Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.


Question 381. How many multitenancy sites can FortiClient EMS support?

  1. 10 sites
  2. 20 sites
  3. 25 sites
  4. Up to 50 sites

Correct Answer: 4. Up to 50 sites

Explanation:

FortiClient EMS multitenancy allows an organization to divide endpoint management into separate sites. Fortinet documents support for up to 50 multitenancy sites. Each site can maintain its own endpoint data and configuration, allowing administrators to separate business units, customers, subsidiaries, or other administrative boundaries. Access can also be restricted so administrators see only their assigned sites. Multitenancy is useful for managed-service or large enterprise environments where a single EMS installation must provide strong administrative separation without requiring a completely separate EMS deployment for every endpoint population.

Question 382. What is the default state of multitenancy in FortiClient EMS?

  1. Enabled with five predefined sites
  2. Disabled
  3. Enabled only for EPP licenses
  4. Enabled only after FortiAnalyzer integration

Correct Answer: 2. Disabled

Explanation:

FortiClient EMS has multitenancy disabled by default. An administrator enables it from EMS Settings by turning on Manage Multiple Customer Sites. Multitenancy should therefore be intentionally configured rather than assumed to be active after installation. Once enabled, EMS introduces global and site-level administration, allowing configuration and endpoint information to be separated among different sites. Organizations should understand this architecture before enabling it because administrative roles, licenses, dashboards, configuration ownership, and Security Fabric connector behavior can all differ between global and individual site contexts.

Question 383. What happens immediately after an administrator enables “Manage Multiple Customer Sites” and saves the setting?

  1. EMS forces the GUI to restart so the multitenancy changes can take effect
  2. Every endpoint is uninstalled
  3. EMS deletes the existing default site
  4. All licenses are returned to FortiCloud

Correct Answer: 1. EMS forces the GUI to restart so the multitenancy changes can take effect

Explanation:

When Manage Multiple Customer Sites is enabled, Fortinet states that EMS forces the graphical interface to restart so the multitenancy configuration can become active. Existing endpoint information is not deleted. Instead, the original EMS environment becomes the default site, while a new global administrative context becomes available. Administrators then use the site selector to move between global and site-level interfaces. This behavior is important during change planning because enabling multitenancy affects the EMS administrative model immediately and should therefore be performed during an appropriate administrative maintenance period.

Question 384. Which two sites initially exist after multitenancy is first enabled?

  1. Primary and Secondary
  2. Production and Development
  3. Global and Default
  4. EMS and FortiGate

Correct Answer: 3. Global and Default

Explanation:

After multitenancy is enabled, EMS initially presents two sites: Global and Default. The Global site provides access to settings and functions that apply across the EMS installation, while the Default site contains the endpoint environment and settings from the original EMS instance. Administrators can then create additional sites according to organizational requirements. Understanding the difference between Global and Default is important because some configuration can be performed only globally, while endpoint-specific policies, profiles, inventories, and other management tasks belong at individual site level.

Question 385. What happens to the original EMS endpoint environment after multitenancy is enabled?

  1. It is deleted and must be recreated
  2. It is retained in the Default site
  3. It moves automatically to every new site
  4. It becomes read-only

Correct Answer: 2. It is retained in the Default site

Explanation:

Enabling multitenancy does not destroy the existing EMS environment. Fortinet documents that the Default site retains the original EMS instance’s endpoints and settings. This design helps organizations introduce multitenancy without rebuilding the original endpoint deployment from scratch. Newly created sites remain separate and can receive their own endpoints, configuration, and assigned licenses. Administrators should nevertheless plan site architecture carefully before enabling multitenancy, because the change introduces a global-versus-site configuration model and affects how administrators access and manage different endpoint populations.

Question 386. Which statement BEST describes data isolation between EMS multitenancy sites?

  1. All sites automatically share endpoint data
  2. Only Software Inventory is isolated
  3. Sites share data when they use the same administrator
  4. Sites are separate and do not share endpoint data and configuration with one another

Correct Answer: 4. Sites are separate and do not share endpoint data and configuration with one another

Explanation:

Fortinet describes multitenancy sites as completely separate from each other. Endpoint data and configuration are isolated by site, and an administrator who has access only to one site cannot view information belonging to another site. This allows EMS to support strong administrative segmentation within a single multitenant deployment. A global administrator may have broader access, but that privilege does not mean the sites themselves merge their endpoint data. This separation is important for managed-service environments, subsidiaries, or organizations requiring delegated administration with clearly defined information boundaries.

Question 387. When EMS multitenancy is enabled, what must a Fortinet Security Fabric connector use to identify the correct EMS site?

  1. An endpoint Installer ID
  2. Only the EMS server IP address
  3. An FQDN whose hostname matches the EMS site name
  4. A FortiAnalyzer device ID

Correct Answer: 3. An FQDN whose hostname matches the EMS site name

Explanation:

With multitenancy enabled, Fortinet Security Fabric connectors must use an FQDN to connect to EMS, and the hostname portion must correspond to the intended EMS site name. Fortinet provides examples such as default.ems… for the Default site and sitea.ems… for a site named SiteA. This enables EMS to determine which site the connecting FortiGate should interact with. A plain shared IP address cannot provide the same site-selection context, making DNS and FQDN planning particularly important in multitenant Security Fabric deployments.

Question 388. Which statement about site names in EMS multitenancy is correct for newer 7.4 releases?

  1. Site names must follow defined naming rules, including length and permitted-character restrictions
  2. Site names can contain any Unicode characters without limitation
  3. Every site name must be exactly eight characters
  4. Site names must contain the EMS serial number

Correct Answer: 1. Site names must follow defined naming rules, including length and permitted-character restrictions

Explanation:

Fortinet introduced specific naming requirements for EMS multitenancy sites. Current 7.4 documentation describes rules such as a maximum length, beginning with a letter, ending with a letter or digit, and using permitted letters, digits, and hyphens for remaining characters. Older sites created before these rules may generate a warning if their existing names do not comply. Administrators should choose DNS-friendly, predictable names because site names can also be significant when building FQDNs for Security Fabric connectors and other multitenant integrations.

Question 389. Which function must be performed from the Global site in a multitenant on-premises EMS deployment?

  1. Creating every endpoint policy
  2. Viewing every site’s Software Inventory simultaneously
  3. Editing each site’s Web Filter profiles
  4. Licensing EMS and allocating licenses to individual sites

Correct Answer: 4. Licensing EMS and allocating licenses to individual sites

Explanation:

In an on-premises multitenant EMS deployment, license management occurs from the Global site. The organization activates its available licenses globally and then assigns portions of that capacity to individual sites. For example, a pool of ZTNA licenses can be divided among multiple customer or organizational sites. Endpoint profiles and policies remain site-level functions, while licensing is centrally controlled. This allows a global EMS administrator to manage overall entitlement capacity while still maintaining separation of endpoint configuration and operations among individual tenant sites.

Question 390. Which widgets appear on the Global site’s Dashboard in an EMS multitenancy deployment?

  1. System Information and License Information only
  2. Every endpoint-status chart from every site
  3. Only Vulnerability Scan widgets
  4. Only Software Inventory widgets

Correct Answer: 1. System Information and License Information only

Explanation:

Fortinet documents that the Global site’s Dashboard displays only the System Information and License Information widgets. Endpoint-specific charts and widgets are available at the individual site level because endpoint data is separated among sites. This arrangement reinforces the distinction between global EMS administration and tenant-specific endpoint operations. Administrators looking for endpoint vulnerability, version, status, or other endpoint-focused dashboards must switch to the relevant site instead of expecting those datasets to be aggregated automatically on the Global Dashboard.

Question 391. What access does the multitenancy Settings administrator role have?

  1. Access to selected endpoint sites but not Global
  2. Access to the Global site and its configuration except administrator configuration
  3. Read-only access to FortiClient endpoints only
  4. Full access to every site and all administrators

Correct Answer: 2. Access to the Global site and its configuration except administrator configuration

Explanation:

The multitenancy Settings administrator is a global-level role. Fortinet states that it can access configuration options on the Global site but cannot configure administrators. This role differs from the Super administrator, which has complete access across Global and all sites, and from a Site administrator, which is restricted to designated individual sites and does not receive Global site access. Separating these roles allows organizations to delegate global infrastructure and settings management without automatically giving every global settings administrator authority to create or modify privileged administrator accounts.

Question 392. What access does a multitenancy Site administrator have?

  1. Global configuration only
  2. Every site automatically
  3. Only the specified site or sites assigned to that administrator, with no Global site access
  4. Only FortiAnalyzer

Correct Answer: 3. Only the specified site or sites assigned to that administrator, with no Global site access

Explanation:

A Site administrator can be granted access to one or multiple designated EMS sites but has no access to the Global site. By default, a Site administrator is a Super administrator inside the sites to which access is granted, although site-level roles can be changed to reduce permissions. This model supports delegated administration—for example, different customer or departmental administrators can manage their assigned endpoints without receiving authority over the global EMS platform or unrelated sites. It is a key security feature of the multitenant architecture.

Question 393. Which restriction applies to EMS administrator names in a multitenancy environment?

  1. Administrator names from the same source must be unique across all sites
  2. Every administrator must use the name admin
  3. LDAP administrator names may be duplicated without restriction
  4. Administrator names must match site names

Correct Answer: 1. Administrator names from the same source must be unique across all sites

Explanation:

Fortinet specifies that administrator names coming from the same source—such as EMS, LDAP, or Windows—must be unique across all sites. Administrators may use the same visible name when the accounts originate from different sources, but two accounts from the same source cannot create an ambiguous duplicate across multitenancy sites. This requirement helps EMS maintain clear identity associations when privileges differ between sites. Administrators designing delegated access should therefore coordinate account naming and directory sourcing before creating large numbers of site-specific administrator assignments.

Question 394. What browser practice does Fortinet warn against when administering multiple EMS sites?

  1. Using HTTPS
  2. Bookmarking the EMS FQDN
  3. Using a supported modern browser
  4. Opening multiple browser tabs to configure different EMS sites simultaneously

Correct Answer: 4. Opening multiple browser tabs to configure different EMS sites simultaneously

Explanation:

Fortinet warns that EMS does not support using multiple browser tabs to configure different sites at the same time. Doing so can produce display problems and break the presentation of site information. Administrators should instead use the EMS Switch Site function in the same management interface when moving between tenants. This restriction matters because multitenancy involves separate site contexts, and attempting to hold different site states in parallel browser tabs can lead to confusion about which site’s configuration is currently displayed or modified.

Question 395. What information does the Managed Windows FortiClient Versions dashboard chart display?

  1. Only the newest available FortiClient release
  2. The percentage of Windows endpoints running each installed FortiClient version
  3. Only endpoints with unsupported Windows versions
  4. Only endpoints using SSL VPN

Correct Answer: 2. The percentage of Windows endpoints running each installed FortiClient version

Explanation:

The Managed Windows FortiClient Versions chart provides a graphical breakdown of the FortiClient versions installed across Windows endpoints. Administrators can sort the data by version or endpoint count, making it useful for identifying older clients and monitoring upgrade adoption. Equivalent charts are available for macOS and Linux endpoints. This visibility helps organizations plan staged FortiClient upgrades and determine whether a large population remains on an older version. It is a monitoring tool rather than an upgrade mechanism itself; deployment configurations are still used to perform upgrades.

Question 396. What does the EMS Endpoint Management dashboard chart show?

  1. Only endpoints with malware
  2. Only endpoints with current licenses
  3. How many endpoints are connected and disconnected
  4. Only endpoints connected through VPN

Correct Answer: 3. How many endpoints are connected and disconnected

Explanation:

The EMS Endpoint Management dashboard chart provides a high-level view of endpoint connectivity by showing how many managed endpoints are connected and disconnected. This helps administrators quickly assess the overall availability of the managed endpoint population without manually reviewing every device. It complements more detailed endpoint statuses such as Online, Away, Offline, Never Seen, or Out-Of-Sync. If an unusually large number of endpoints suddenly appear disconnected, administrators can use this dashboard indicator as a starting point for investigating EMS connectivity, network changes, Telemetry service availability, DNS, or certificate problems.

Question 397. Before upgrading EMS 7.4 when it manages FortiClient versions older than 7.0, what does Fortinet require for those older clients?

  1. They must first be upgraded to FortiClient 7.0.7 or newer
  2. They must all be downgraded to FortiClient 6.4
  3. They must be converted to unmanaged clients
  4. No action is required because EMS 7.4 supports every historical FortiClient release

Correct Answer: 1. They must first be upgraded to FortiClient 7.0.7 or newer

Explanation:

Fortinet’s EMS 7.4 release guidance states that EMS 7.4 supports FortiClient branches 7.4, 7.2, and 7.0. Organizations managing significantly older clients must therefore upgrade those endpoints to FortiClient 7.0.7 or later before upgrading EMS to the 7.4 branch. This compatibility planning prevents endpoints from becoming unsupported after the management server upgrade. Administrators should always review the current compatibility matrix and recommended upgrade path because management-server and endpoint versions are interdependent and an unsupported combination may lose functionality or management support.

Question 398. What does Fortinet state about downgrading FortiClient EMS to a previous EMS version?

  1. Downgrading is supported only once
  2. Downgrading is supported when FortiAnalyzer is connected
  3. Downgrading is available only through the GUI
  4. Downgrading to previous EMS versions is not supported

Correct Answer: 4. Downgrading to previous EMS versions is not supported

Explanation:

Fortinet explicitly states that FortiClient EMS does not support downgrading to previous EMS versions. Administrators should therefore treat an EMS upgrade as a change that cannot simply be reversed by running an older installer. This makes pre-upgrade planning particularly important. Organizations should verify FortiClient compatibility, create a valid EMS database backup, consider a full server or VM backup where appropriate, review release notes, and test the target version before production rollout. Recovery should rely on documented backup and restoration strategies rather than an unsupported application downgrade.

Question 399. What happens if an EMS upgrade is attempted while the environment still uses an unsupported legacy 158 license?

  1. EMS automatically converts the license
  2. EMS upgrades but disables ZTNA
  3. The upgrade does not proceed and reports that the legacy license is unsupported
  4. The license automatically becomes a free trial

Correct Answer: 3. The upgrade does not proceed and reports that the legacy license is unsupported

Explanation:

Fortinet’s EMS 7.4 release notes state that legacy 158 licenses, which reached end of life, are not supported by EMS 7.4. When an upgrade is attempted while such licensing is present, the installer reports that the legacy license is not supported after upgrade and does not proceed. Similarly, migration from Windows-based EMS 7.2 to Linux-based EMS 7.4 can abort if unsupported legacy licensing is detected. Administrators should therefore review license eligibility before starting an EMS upgrade or migration rather than discovering the problem during the maintenance window.

Question 400. An organization wants to divide one EMS environment among several departments while preserving separation, delegated administration, centralized licensing, and compatible endpoint upgrades. Which design BEST meets the requirement?

  1. Use separate browser tabs for every department and share one administrator account
  2. Use one Default site with no access separation and manually track department endpoints
  3. Disable multitenancy and give every department Global administrator rights
  4. Enable EMS multitenancy, create separate sites, assign site-specific administrators and license allocations from Global, use site-aware FQDNs for Security Fabric connectors, and verify FortiClient compatibility before EMS upgrades

Correct Answer: 4. Enable EMS multitenancy, create separate sites, assign site-specific administrators and license allocations from Global, use site-aware FQDNs for Security Fabric connectors, and verify FortiClient compatibility before EMS upgrades

Explanation:

EMS multitenancy is designed for exactly this kind of administrative separation. Each department can receive its own isolated site and administrators restricted to that site, while Global administrators retain control of shared platform functions and license allocation. Security Fabric connectors identify the appropriate site through site-aware FQDNs. Endpoint data and configuration remain separated between tenants. Finally, upgrade planning must still account for EMS-to-FortiClient compatibility because multitenancy does not override version requirements. This provides centralized infrastructure while maintaining clear administrative and data boundaries among departments.