi-Fi connections. Separating system events from other security-event types makes searching and retention more manageable. If an administrator is investigating why an endpoint repeatedly disconnects from EMS or changes network context, the system-event index is more relevant than the malware-alert or PUA index.

Question 355. What does the EMS Elasticsearch alerts index primarily store?

  1. Endpoint-related alerts stemming from malware detection
  2. Active Directory computer objects
  3. FortiGate BGP updates
  4. EMS license invoices

Correct Answer: 2. Endpoint-related alerts stemming from malware detection

Explanation:

Fortinet documents a dedicated Elasticsearch alerts index for endpoint-related alerts associated with malware detection. EMS stores individual endpoint alert events there, separating them from vulnerability, PUA, and system-event datasets. This structure supports more efficient consolidated event analysis and helps administrators focus on specific event categories. When investigating malware-related endpoint alerts through All Events or underlying Elasticsearch storage, the alerts index is the relevant source. It should not be confused with EMS email-alert configuration, which controls administrator notifications for conditions such as license or LDAP issues.

Question 356. If EMS connects to Elasticsearch and discovers that required event indexes do not exist, what does EMS do?

  1. Disables event collection permanently
  2. Requires the endpoint user to create the indexes
  3. Creates the required indexes
  4. Sends all events to FortiGate instead

Correct Answer: 3. Creates the required indexes

Explanation:

When EMS establishes its Elasticsearch connection, it checks whether the indexes required for endpoint event storage are present. If the necessary indexes do not exist, EMS creates them. These indexes are then used for event categories such as malware alerts, potentially unwanted applications, vulnerabilities, and endpoint system events. This automated behavior reduces the amount of manual Elasticsearch preparation required for EMS integration. Administrators are still responsible for deploying, sizing, securing, and maintaining the Elasticsearch environment appropriately, but they do not normally have to create each EMS event-specific index manually.

Question 357. From which sources can EMS obtain device information for Windows, macOS, and Linux endpoints?

  1. Only FortiAnalyzer
  2. Only Google Admin console
  3. Only FortiGate
  4. Active Directory, Windows workgroups, or manual FortiClient connections

Correct Answer: 4. Active Directory, Windows workgroups, or manual FortiClient connections

Explanation:

EMS needs an inventory of devices that may be managed. For Windows, macOS, and Linux endpoints, Fortinet documents several sources: an Active Directory server, Windows workgroup, or a manual FortiClient connection. These methods let EMS learn about endpoints through existing enterprise directory infrastructure, local network groupings, or direct client registration. Discovery or visibility alone does not always mean FortiClient is already installed or registered; EMS endpoint status provides additional information about management state. Chromebook discovery uses a different source, the Google Admin console.

Question 358. From where does FortiClient EMS obtain Chromebook device information?

  1. The Google Admin console
  2. Windows workgroup discovery
  3. FortiAnalyzer
  4. FortiSandbox

Correct Answer: 1. The Google Admin console

Explanation:

Chromebook endpoint information is obtained from the Google Admin console, rather than through Active Directory, Windows workgroups, or ordinary desktop FortiClient discovery mechanisms. This reflects the management architecture of ChromeOS devices, where organizational device and extension management are commonly handled through Google’s administrative platform. EMS can integrate with that environment to support FortiClient Chromebook functionality. Administrators planning a mixed endpoint deployment should therefore recognize that discovery and onboarding methods differ by operating system and should not expect desktop Windows discovery methods to apply to Chromebooks.

Question 359. In the EMS endpoint-summary view for an MDM-managed mobile device, what does MDM Deployment Status = Installed mean?

  1. FortiClient has been uninstalled
  2. The MDM platform rejected the request
  3. The ZTNA certificate has been successfully installed on the endpoint
  4. The certificate has been revoked

Correct Answer: 3. The ZTNA certificate has been successfully installed on the endpoint

Explanation:

The endpoint summary displays MDM-related certificate deployment status for supported mobile workflows. Installed means the ZTNA certificate has been successfully installed on the endpoint. Other documented statuses include Pending, where the MDM platform has accepted the request but certificate installation is not complete; Missing, where the certificate is absent; and Revoked, where the certificate is no longer trusted. These states help administrators distinguish MDM enrollment from actual certificate-provisioning success when troubleshooting mobile ZTNA access.

Question 360. An administrator wants to investigate widespread endpoint events, identify devices with profile synchronization problems, review network and hardware details on one affected laptop, and export filtered events for external analysis. Which EMS workflow BEST meets the requirement?

  1. Rebuild every endpoint profile immediately
  2. Use the Endpoints quick-status bar to identify Out-Of-Sync devices, inspect endpoint Network Status and Hardware Details, use All Events for consolidated investigation, and export the filtered event list as CSV or JSON
  3. Use only FortiClient deployment packages
  4. Disable Elasticsearch and rely exclusively on endpoint users

Correct Answer: 2. Use the Endpoints quick-status bar to identify Out-Of-Sync devices, inspect endpoint Network Status and Hardware Details, use All Events for consolidated investigation, and export the filtered event list as CSV or JSON

Explanation:

EMS provides several complementary troubleshooting tools. The quick-status bar rapidly identifies endpoint populations such as Out-Of-Sync or Security Risk devices. The selected endpoint’s detail page exposes Network Status, Hardware Details, assigned configuration, tags, and other context. For a broader investigation, All Events consolidates endpoint events and supports filtering, saved views, endpoint actions, and CSV or JSON export. In an on-premises deployment, All Events requires Elasticsearch integration. Using these existing visibility tools first provides evidence about the problem before administrators make potentially unnecessary changes to otherwise valid profiles or deployment configurations.