View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 201. After an installed FortiClient endpoint reboots or detects a network change, what is the FIRST EMS-location method in Fortinet’s documented Telemetry connection order?
- Query FortiAnalyzer for the nearest EMS
- Use the remembered Telemetry server list
- Scan the internet for an EMS server
- Use an EMS address manually entered by the endpoint user, if one has been provided
Correct Answer: 4. Use an EMS address manually entered by the endpoint user, if one has been provided
Explanation:
Fortinet documents an ordered process that FortiClient can use to locate EMS after reboot, network rejoin, or a network change. A manually entered EMS IP address or server information is considered before the Telemetry server list and remembered server information. If that method does not provide a usable EMS connection, FortiClient proceeds through its other discovery options. Understanding this sequence is useful when troubleshooting why a client connects to an unexpected EMS instance. Administrators should examine manually configured connection information before assuming that a Telemetry server list or remembered EMS entry is controlling the connection.
Question 202. How does FortiClient use an EMS Telemetry server list when one of the listed EMS addresses is in the same subnet as the endpoint?
- It ignores that EMS and chooses the last entry in the list
- It attempts to connect to the EMS in the list that is in the same subnet as the endpoint
- It always sends the connection through FortiGate first
- It selects an EMS randomly
Correct Answer: 2. It attempts to connect to the EMS in the list that is in the same subnet as the endpoint
Explanation:
When FortiClient evaluates its Telemetry server list, it looks for EMS addresses that are in the endpoint’s subnet. If it finds a matching EMS server, it attempts to use that server for the Telemetry connection. This behavior can help distributed environments steer clients toward an appropriate EMS address based on network location. If no EMS address in the list matches the local subnet, FortiClient uses a different fallback process. Administrators should therefore review both server-list order and subnet relationships when investigating unexpected EMS selection after an endpoint moves between networks.
Question 203. No EMS in the Telemetry server list belongs to the endpoint’s current subnet. What does FortiClient do next?
- It attempts to reach EMS servers in configured list order and uses the first reachable server
- It permanently disables Telemetry
- It waits until the endpoint returns to its original subnet
- It connects directly to FortiAnalyzer instead
Correct Answer: 1. It attempts to reach EMS servers in configured list order and uses the first reachable server
Explanation:
If FortiClient cannot find an EMS server from the Telemetry server list that belongs to the endpoint’s current subnet, it does not simply abandon the connection. Fortinet documents that FortiClient begins with the top of the configured list and attempts to connect to the first EMS server that is reachable. The order of entries therefore has operational significance. Administrators can use that ordering to influence preferred and fallback EMS connectivity. Incorrect list order can cause endpoints to select a functioning but undesired EMS when several servers are reachable from the same location.
Question 204. What is the purpose of the remembered Telemetry server list in FortiClient?
- To store FortiGate administrator passwords
- To maintain antivirus signatures
- To retain EMS server addresses previously learned so FortiClient can reuse them for later Telemetry connections
- To cache FortiAnalyzer reports
Correct Answer: 3. To retain EMS server addresses previously learned so FortiClient can reuse them for later Telemetry connections
Explanation:
FortiClient can be configured to remember EMS server addresses learned during previous Telemetry connections. These remembered server addresses provide another way for FortiClient to reconnect after events such as rebooting, rejoining the network, or moving to a different network. The remembered list is used after higher-priority connection methods in the documented connection sequence. This feature improves resilience by allowing FortiClient to reuse known management-server information rather than requiring manual EMS entry every time network conditions change. It should not be confused with VPN gateway information, FortiGuard addresses, or FortiAnalyzer destinations.
Question 205. In an EMS-managed FortiClient environment, who controls the management connection between FortiClient and EMS?
- The local endpoint user exclusively
- EMS
- FortiAnalyzer
- The DNS server
Correct Answer: 2. EMS
Explanation:
Fortinet states that EMS controls the connection between an EMS-managed FortiClient endpoint and EMS. When FortiClient is centrally managed, configuration is locked to prevent the endpoint user from freely changing management settings. To intentionally disconnect a managed FortiClient endpoint from EMS, the administrator performs the action from EMS rather than relying on the endpoint user to break the management relationship locally. This centralized control helps preserve endpoint-policy enforcement and prevents users from bypassing enterprise settings simply by disconnecting FortiClient from its management server.
Question 206. What can an EMS administrator do with a rogue endpoint that should never be permitted to reconnect to EMS?
- Only hide it from the endpoint list
- Move it to FortiAnalyzer
- Change its Web Filter category
- Disconnect it and prevent it from reconnecting to EMS
Correct Answer: 4. Disconnect it and prevent it from reconnecting to EMS
Explanation:
Fortinet’s Telemetry security guidance specifically allows administrators to disconnect a rogue endpoint and prevent that endpoint from reconnecting to EMS in the future. This is stronger than merely showing the endpoint as offline or temporarily stopping a Telemetry session. It provides a management-security control for devices that should no longer participate in the organization’s EMS environment. Such an action may be appropriate when an endpoint is unauthorized, retired, compromised, or incorrectly registered. Administrators should distinguish blocking future EMS registration from network quarantine, because quarantine addresses endpoint network access while management disconnection addresses the EMS relationship itself.
Question 207. Which statement correctly describes how FortiClient configuration is handled when EMS is integrated with FortiGate?
- EMS provides the endpoint profile; FortiGate does not provide FortiClient’s configuration profile
- FortiGate replaces EMS and directly provisions all FortiClient settings
- FortiAnalyzer becomes the FortiClient configuration server
- Endpoint users must manually reproduce FortiGate settings in FortiClient
Correct Answer: 1. EMS provides the endpoint profile; FortiGate does not provide FortiClient’s configuration profile
Explanation:
Even when EMS participates in a Fortinet Security Fabric with FortiGate, EMS remains responsible for FortiClient endpoint provisioning. FortiClient connects to EMS and receives its endpoint profile as part of an endpoint policy. FortiGate can consume endpoint information and dynamic endpoint groups from EMS and use those details for network-security decisions, but Fortinet explicitly notes that FortiGate does not provide FortiClient configuration information. Understanding this separation of responsibilities is important for troubleshooting: a wrong FortiClient profile should be investigated in EMS, while an incorrect posture-based firewall decision may require checking FortiGate integration.
Question 208. Which endpoint information can EMS provide to FortiOS as part of Security Fabric integration?
- Only the EMS license count
- Only antivirus scan history
- Information such as logged-in user details, MAC address, OS information, FortiClient version, and FortiClient UUID
- Only FortiClient installer filenames
Correct Answer: 3. Information such as logged-in user details, MAC address, OS information, FortiClient version, and FortiClient UUID
Explanation:
EMS can share substantial endpoint context with FortiOS. Fortinet lists information including the logged-in username, full name, email address, phone number, avatar information, social-network account IDs, MAC address, operating-system type and version, FortiClient version, and FortiClient UUID. This information helps FortiGate make network decisions using richer endpoint context than a simple IP address. Security Fabric integration therefore combines EMS’s endpoint knowledge with FortiGate’s enforcement capabilities. Administrators troubleshooting missing endpoint context on FortiGate should verify the EMS connector and synchronization path rather than expecting FortiClient to provide its complete configuration directly to FortiGate.
Question 209. Which endpoint changes can cause EMS to notify FortiGate through its websocket integration so FortiOS loads updated information?
- Changes to system information, user avatar, vulnerabilities, or security posture tags
- Only changes to the EMS administrator password
- Only changes to the FortiClient installer package
- Only SMTP configuration changes
Correct Answer: 1. Changes to system information, user avatar, vulnerabilities, or security posture tags
Explanation:
FortiGate maintains a websocket relationship with EMS in supported Security Fabric integrations. EMS can notify FortiGate when important endpoint information changes, including system information, user-avatar information, vulnerabilities, and security posture tags. FortiOS can then load the updated endpoint information without waiting for an unrelated management event. This supports timely posture-aware enforcement, particularly when vulnerability or security-tag state changes. Administrators investigating stale endpoint information in FortiGate should therefore consider websocket and EMS connector connectivity in addition to FortiClient Telemetry itself.
Question 210. Which protocol and default port does FortiClient use to upload logs and Windows host events directly to FortiAnalyzer or FortiManager?
- UDP 53
- TCP 443
- UDP 161
- TCP 514
Correct Answer: 4. TCP 514
Explanation:
Fortinet’s FortiClient required-services documentation identifies TCP port 514 for uploading FortiClient logs and Windows host events to FortiAnalyzer or FortiManager. This is separate from FortiClient Telemetry to EMS on TCP 8013 and separate from the EMS-to-FortiOS integration ports used for Security Fabric functions. Administrators troubleshooting missing endpoint logs should therefore distinguish between the path used for management traffic and the path used for centralized logging. A functioning EMS connection does not prove that FortiAnalyzer log forwarding is reachable, because these flows can use different destinations and ports.
Question 211. Which protocol and default port does FortiClient use to send files directly to an on-premises FortiSandbox for analysis according to the required-services table?
- TCP 514
- UDP 500
- TCP 8013
- TCP 10443
Correct Answer: 2. TCP 514
Explanation:
Fortinet’s FortiClient required-services table lists TCP 514 for sending files to FortiSandbox for analysis. Administrators should not confuse this with TCP 10443 for EMS deployment-package downloads, TCP 8013 for FortiClient Telemetry, or UDP 500 used by IKE in IPsec VPN connections. Network-security devices between FortiClient and FortiSandbox must permit the required traffic if direct sandbox integration is expected to work. If file submission fails while other FortiClient functions remain healthy, checking the FortiSandbox destination and corresponding network path is a logical troubleshooting step.
Question 212. Which ports are associated with EMS SCEP services used for installing a ZTNA certificate?
- TCP 25 and 110
- TCP 8013 and 8015
- TCP 4001 and 4002
- UDP 500 and 4500
Correct Answer: 3. TCP 4001 and 4002
Explanation:
Fortinet’s EMS required-services documentation lists ports 4001 and 4002 for the SCEP service used in installing zero-trust network access certificates. ZTNA certificate provisioning is different from FortiClient Telemetry, FortiOS-to-EMS communication, and VPN transport. Therefore, an endpoint can potentially communicate successfully with EMS for normal management while certificate enrollment fails because the required SCEP path is blocked. When troubleshooting ZTNA certificate-installation issues, administrators should verify SCEP reachability and certificate-service configuration rather than focusing only on the standard TCP 8013 management connection.
Question 213. Which default port is associated with a Chromebook connecting to the EMS profile server?
- TCP 8443
- TCP 22
- TCP 10443
- UDP 8888
Correct Answer: 1. TCP 8443
Explanation:
Fortinet’s EMS required-services documentation identifies TCP 8443 as the default port used when a Chromebook connects to the EMS profile server. The connection information is configured through the Google Admin console when the profile is added. This is distinct from standard FortiClient Telemetry for desktop endpoints and highlights the importance of platform-specific connectivity requirements. Administrators managing a mixed endpoint population should not assume that every operating system uses identical management-service ports. If Chromebook profile connectivity fails, TCP 8443 and the corresponding Google Admin configuration should be checked.
Question 214. Which EMS service uses TCP 443 outbound to forticlient-rs.forticloud.com?
- LDAP synchronization
- Creating installers on Fortinet-hosted servers and downloading them to EMS
- FortiClient Telemetry
- Local PostgreSQL replication
Correct Answer: 2. Creating installers on Fortinet-hosted servers and downloading them to EMS
Explanation:
EMS can use Fortinet-hosted infrastructure to create FortiClient installers. Fortinet documents forticlient-rs.forticloud.com over TCP 443 for creating installers on Fortinet-hosted servers and downloading the completed packages to EMS for deployment. This means an EMS server that otherwise has working endpoint management can still encounter installer-creation problems if its outbound access to the required FortiCloud destination is blocked. Administrators operating highly restricted networks should review all EMS external connectivity requirements before assuming that only licensing and FortiGuard addresses need internet access.
Question 215. Which protocol and port are used by legacy FortiGuard URL rating from FortiClient by default?
- TCP 8013
- TCP 10443
- UDP 8888
- UDP 4500
Correct Answer: 3. UDP 8888
Explanation:
Fortinet documents UDP port 8888 as the default for legacy FortiGuard URL-rating communication. FortiClient can alternatively use FortiGuard Anycast, which uses TCP 443 for URL rating. Administrators can select the appropriate FortiGuard mode in Web Filter configuration. This difference matters during troubleshooting because a firewall that allows HTTPS to FortiGuard Anycast does not automatically prove that legacy UDP rating traffic is permitted, and the reverse is also true. Understanding which rating mode the profile uses helps identify the correct destinations, protocols, and ports to test.
Question 216. Which ports are normally associated with FortiClient IPsec VPN establishment?
- TCP 80 and 443 only
- UDP 500, ESP IP protocol 50, and UDP 4500 for NAT-T
- TCP 8013 and 8015
- UDP 514 only
Correct Answer: 2. UDP 500, ESP IP protocol 50, and UDP 4500 for NAT-T
Explanation:
Fortinet’s FortiClient required-services documentation lists the standard IPsec connectivity components: UDP 500 for IKE, ESP using IP protocol 50, and UDP 4500 for NAT Traversal. These differ from SSL VPN, which commonly uses TCP 443, and from EMS management communication. When an IPsec tunnel is correctly provisioned in an EMS Remote Access profile but cannot establish, administrators should check whether the network permits the required IKE, ESP, and NAT-T traffic. If the client is behind NAT, UDP 4500 is particularly relevant because IPsec traffic commonly transitions to NAT-T.
Question 217. FortiClient connects to EMS after installation and successfully downloads its endpoint policy. What user-visible confirmation can appear?
- A system-tray bubble message indicating that the download is complete
- A FortiGate reboot notification
- An Active Directory password-reset window
- A FortiAnalyzer upgrade prompt
Correct Answer: 1. A system-tray bubble message indicating that the download is complete
Explanation:
After FortiClient Telemetry successfully connects to EMS, FortiClient receives an endpoint policy. That policy may contain endpoint-profile configuration as well as a Telemetry server list. Fortinet documents that a system-tray bubble message can appear when the policy download completes. This is useful during onboarding because it provides an endpoint-side indication that EMS registration and initial policy delivery have progressed successfully. If the endpoint connects but never receives expected settings, administrators should verify whether the endpoint policy is eligible, enabled, and delivered through Telemetry rather than assuming registration alone guarantees complete configuration.
Question 218. Which file type is used as the EMS 7.4 Linux installation package when performing an EMS upgrade through emscli?
- .msi
- .exe
- .pkg
- .bin
Correct Answer: 4. .bin
Explanation:
FortiClient EMS 7.4 uses Linux-based installation packages with a .bin extension for documented EMS upgrades. Fortinet’s upgrade guidance shows version-specific AMD64 and ARM64 .bin files downloaded from the Fortinet Support site and then supplied to the execute upgrade ems command. The file may be used from a local path or copied from a remote host. This is different from older Windows-based EMS generations and reinforces why administrators must follow the 7.4 Linux-specific maintenance procedures instead of expecting an MSI or Windows executable upgrade workflow.
Question 219. Which remote copy services does the execute upgrade ems command support when obtaining an EMS installation file from another host?
- HTTP only
- SCP, FTP, or SFTP
- SMB only
- TFTP only
Correct Answer: 2. SCP, FTP, or SFTP
Explanation:
The EMS CLI reference documents SCP, FTP, and SFTP as supported remote copy services for the execute upgrade ems workflow. SCP is the default remote copy service. The administrator provides the path to the installation file, remote host address, credentials, and—when necessary—the remote port. The documented default remote ports are 22 for SCP/SFTP and 21 for FTP. This flexibility allows administrators to stage the EMS .bin upgrade package on another system and have EMS retrieve it rather than requiring the package to already exist on the EMS host.
Question 220. A remote endpoint can browse the internet and establish an SSL VPN, but it cannot receive EMS policies. FortiAnalyzer logs are also absent. Which troubleshooting approach is BEST?
- Rebuild every endpoint profile immediately
- Assume SSL VPN proves all Fortinet services are reachable
- Verify each required path independently—such as TCP 8013 for EMS Telemetry and TCP 514 for FortiAnalyzer logging—because successful TCP 443 VPN connectivity does not validate those separate services
- Disable all endpoint security modules
Correct Answer: 3. Verify each required path independently—such as TCP 8013 for EMS Telemetry and TCP 514 for FortiAnalyzer logging—because successful TCP 443 VPN connectivity does not validate those separate services
Explanation:
FortiClient uses different network services for different functions. SSL VPN commonly uses TCP 443, FortiClient Telemetry to EMS uses TCP 8013 by default, and FortiAnalyzer or FortiManager log upload uses TCP 514. Therefore, successful SSL VPN connectivity proves only that the VPN path is working; it does not establish that EMS management or logging destinations are reachable. When multiple functions fail, administrators should map each feature to its destination, protocol, and port, then test those paths independently. Rebuilding valid EMS policies before confirming connectivity can introduce unnecessary configuration changes and obscure the original problem.