Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.


Question 221. Starting with EMS 7.4.5, what capability is available for protecting the EMS database without relying on an external cron job?

  1. Automatic database replication to every endpoint
  2. Automatic export to FortiAnalyzer only
  3. Scheduled EMS database backups configured directly in EMS
  4. Continuous database backup to FortiGate flash storage

Correct Answer: 3. Scheduled EMS database backups configured directly in EMS

Explanation:

Starting with EMS 7.4.5, administrators can configure scheduled database backups directly under System Settings > EMS Settings > Scheduled Backup. Fortinet recommends using this built-in scheduled-backup functionality for automated EMS database protection. Administrators can determine how frequently backups occur and whether the resulting files are stored locally or sent to a supported remote server. Earlier environments could automate backups with operating-system tools such as cron jobs, but the integrated scheduling capability simplifies routine backup administration. Regular database backups are important because EMS contains endpoint-management configuration, policies, profiles, administrative data, and other critical management information.

Question 222. Which schedule types are supported by the EMS 7.4.5 scheduled database backup feature?

  1. Daily, weekly, and monthly
  2. Hourly only
  3. Quarterly and yearly only
  4. Every five minutes only

Correct Answer: 1. Daily, weekly, and monthly

Explanation:

The built-in scheduled-backup feature supports daily, weekly, and monthly schedules. Administrators can define the interval appropriate to each schedule type. For example, a weekly schedule can specify how many weeks should pass between backups and which days of the week the backup should occur. EMS also allows the administrator to specify the starting time in UTC. The selected schedule should reflect the organization’s recovery objectives, rate of configuration change, available storage, and operational requirements. Frequent backups reduce the amount of recent EMS configuration that could be lost following a database failure.

Question 223. Which remote protocols can EMS use to store scheduled database backups on an external server?

  1. HTTP and HTTPS only
  2. SMB and NFS only
  3. FTP and TFTP only
  4. SCP or SFTP**

Correct Answer: 4. SCP or SFTP

Explanation:

For built-in scheduled backups, EMS supports storing the backup on a remote server by using SCP or SFTP. The administrator supplies information such as the remote server address, username, password, backup path, and other required connection settings. The account used for the backup must have permission to write to the selected remote location. Keeping backups on a separate system can improve recoverability because the backup remains available even if the EMS server itself becomes unavailable. Organizations should also protect remote credentials and backup files according to their security policies.

Question 224. Which two backup output formats can an administrator select when manually backing up the EMS database from the System Information widget?

  1. ISO or TAR
  2. Database or Zip
  3. MSI or EXE
  4. CSV or XML

Correct Answer: 2. Database or Zip

Explanation:

When creating an EMS database backup from the System Information widget, the administrator can select Database or Zip as the compression type. The Database option produces the EMS database backup format, while Zip packages the backup as a compressed archive. The administrator also supplies and confirms a password, which is later required when restoring the database. Backups should be stored securely because they may contain sensitive management configuration and endpoint-related information. Administrators should also periodically validate their restore procedures instead of assuming that successful backup creation alone guarantees recoverability.

Question 225. What credential is required when restoring an EMS database backup through the GUI?

  1. The password that was assigned when the database backup was created
  2. The FortiGate administrator password
  3. The endpoint user’s Windows password
  4. The EMS license registration code

Correct Answer: 1. The password that was assigned when the database backup was created

Explanation:

When an EMS database backup is created, the administrator specifies a backup password. During restoration, EMS requires that same password before the database can be restored. This protects the backup and prevents unauthorized restoration of its contents. The restore workflow is available from the System Information widget, where the administrator selects the backup file, enters the original backup password, and starts restoration. After the database has been restored, EMS needs time to reload the restored information before normal administration resumes. The backup password is unrelated to FortiGate credentials or endpoint user passwords.

Question 226. Beginning with EMS 7.4.4, which database-restore capability is supported?

  1. Restoring only between identical standalone servers
  2. Restoring only from HA to HA
  3. Restoring only from Linux to Windows EMS
  4. Restoring across deployment models, such as standalone EMS to EMS HA or vice versa**

Correct Answer: 4. Restoring across deployment models, such as standalone EMS to EMS HA or vice versa

Explanation:

Fortinet documents that starting with EMS 7.4.4, database restoration can occur across different deployment models. For example, administrators can restore a backup from a standalone EMS into an EMS HA setup or restore from an HA environment into a standalone deployment. This is an improvement over earlier 7.4 behavior, where cross-model restoration had limitations. The capability provides greater flexibility for disaster recovery, architecture changes, and migration planning. Administrators should still use a supported version-specific restoration procedure and confirm database compatibility before making a production architecture change.

Question 227. When using the EMS CLI execute restore command with a local backup file, where must the file be located according to the documented 7.4.4 CLI workflow?

  1. /tmp
  2. /exchange
  3. /var/www
  4. /home/admin

Correct Answer: 2. /exchange

Explanation:

In the documented EMS 7.4.4 CLI restore workflow, a backup specified with the –local.file option must be located in the /exchange directory. The execute restore command can restore backups from either local or remote locations. When restoring remotely, administrators provide the remote server information and select a supported copy service such as SCP, FTP, or SFTP. Knowing the required local path prevents restore attempts from failing because the backup file exists on the EMS server but is stored outside the location accepted by the command.

Question 228. Which statement about deleting an endpoint from FortiClient EMS is correct?

  1. Any registered domain endpoint can always be deleted directly
  2. EMS deletes endpoints only after FortiGate approval
  3. The Delete Device option is available for disconnected non-domain devices
  4. Deleting an endpoint automatically uninstalls FortiClient from every device

Correct Answer: 3. The Delete Device option is available for disconnected non-domain devices

Explanation:

Fortinet documents that administrators can delete disconnected non-domain devices from EMS. If the endpoint is still registered, the administrator should disconnect it first and then use Action > Delete Device. The deletion option is not a general mechanism for removing every domain-managed endpoint from directory-based management, nor does deleting the EMS record automatically uninstall FortiClient software from the operating system. Administrators should distinguish between deleting an EMS record, deregistering an endpoint, uninstalling FortiClient, and removing a device from a directory environment because each operation has a different purpose.

Question 229. An administrator selects “Deregister” for an online FortiClient endpoint in EMS. When does EMS perform the disconnection?

  1. At the endpoint’s next FortiClient Telemetry communication
  2. Only after EMS reboots
  3. Exactly 24 hours later
  4. Only after FortiAnalyzer confirms the request

Correct Answer: 1. At the endpoint’s next FortiClient Telemetry communication

Explanation:

When an administrator chooses Deregister, EMS disconnects the endpoint during the endpoint’s next FortiClient Telemetry communication. This behavior is similar to other EMS remote actions that depend on the endpoint communicating with its management server. After deregistration, FortiClient can later be manually reconnected to EMS if appropriate. Deregistration should not be confused with network quarantine or deleting the endpoint record. Quarantine restricts network access, while deregistration terminates the FortiClient-to-EMS management relationship. If an endpoint is offline, the deregistration command cannot reach the device until management communication resumes.

Question 230. Which EMS endpoint action requests FortiClient log files from a managed device for troubleshooting?

  1. Clear Events
  2. Request FortiClient Logs
  3. Set Importance
  4. Mark as Uninstalled

Correct Answer: 2. Request FortiClient Logs

Explanation:

The EMS Endpoints pane includes Request FortiClient Logs as a remote action. This allows administrators to obtain FortiClient-generated logs from a managed endpoint for troubleshooting. EMS also provides separate actions for requesting diagnostic results and downloading available logs or diagnostic packages. These capabilities are useful when investigating endpoint-specific problems such as policy application, VPN behavior, Web Filter issues, or communication errors. Administrators should select the action that corresponds to the information they need rather than assuming normal EMS server logs contain all endpoint-level diagnostic data.

Question 231. Which EMS endpoint action is designed to obtain a broader diagnostic package rather than ordinary FortiClient log files?

  1. Set Custom Tags
  2. Update Signatures
  3. Request Diagnostic Results
  4. Move To

Correct Answer: 3. Request Diagnostic Results

Explanation:

Request Diagnostic Results instructs a managed endpoint to generate a diagnostic package containing information useful for deeper FortiClient troubleshooting. This is separate from Request FortiClient Logs, which focuses on client logs. EMS also provides options to download available diagnostic results after they have been generated and uploaded. Diagnostic packages can provide broader system and FortiClient state information and are often useful when escalating a difficult issue to Fortinet support. Because these remote requests depend on endpoint communication, an offline endpoint may not immediately process the request.

Question 232. What happens when an EMS administrator uses “Revoke Client Certificate” on a supported endpoint?

  1. EMS removes the endpoint’s Windows login certificate permanently with no replacement
  2. FortiGate licensing is revoked
  3. Only the VPN password is cleared
  4. EMS revokes the FortiClient ZTNA certificate and prompts FortiOS and FortiClient to establish a new certificate signing request**

Correct Answer: 4. EMS revokes the FortiClient ZTNA certificate and prompts FortiOS and FortiClient to establish a new certificate signing request

Explanation:

The Revoke Client Certificate action is used when the ZTNA certificate held by FortiClient may be compromised or should no longer be trusted. Fortinet states that after revocation, EMS prompts FortiOS and FortiClient with a new certificate-signing request so a replacement trust relationship can be established. This action is available when the relevant ZTNA or EPP licensing is present. The certificate is used when FortiClient securely tunnels TCP application traffic through HTTPS to FortiGate in ZTNA workflows, so certificate integrity is essential to device trust.

Question 233. What does the “Delete Stale Verified Users” endpoint action do?

  1. Deletes all EMS administrator accounts
  2. Removes stale verified users while retaining the last-seen record for each machine user
  3. Revokes every FortiClient license assigned to the device
  4. Deletes the device from Active Directory

Correct Answer: 2. Removes stale verified users while retaining the last-seen record for each machine user

Explanation:

The Delete Stale Verified Users action cleans up older verified-user records associated with an endpoint. Fortinet explains that EMS keeps the most recently seen record for each machine user while removing stale verified-user entries. For example, if multiple users have onboarded through FortiClient on the same endpoint, older records can be removed. Importantly, Fortinet notes that this operation does not affect license seats. It is therefore an identity-record maintenance operation rather than a licensing or directory-account deletion function.

Question 234. What is the primary purpose of the FortiClient EMS REST API?

  1. To perform configuration operations on EMS programmatically
  2. To replace FortiClient antivirus signatures
  3. To provide IPsec encryption between endpoints
  4. To configure only the PostgreSQL database

Correct Answer: 1. To perform configuration operations on EMS programmatically

Explanation:

The FortiClient EMS API allows administrators and integrations to perform EMS configuration operations programmatically rather than relying exclusively on the graphical interface. Fortinet provides API documentation through the FortiAPI section of the Fortinet Developer Network. API access can support automation, integration with external systems, and repeatable administrative workflows. It should be protected with appropriate authentication and least-privilege controls because programmatic configuration access can affect managed endpoints and EMS settings. The API complements rather than replaces FortiClient Telemetry, which is the endpoint-management communication channel between FortiClient and EMS.

Question 235. Where does Fortinet direct administrators to view detailed FortiClient EMS API documentation?

  1. The FortiGate routing monitor
  2. The Microsoft Entra portal
  3. The FortiAPI tab on the Fortinet Developer Network
  4. The FortiClient endpoint log viewer

Correct Answer: 3. The FortiAPI tab on the Fortinet Developer Network

Explanation:

Fortinet’s EMS documentation states that detailed API information is available through the FortiAPI tab on FNDN, the Fortinet Developer Network. The EMS Administration Guide confirms that the REST API can perform configuration operations but refers administrators to FNDN for the detailed interface documentation. This separation allows Fortinet to maintain developer-oriented specifications independently of the general administration guide. Administrators planning automation should use the current API documentation that matches the EMS version they operate and should test programmatic changes in a controlled environment before applying them to production.

Question 236. When can an administrator manually renew an ACME certificate from the EMS Server Certificates page?

  1. Only after the certificate has been expired for 90 days
  2. When the ACME certificate is within 30 days of expiration
  3. Only when every endpoint is offline
  4. Only during EMS license renewal

Correct Answer: 2. When the ACME certificate is within 30 days of expiration

Explanation:

FortiClient EMS supports ACME-managed server certificates, including certificates from services such as Let’s Encrypt. Fortinet states that when an ACME certificate becomes eligible for renewal—specifically, when it is within 30 days of expiration—the administrator can select it on the EMS Server Certificates page and initiate renewal. Timely certificate renewal prevents HTTPS, installer-download, Telemetry, or other EMS services from presenting an expired certificate. ACME is designed to simplify certificate lifecycle management, but administrators should still monitor certificate status and verify that required ACME network connectivity remains available.

Question 237. Which EMS service normally uses the configured endpoint-control certificate on TCP 8013?

  1. FortiClient endpoint-control/Telemetry service
  2. Chromebook profile service
  3. Installer download service
  4. EMS administrative GUI

Correct Answer: 1. FortiClient endpoint-control/Telemetry service

Explanation:

Fortinet maps the EMS Endpoint Control daemon to TCP 8013, the default port used for FortiClient endpoint management and Telemetry. EMS allows administrators to configure the certificate used by this service. Other EMS services use different ports and may use different certificate selections: the administrative web GUI commonly uses TCP 443, installer downloads use TCP 10443, FortiOS websocket notifications use TCP 8015, and the Chromebook profile service uses TCP 8443. Understanding which certificate protects each EMS service is useful when certificate trust problems affect only one component.

Question 238. Which System Settings option permits a Windows user with appropriate administrative privileges to shut down FortiClient while it is registered to EMS?

  1. Hide System Tray Icon
  2. Do Not Allow User to Back Up Configuration
  3. Show Host Tag on FortiClient GUI
  4. Allow User to Shutdown When Registered to EMS**

Correct Answer: 4. Allow User to Shutdown When Registered to EMS

Explanation:

The Allow User to Shutdown When Registered to EMS option controls whether a user can shut down FortiClient while the client remains registered with EMS. Fortinet specifies that this feature is available for FortiClient Windows and that the user must have administrative privileges to perform the shutdown. In a tightly controlled enterprise environment, administrators may prefer to prevent users from stopping FortiClient because doing so could temporarily interrupt endpoint-security enforcement. The setting should therefore reflect the organization’s balance between local administrative flexibility and continuous endpoint protection.

Question 239. What does the “Hide System Tray Icon” setting do on a managed FortiClient endpoint?

  1. Disables FortiClient Telemetry
  2. Deletes FortiClient from the endpoint
  3. Hides the FortiClient icon from the operating system’s system tray
  4. Prevents EMS administrators from seeing the endpoint

Correct Answer: 3. Hides the FortiClient icon from the operating system’s system tray

Explanation:

Hide System Tray Icon is a FortiClient System Settings option that removes the FortiClient tray icon from the endpoint user’s normal desktop interface. This can reduce user interaction with FortiClient in managed environments where endpoint configuration is centrally controlled. Hiding the icon does not uninstall FortiClient, disable Telemetry, or remove the endpoint from EMS management. Administrators should distinguish interface-visibility controls from actual service or security-feature controls. FortiClient can continue enforcing its assigned EMS profiles while its tray icon is hidden from the user.

Question 240. An organization wants recoverable EMS configuration, automated administration, protected ZTNA certificate handling, and clean removal of a retired non-domain endpoint. Which approach BEST meets these requirements?

  1. Configure scheduled EMS database backups, use the EMS REST API with appropriate controls, revoke compromised client certificates when required, deregister a retired endpoint, and delete the disconnected non-domain device from EMS
  2. Depend only on endpoint-local configuration backups and never back up EMS
  3. Delete endpoints while they are registered and reuse compromised certificates
  4. Disable all EMS certificates before using API automation

Correct Answer: 1. Configure scheduled EMS database backups, use the EMS REST API with appropriate controls, revoke compromised client certificates when required, deregister a retired endpoint, and delete the disconnected non-domain device from EMS

Explanation:

The scenario combines several different EMS operational responsibilities. Scheduled database backups protect critical EMS configuration and simplify recovery. The EMS REST API supports controlled automation of configuration operations. ZTNA client certificates should be revoked when they are compromised so FortiClient and FortiOS can establish replacement certificate trust. Finally, a retired non-domain endpoint that is still registered should first be deregistered; once disconnected, its device record can be deleted from EMS. Treating backup, automation, certificate security, and endpoint lifecycle as separate but coordinated tasks provides a more reliable and secure management design.