View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 361. What is the default number of unsuccessful administrator login attempts before FortiClient EMS locks the administrator account temporarily?
- One attempt
- Five attempts
- Three attempts
- Ten attempts
Correct Answer: 3. Three attempts
Explanation:
FortiClient EMS includes an administrator lockout mechanism designed to reduce the risk of repeated password-guessing attempts against the management interface. The Admin Lockout Attempt setting specifies how many unsuccessful login attempts are allowed before EMS temporarily locks the administrator. Fortinet documents the default value as three attempts, while the setting can be increased up to the supported maximum. Administrators should combine account lockout with strong credentials, role-based permissions, secure HTTPS access, and appropriate session controls. A lockout is temporary and is governed separately by the configured Admin Lockout Period.
Question 362. What is the maximum value that can be configured for Admin Lockout Attempt in EMS?
- 10 attempts
- 20 attempts
- 50 attempts
- Unlimited attempts
Correct Answer: 1. 10 attempts
Explanation:
FortiClient EMS allows administrators to customize how many failed sign-in attempts trigger temporary account lockout. Fortinet documents a maximum value of 10 unsuccessful attempts. Increasing the threshold can reduce accidental lockouts caused by mistyped passwords, while a lower value provides stronger resistance to repeated guessing attempts. The setting should be selected according to organizational security policy. Administrators should also understand that the lockout threshold operates together with the Admin Lockout Period, which determines how long the administrator remains unable to sign in after reaching the configured failure threshold.
Question 363. What happens if an administrator attempts to log in during an active EMS Admin Lockout Period using the correct password?
- The login succeeds because the password is correct
- EMS immediately disables the account permanently
- EMS changes the administrator password
- The login still fails, and the lockout period restarts**
Correct Answer: 4. The login still fails, and the lockout period restarts
Explanation:
During the configured EMS administrator lockout period, login attempts do not succeed even when the administrator provides the correct credentials. Fortinet further documents that each login attempt made during the lockout period causes that period to reset and begin again. Administrators should therefore avoid repeatedly retrying credentials while an account is known to be locked because doing so can prolong the lockout. Once the configured lockout time passes without further login attempts, EMS resets the temporary lockout and permits the administrator to attempt authentication again.
Question 364. What happens after the configured EMS Admin Lockout Period expires?
- The administrator must reinstall EMS
- The temporary lockout resets and the administrator can attempt to log in again
- The account is permanently deleted
- EMS automatically grants Super administrator privileges
Correct Answer: 2. The temporary lockout resets and the administrator can attempt to log in again
Explanation:
EMS administrator lockout is intended to be temporary. After the configured Admin Lockout Period expires, the lockout resets and the administrator can attempt to sign in again. If the administrator subsequently reaches the configured failed-attempt threshold again, another lockout period begins. This behavior allows EMS to slow repeated guessing attacks without permanently removing the account. Administrators should distinguish this temporary failed-login lockout from other account controls, such as automatically disabling administrator accounts after a configured number of inactive days.
Question 365. What does “Expire login session after x minutes” control in EMS Admin User Settings?
- How long an inactive EMS administrator session can remain logged in before automatic logout
- How long FortiClient VPN sessions stay connected
- How long antivirus signatures remain valid
- How long an endpoint remains quarantined
Correct Answer: 1. How long an inactive EMS administrator session can remain logged in before automatic logout
Explanation:
The Expire login session after x minutes setting controls administrator web-session inactivity. If an EMS administrator remains inactive for longer than the configured number of minutes, EMS automatically logs that user out. This helps reduce the risk of an unattended management session remaining accessible indefinitely. Fortinet also permits a value of zero, which keeps inactive users logged in indefinitely. In security-sensitive environments, administrators generally use a finite timeout appropriate to their operational requirements. This setting affects the EMS administrator interface, not FortiClient VPN sessions, endpoint Telemetry, or antivirus functionality.
Question 366. What does configuring the EMS administrator session inactivity timeout to 0 do?
- Immediately logs out all administrators
- Disables all administrator accounts
- Keeps inactive administrator sessions logged in indefinitely
- Forces password changes at every login
Correct Answer: 3. Keeps inactive administrator sessions logged in indefinitely
Explanation:
Fortinet documents that entering 0 for the administrator login-session inactivity timeout disables automatic inactivity logout. As a result, inactive EMS administrator sessions remain logged in indefinitely unless the user explicitly signs out or the session ends for another reason. While this can be convenient in certain controlled environments, it creates additional security risk if an administrator leaves a browser session unattended. Organizations should select a timeout that balances usability with protection of the EMS management interface and should consider workstation locking and privileged-access policies as complementary controls.
Question 367. What does the “Disable administrators’ accounts when inactive for x days” setting do?
- Deletes inactive administrator accounts permanently
- Disables an administrator account after the configured period without login activity
- Changes inactive administrators to endpoint users
- Revokes the EMS server certificate
Correct Answer: 2. Disables an administrator account after the configured period without login activity
Explanation:
EMS can automatically disable administrator accounts that have not been used for a specified number of days. For example, if the setting is configured for 10 days and an administrator does not log in during that period, EMS disables the account so it cannot authenticate. This helps reduce the risk created by dormant privileged accounts that remain enabled indefinitely. Fortinet documents that a Super administrator can reactivate such a disabled account. This control is different from temporary failed-login lockout because it is based on prolonged inactivity rather than repeated incorrect password attempts.
Question 368. Who can reactivate an EMS administrator account that EMS disabled because of prolonged inactivity?
- Any endpoint user
- FortiAnalyzer only
- The disabled administrator without assistance
- A Super administrator**
Correct Answer: 4. A Super administrator
Explanation:
When EMS automatically disables an administrator account because it has been inactive for longer than the configured threshold, Fortinet specifies that a Super administrator can reactivate the account. This reflects EMS’s role-based administrative model: high-impact account-management operations are reserved for highly privileged administrators. Automatic inactivity disabling protects the environment from dormant privileged accounts, while Super administrator reactivation provides a controlled recovery mechanism for legitimate users returning after a long absence. Organizations should therefore maintain appropriately protected Super administrator access so account recovery remains possible when required.
Question 369. What does the EMS “Change password after x days” setting apply to?
- Built-in EMS users such as the admin account and local administrators created in EMS
- All Active Directory passwords
- FortiGate administrator passwords
- Every endpoint user’s operating-system password
Correct Answer: 2. Built-in EMS users such as the admin account and local administrators created in EMS
Explanation:
The Change password after x days control applies specifically to built-in EMS accounts, including the built-in admin user and local administrators created within EMS. It does not control password expiration in Active Directory, SAML identity providers, FortiGate, or endpoint operating systems. Those external identity sources maintain their own credential policies. Fortinet also allows the administrator to enter zero to disable this EMS password-expiration setting. Understanding the scope of this control helps avoid confusion when an LDAP-based administrator’s password does not follow the expiration schedule configured for EMS local accounts.
Question 370. What does entering 0 for “Change password after x days” do?
- Forces immediate password reset
- Deletes all local administrator passwords
- Enables daily password changes
- Disables the EMS local-account password-expiration setting**
Correct Answer: 1. Disables the EMS local-account password-expiration setting
Explanation:
Fortinet allows an administrator to enter 0 for the local-account password-change interval. This disables the EMS-enforced password-expiration requirement for built-in EMS users. It does not remove passwords or disable authentication; it simply stops EMS from forcing local administrators to change their passwords after a specified number of days. Organizations may instead rely on another internal password-management policy, but they should ensure that local privileged accounts remain adequately protected. This setting does not control credentials managed by LDAP, SAML, Microsoft Entra ID, or another external identity source.
Question 371. What happens the first time an administrator logs in to a newly installed FortiClient EMS 7.4 system using the default admin account?
- EMS permanently keeps the password blank
- EMS automatically creates an LDAP account
- EMS requires creation of a new username and password for increased security
- FortiGate must approve the login
Correct Answer: 4. EMS requires creation of a new username and password for increased security
Explanation:
On a newly installed EMS system, Fortinet documents that the default admin account initially has no password. After the administrator signs in for the first time, EMS requires the administrator to create a new set of credentials that follows the displayed password rules. This prevents the system from continuing to operate with the initial blank-password state. The initial-login process is therefore part of hardening the EMS management interface. Production administrators should also configure trusted certificates, appropriate administrator roles, lockout behavior, and inactivity controls after completing initial access.
Question 372. Under what condition can EMS display a certificate-related popup after an administrator logs in?
- If no secure SSL certificate has been imported or the certificate has not been correctly configured for Endpoint Control
- Whenever an endpoint has a vulnerability
- Whenever FortiAnalyzer is disconnected
- Whenever an administrator changes a password
Correct Answer: 3. If no secure SSL certificate has been imported or the certificate has not been correctly configured for Endpoint Control
Explanation:
Fortinet documents that EMS can display a popup after login when a secure SSL certificate has not been imported or when an imported certificate has not been configured correctly for the Endpoint Control service. The warning helps administrators identify an incomplete certificate configuration that could cause trust problems for browsers, endpoints, or FortiGate integrations. Importing a certificate alone is not always sufficient; it must also be assigned to the appropriate EMS service. Certificate deployment should therefore include both upload and service-assignment verification.
Question 373. Why should the certificate assigned to the EMS Endpoint Control service be trusted by FortiClient endpoints?
- The certificate is used to license FortiClient
- Endpoint Control communication must be protected by a certificate the connecting endpoints can trust
- It determines FortiClient antivirus severity
- It stores user SAML passwords
Correct Answer: 1. Endpoint Control communication must be protected by a certificate the connecting endpoints can trust
Explanation:
EMS uses certificates to secure communication with FortiClient endpoints and other connected Fortinet components. The certificate presented for Endpoint Control should be trusted by the connecting endpoints so that the TLS-protected management connection can be validated reliably. Fortinet’s ZTNA deployment guidance recommends installing a server certificate from a trusted public or private certificate authority and assigning it as the Endpoint Control certificate. This reduces trust warnings and provides stronger identity assurance than relying on an untrusted default certificate.
Question 374. Which EMS service and port pair is correctly matched?
- Chromebook daemon — TCP 8013
- Endpoint Control daemon — TCP 10443
- Installer service — TCP 8443
- Endpoint Control daemon — TCP 8013**
Correct Answer: 4. Endpoint Control daemon — TCP 8013
Explanation:
The EMS Endpoint Control service uses TCP 8013 by default and is the primary management and Telemetry communication channel between FortiClient and EMS. Fortinet separately documents TCP 10443 for installer downloads, TCP 8443 for the Chromebook daemon, and TCP 443 for the EMS administrative GUI. The websocket notification daemon uses TCP 8015. Because different EMS functions can use different server certificates and ports, administrators troubleshooting TLS or connectivity issues should identify the specific service that is failing before making network or certificate changes.
Question 375. Which EMS service uses the same web-server certificate category as the GUI and listens on TCP 10443?
- FortiClient installer download service
- Chromebook profile service
- Endpoint Control Telemetry service
- PostgreSQL database service
Correct Answer: 2. FortiClient installer download service
Explanation:
The EMS web-server certificate covers the Apache web services, including the administrative GUI on TCP 443 and FortiClient installer downloads on TCP 10443. The same web-server certificate category is also associated with the notification/websocket service on TCP 8015. Endpoint Control on TCP 8013 is configured separately, as is the Chromebook service on TCP 8443. Understanding these certificate assignments helps administrators diagnose cases where the EMS GUI is trusted but FortiClient Telemetry is not, or where installer downloads show certificate problems even though endpoint management is otherwise functioning.
Question 376. Which EMS service normally uses TCP 8443 and can have a separate certificate assignment?
- FortiClient installer download
- FortiOS websocket notifications
- Chromebook daemon
- Endpoint Control Telemetry
Correct Answer: 3. Chromebook daemon
Explanation:
Fortinet documents TCP 8443 for the EMS Chromebook daemon. EMS Server Certificates allows administrators to see which certificate is assigned to the Chromebook service separately from certificates used by the web server or Endpoint Control. This distinction matters in mixed-platform environments because a certificate issue affecting Chromebook connectivity may not affect Windows or macOS FortiClient Telemetry. Administrators should map the failing feature to its exact EMS service, port, and certificate assignment before troubleshooting network access or trust-chain issues.
Question 377. If EMS has only the FortiCare-issued certificates and its built-in default certificate available, which certificate does EMS prefer first?
- The default certificate
- The .2.cert FortiCare certificate
- A randomly selected certificate
- The .1.cert FortiCare certificate**
Correct Answer: 4. The .1.cert FortiCare certificate
Explanation:
Licensed EMS systems can receive FortiCare-issued certificates named with .1.cert and .2.cert suffixes. Fortinet documents that when only these certificates and the EMS default certificate are available, EMS prefers the FortiCare-issued certificates over the default certificate, with .1.cert preferred over .2.cert. However, these certificates may not be trusted automatically by standard browsers or endpoints because they are not necessarily issued by a public CA. For production deployments, administrators often configure a certificate issued by a trusted public or organizational certificate authority.
Question 378. What can an administrator configure with “Reset Stalled Deployment Interval”?
- The number of hours after which EMS resets a deployment considered stalled
- The number of minutes before an administrator password expires
- The amount of time FortiGate caches routing information
- The interval for Web Filter category updates
Correct Answer: 2. The number of hours after which EMS resets a deployment considered stalled
Explanation:
The Reset Stalled Deployment Interval setting specifies how many hours EMS waits before resetting a deployment that has become stalled. This provides an automated recovery mechanism for deployment tasks that are no longer progressing normally. A stalled deployment is different from an endpoint simply being offline or a user intentionally scheduling installation for later. Administrators should review endpoint connectivity, installer availability, operating-system compatibility, and deployment configuration when repeated stalls occur instead of relying solely on automatic reset. The interval is configured as an EMS management setting and can also be site-specific in multisite deployments.
Question 379. In a multisite EMS deployment, which statement about the login banner is correct?
- One banner is automatically shared globally across every site and cannot differ
- Login banners are supported only on FortiClient endpoints
- The login banner is configured at the site level and appears when signing in to that specific site
- Login banners require FortiAnalyzer
Correct Answer: 3. The login banner is configured at the site level and appears when signing in to that specific site
Explanation:
Fortinet lists Enable login banner among settings configured separately for individual EMS sites. The banner displayed applies when an administrator signs in to the specified site, allowing organizations to present site-specific legal notices, operational messages, or administrative warnings. This reflects the broader multisite design in which many EMS settings and objects—including endpoint policies, profiles, deployment packages, Feature Select, Software Inventory, and site-level permissions—are managed independently per site. Administrators should therefore avoid assuming that every EMS setting automatically propagates across all sites.
Question 380. An EMS administrator reports repeated account lockouts, certificate warnings on endpoints, and deployment jobs that remain stuck. Which troubleshooting approach BEST addresses all three issues?
- Review Admin Lockout Attempt and Lockout Period settings, verify a trusted certificate is assigned to the Endpoint Control service, and examine the Reset Stalled Deployment Interval together with deployment connectivity
- Disable all administrator security settings and use the default certificate permanently
- Reinstall every FortiClient endpoint immediately
- Replace FortiGate because all three symptoms must originate from the firewall
Correct Answer: 1. Review Admin Lockout Attempt and Lockout Period settings, verify a trusted certificate is assigned to the Endpoint Control service, and examine the Reset Stalled Deployment Interval together with deployment connectivity
Explanation:
The three symptoms involve different EMS subsystems. Administrator lockouts should be investigated through the configured failed-attempt threshold and lockout period. Endpoint certificate warnings point to server-certificate trust and whether the correct certificate is assigned to Endpoint Control on TCP 8013. Stalled deployments require review of deployment state, endpoint reachability, installer access, and the configured stalled-deployment reset interval. Treating each issue according to its subsystem avoids destructive troubleshooting such as reinstalling endpoints or disabling security controls without evidence. A systematic EMS troubleshooting approach maps each symptom to the relevant configuration and communication path.