View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 281. An endpoint qualifies for both a user-based endpoint policy and a group-based endpoint policy in FortiClient EMS. Which policy takes precedence?
- The group-based policy always takes precedence
- The user-based policy takes precedence
- EMS merges both policies
- The policy created most recently takes precedence
Correct Answer: 2. The user-based policy takes precedence
Explanation:
FortiClient EMS supports policies assigned according to endpoint groups, user groups, and individual users. When the same endpoint qualifies for both a user-based policy and a group-based policy, EMS gives precedence to the user-based policy. This allows administrators to create exceptions or more specific configurations for individual users without restructuring broader device-group assignments. If no direct user policy exists, EMS can evaluate policies assigned to the applicable containers or groups and use priority to determine the result. Understanding this hierarchy is important when an endpoint receives a configuration different from the one expected from its device group alone.
Question 282. What does Fortinet recommend when using user-based endpoint policies on Windows devices?
- Enable Windows Fast Startup
- Disable FortiClient Telemetry
- Enable guest logon
- Disable Windows switch users functionality to help EMS apply the user-based policy correctly
Correct Answer: 4. Disable Windows switch users functionality to help EMS apply the user-based policy correctly
Explanation:
Fortinet recommends disabling the Windows switch users capability when administrators rely on user-based endpoint policies. User-based policy selection depends on EMS accurately associating the active user with the endpoint. Multiple simultaneously available Windows user sessions can complicate that association and cause unexpected policy behavior. Disabling user switching helps ensure that the identity used for policy selection corresponds to the currently intended endpoint user. This recommendation applies specifically to reliable user-based policy assignment and is separate from ordinary endpoint group policy behavior, licensing, or Windows authentication configuration.
Question 283. No policy is assigned directly to a FortiClient user. Multiple inherited policies apply through the user’s group containers. Which policy does EMS select?
- The applicable inherited policy with the highest global priority
- The oldest inherited policy
- Every inherited policy simultaneously
- The policy with the shortest name
Correct Answer: 1. The applicable inherited policy with the highest global priority
Explanation:
EMS follows a defined policy-selection process for Active Directory user and group assignments. If no policy is assigned directly to the FortiClient user, EMS evaluates applicable policies from the user’s group containers or user groups. When multiple inherited policies qualify, EMS applies the one with the highest global priority. This gives administrators predictable control over overlapping assignments. Troubleshooting should therefore include the user’s directory memberships, directly assigned policies, inherited policy candidates, and global priority ordering. Merely identifying one applicable group policy does not prove that it will become the effective policy.
Question 284. Who can enable or disable functions in FortiClient EMS Feature Select?
- Any endpoint user
- Any read-only EMS administrator
- An EMS superadministrator
- Only a FortiGate administrator
Correct Answer: 3. An EMS superadministrator
Explanation:
Fortinet restricts modification of Feature Select to an EMS superadministrator. Other EMS administrative users can view which features are enabled or disabled but cannot change the Feature Select configuration. Feature Select is significant because it controls which licensed EMS capabilities are exposed elsewhere in the interface. Disabling a feature can remove its endpoint-profile settings, dashboard widgets, logging configuration, or other related controls. Because these changes can have broad effects across endpoint management, Fortinet limits the ability to modify Feature Select to the highest EMS administrative role.
Question 285. Which statement BEST describes the relationship between EMS licensing and Feature Select?
- Only capabilities supported by the applied EMS license are available for enablement in Feature Select
- Feature Select ignores the EMS license
- Every FortiClient feature is always available regardless of license
- Feature Select automatically upgrades the organization’s license
Correct Answer: 1. Only capabilities supported by the applied EMS license are available for enablement in Feature Select
Explanation:
Feature Select does not bypass FortiClient EMS licensing. Fortinet states that only features included in the applied license are available for enablement. For example, an EMS deployment licensed only for ZTNA functionality cannot simply enable an EPP-only capability such as the full Firewall feature. Feature availability therefore depends first on the organization’s entitlement and then on the Feature Select configuration. When an administrator cannot locate an expected profile category or feature toggle, checking the EMS license should come before assuming that the GUI or installation is malfunctioning.
Question 286. What restriction applies when the Chromebook feature is enabled in EMS Feature Select?
- Malware Protection must be disabled
- Remote Access cannot be configured
- FortiAnalyzer integration becomes mandatory
- Web Filter cannot be disabled in Feature Select
Correct Answer: 4. Web Filter cannot be disabled in Feature Select
Explanation:
FortiClient EMS works with the FortiClient Web Filter extension to provide filtering for managed Chromebook users. Because Chromebook support depends on Web Filter functionality, Fortinet states that administrators cannot disable Web Filter when the Chromebook feature is enabled in Feature Select. This dependency ensures that enabling Chromebook management does not leave EMS in a configuration where the core functionality needed for those endpoints is unavailable. Administrators planning Chromebook deployment should therefore enable the required EMS Chromebook and web-filtering components and verify the related profile-server connectivity before onboarding devices.
Question 287. An administrator starts a Quick AV Scan from the EMS Endpoints pane. When does the scan normally begin on the selected endpoint?
- Immediately even if the endpoint is offline
- At the endpoint’s next FortiClient Telemetry communication
- Only after EMS restarts
- During the next license synchronization
Correct Answer: 2. At the endpoint’s next FortiClient Telemetry communication
Explanation:
EMS lets administrators remotely request both Quick and Full antivirus scans. Fortinet documents that the requested scan starts on the endpoint at its next FortiClient Telemetry communication. Therefore, an offline endpoint cannot process the request immediately. This is consistent with many other EMS remote actions that rely on the management channel between FortiClient and EMS. If a requested scan appears not to start, administrators should verify endpoint connectivity and Telemetry status before modifying the antivirus profile or reinstalling FortiClient.
Question 288. What happens when an EMS administrator chooses “Update Signatures” for a managed FortiClient endpoint?
- EMS downloads the signatures and permanently stores them in the endpoint database
- FortiAnalyzer pushes antivirus signatures to FortiClient
- FortiClient receives the request and downloads the signature updates from the Internet
- FortiGate must reboot before the update begins
Correct Answer: 3. FortiClient receives the request and downloads the signature updates from the Internet
Explanation:
The Update Signatures action lets EMS instruct a selected FortiClient endpoint to refresh its security signatures. Fortinet states that FortiClient receives the request and then downloads the required signatures from the Internet. EMS is therefore initiating the action rather than acting as the permanent storage source for all endpoint signatures in this workflow. If updating fails, administrators should verify both EMS-to-endpoint communication and the endpoint’s ability to reach the required FortiGuard update infrastructure. Signature update problems can exist even when Telemetry itself is healthy.
Question 289. Which EMS action should an administrator use when a discovered endpoint should remain visible in its environment but should not be actively managed by EMS?
- Revoke Client Certificate
- Quarantine
- Delete Device
- Exclude from Management
Correct Answer: 4. Exclude from Management
Explanation:
EMS includes an Exclude from Management action for endpoints, domains, or workgroups that should not participate in normal EMS management. This is different from deleting a device record, disconnecting FortiClient, or quarantining a device from network access. Administrators can right-click a domain or workgroup and exclude it, or select an individual endpoint and use the same management action. This is useful when directory discovery includes devices that the organization intentionally does not want EMS to control. The distinction helps keep management scope aligned with administrative requirements.
Question 290. What additional entitlement is required before an administrator can request FortiGuard Forensics Analysis for a suspected endpoint?
- A Forensics license applied to EMS
- A FortiMail license
- An unlimited FortiGate VDOM license
- A separate Active Directory license
Correct Answer: 1. A Forensics license applied to EMS
Explanation:
FortiGuard Forensics Analysis is not automatically available with every standard EMS deployment. Fortinet requires a Forensics license to be applied to EMS. The feature must also be enabled under Feature Select, and an appropriate System Settings profile must enable the forensics functionality for targeted endpoints. Once configured, administrators can request analysis of a suspected endpoint. The collected forensic information is uploaded for investigation by the Fortinet forensics team, which provides a verdict and a downloadable report. Licensing and endpoint-profile preparation must therefore occur before the feature can be used operationally.
Question 291. Which endpoint platforms are supported for on-premises EMS FortiGuard Forensics Analysis in current FortiClient 7.4 documentation?
- Android and iOS only
- Linux only
- Windows and macOS, with macOS support beginning with FortiClient 7.4.1
- Chromebook only
Correct Answer: 3. Windows and macOS, with macOS support beginning with FortiClient 7.4.1
Explanation:
Current Fortinet 7.4 documentation states that on-premises EMS can request forensic analysis for Windows and macOS endpoints. For macOS, FortiClient 7.4.1 and later support the forensic-analysis capability. This is important because older 7.4.0 documentation described the feature more narrowly, so administrators should use documentation matching the applicable FortiClient release. The Forensics license is still required, and the feature must be enabled and assigned through an appropriate EMS profile before analysis can be requested.
Question 292. In FortiGuard Forensics Analysis, what does a status of “Pending” mean?
- Fortinet has completed its final verdict
- EMS has submitted the request to FortiClient, but the forensic agent has not started running yet
- FortiClient has completed uploading forensic data
- The report has already been downloaded
Correct Answer: 2. EMS has submitted the request to FortiClient, but the forensic agent has not started running yet
Explanation:
Fortinet documents several stages in the forensic-analysis workflow. Pending means EMS has notified FortiClient that a forensic request exists, but the forensic agent has not started collecting information. Later states include Running, Collection Completed, Upload Started, Upload Completed, and Upload Failed. Understanding these states helps administrators determine where a forensic request is delayed. A Pending request may indicate that the endpoint has not yet processed the request or that the agent has not started, while Upload Failed indicates a later-stage problem involving transfer of collected forensic data.
Question 293. After Fortinet completes forensic analysis of an endpoint, how can the EMS administrator obtain the detailed findings?
- Download the completed forensic report from EMS and view the analyst verdict
- Read the results from DHCP logs
- Retrieve them only from FortiGate CLI
- Reinstall FortiClient to display the report
Correct Answer: 1. Download the completed forensic report from EMS and view the analyst verdict
Explanation:
Once the Fortinet forensics team completes its investigation, EMS makes the analysis results available to the administrator. Fortinet documents a Download Report option along with the analyst’s verdict in the endpoint’s forensic information. EMS can also filter endpoints according to forensic status and verdict, helping administrators track investigations across multiple devices. The report is the detailed output of the forensic service and is separate from ordinary FortiClient logs or the diagnostic-tool package. It can help incident responders understand the evidence collected from a suspected device and decide what remediation should follow.
Question 294. What is the default state of “Let EMS schedule automatic upgrade” in supported EMS 7.4 releases?
- Disabled permanently
- Available only in HA
- Available only with a Forensics license
- Enabled by default
Correct Answer: 4. Enabled by default
Explanation:
Fortinet’s EMS 7.4 automatic-upgrade improvements introduced the Let EMS schedule automatic upgrade control under EMS Settings. Fortinet states that this option is enabled by default. It allows EMS to schedule installation of a later patch within the current EMS release branch when one becomes available. Administrators can disable automatic scheduling if organizational change-control policy requires all upgrades to be initiated manually. Even when automatic scheduling is enabled, EMS provides upgrade information and allows administrators to review or adjust the scheduled maintenance timing.
Question 295. When a later patch of the current EMS release becomes available, what upgrade timing does EMS schedule by default?
- Exactly seven days later
- Immediately
- A date approximately 45 to 52 days in the future
- One year later
Correct Answer: 3. A date approximately 45 to 52 days in the future
Explanation:
Fortinet’s EMS automatic-upgrade mechanism schedules an available later patch approximately 45 to 52 days in the future by default. Fortinet distributes upgrade timing over about a week rather than upgrading all EMS installations simultaneously. This staged approach reduces the impact if an issue is discovered in the new patch. EMS displays information about the available upgrade and scheduled date, allowing administrators to upgrade immediately or choose a more convenient maintenance time. Organizations should still review compatibility, backups, change-control procedures, and release information before production upgrades.
Question 296. When EMS displays an automatic-upgrade notification, how far can an administrator reschedule the upgrade according to the EMS 7.4.3 improvement documentation?
- Up to 365 days
- Up to 45 days from the notification
- Only 24 hours
- It cannot be rescheduled
Correct Answer: 2. Up to 45 days from the notification
Explanation:
The EMS 7.4.3 automatic-upgrade improvements allow an administrator to choose Schedule Upgrade and reschedule the maintenance for up to 45 days from the notification. This provides flexibility for organizations that need to coordinate upgrades with formal maintenance windows, staffing availability, or change-management processes. Administrators can also choose to upgrade immediately. Although EMS assists with upgrade scheduling, organizations should still make appropriate database backups and confirm compatibility before maintenance, particularly when FortiClient endpoint versions or other integrated Fortinet products may be affected.
Question 297. What is the purpose of configuring a FortiClient installer for automatic endpoint upgrade through EMS?
- To automatically reinstall the EMS server
- To make FortiClient unmanaged after the first installation
- To replace FortiGuard signature updates
- To automatically upgrade deployed FortiClient endpoints when a newer applicable FortiClient version becomes available through EMS
Correct Answer: 4. To automatically upgrade deployed FortiClient endpoints when a newer applicable FortiClient version becomes available through EMS
Explanation:
EMS can create a FortiClient installer configured for automatic upgrade. After that installer has been deployed, FortiClient can automatically upgrade to a newer applicable version when the new version becomes available through EMS. This helps organizations keep large endpoint populations current without manually launching an upgrade on every device. Automatic endpoint upgrade is distinct from EMS server automatic upgrade and from antivirus or vulnerability signature updates. Administrators should test new FortiClient versions, review compatibility, and use deployment controls appropriately before broad production rollout.
Question 298. Why does an operating EMS periodically communicate with FortiCloud in the automatic-upgrade workflow?
- To retrieve entitlement status and information about the latest patch release
- To authenticate every endpoint user
- To replace the EMS PostgreSQL database
- To create FortiGate firewall policies
Correct Answer: 2. To retrieve entitlement status and information about the latest patch release
Explanation:
Fortinet states that EMS periodically contacts FortiCloud while operating so it can retrieve entitlement status and latest patch-release information. This communication enables EMS to determine whether a newer patch is available and supports the automatic-upgrade notification and scheduling process. Consequently, network restrictions preventing EMS from reaching required FortiCloud services can interfere with update awareness and automated upgrade workflows. This communication is different from FortiClient endpoint Telemetry, FortiGuard antivirus updates, or SAML authentication. Each uses separate services and should be troubleshot according to its specific purpose.
Question 299. An endpoint policy contains an Off-Fabric profile. What additional configuration does Fortinet recommend including in that policy?
- On-fabric detection rules
- A FortiAnalyzer administrator password
- A database backup schedule
- A Chromebook profile
Correct Answer: 1. On-fabric detection rules
Explanation:
An Off-Fabric profile defines configuration to apply when EMS determines that the endpoint is outside the trusted network context. Fortinet therefore recommends including on-fabric detection rules in a policy that uses an Off-Fabric profile. Those rules give EMS the information needed to distinguish on-fabric from off-fabric conditions reliably. Without suitable detection logic, the context that should determine which profile is appropriate may be ambiguous or ineffective. Organizations commonly use more restrictive settings for off-fabric endpoints, such as stronger remote-access or filtering requirements, making accurate fabric detection important to policy design.
Question 300. An administrator reports three issues: a user receives the wrong endpoint policy, an AV scan request has not started on an offline laptop, and an expected Firewall feature is missing from EMS. Which troubleshooting approach is BEST?
- Reinstall EMS immediately
- Delete all endpoint profiles and recreate them
- Check user-versus-group policy precedence and global priority, confirm Telemetry communication for the scan request, and verify both EMS licensing and Feature Select for the missing feature
- Disable FortiGuard and FortiCloud connectivity
Correct Answer: 3. Check user-versus-group policy precedence and global priority, confirm Telemetry communication for the scan request, and verify both EMS licensing and Feature Select for the missing feature
Explanation:
The three symptoms have different likely causes. A user receiving an unexpected policy should be investigated through EMS policy hierarchy: direct user policies take precedence over group-based policies, and priority resolves other applicable policies. A remote AV scan starts only when the endpoint next communicates with EMS, so an offline device will not process the request immediately. Finally, Feature Select exposes only features supported by the installed EMS license, so a missing Firewall option may be an entitlement or Feature Select issue. Addressing each symptom at its relevant layer is more effective than making broad configuration changes.