View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 21. What must an administrator do before FortiClient EMS can manage and provision endpoints?
- Connect EMS to FortiAnalyzer
- Activate an appropriate FortiClient EMS license
- Configure a FortiGate HA cluster
- Enable SSL VPN on every endpoint
Correct Answer: 2. Activate an appropriate FortiClient EMS license
Explanation:
FortiClient EMS must have an active license before it can manage and provision FortiClient endpoints. Fortinet provides several licensing options depending on the required FortiClient features and deployment model. Licensing can cover supported Windows, macOS, Linux, mobile, and Chromebook endpoints. The normal licensing workflow should therefore be completed as part of initial EMS deployment before administrators begin onboarding production endpoints. Licensing is separate from integrations such as FortiAnalyzer or FortiGate. Those products can extend endpoint visibility, ZTNA, and Security Fabric capabilities, but they do not replace the requirement for an EMS license.
Question 22. Which FortiClient EMS license provides features such as next-generation antivirus, anti-ransomware, anti-exploit, Application Firewall, and USB device control in addition to ZTNA features?
- Free VPN license
- Chromebook-only license
- FortiAnalyzer license
- Endpoint Protection Platform (EPP) license
Correct Answer: 4. Endpoint Protection Platform (EPP) license
Explanation:
The Endpoint Protection Platform license is the full FortiClient security license. It includes the capabilities provided by the ZTNA license and adds advanced endpoint-protection features such as next-generation antivirus, anti-ransomware, anti-exploit, cloud-based malware detection, Application Firewall, software inventory, USB device control, and advanced sandbox capabilities. The ZTNA license is more focused on telemetry, posture checking, remote access, vulnerability scanning, Web Filter, and related zero-trust functionality. Administrators should therefore select the license according to the endpoint-security features that are required by the organization’s endpoint profiles.
Question 23. Under FortiClient EMS per-user licensing, how many devices can one user normally register before an additional license is consumed?
- Three devices
- One device
- Five devices
- Ten devices
Correct Answer: 1. Three devices
Explanation:
With FortiClient EMS per-user licensing, one user license normally allows the user to register up to three devices. Fortinet documents that when the same user registers a fourth device, that user consumes two licenses. EMS also supports per-endpoint licensing, but administrators cannot combine per-user and per-endpoint licensing on the same EMS instance. User verification is recommended for per-user deployments because EMS needs reliable user identity information to assign license consumption correctly. Understanding this behavior is important when sizing licenses for users who routinely use multiple desktops, laptops, or mobile devices.
Question 24. Which statement about FortiClient EMS per-user and per-endpoint licensing is correct?
- EMS automatically converts per-user licenses to per-endpoint licenses every month
- Both licensing types must always be installed together
- An EMS instance cannot use both per-user and per-endpoint licensing simultaneously
- Per-user licensing is supported only for Chromebooks
Correct Answer: 3. An EMS instance cannot use both per-user and per-endpoint licensing simultaneously
Explanation:
FortiClient EMS supports both per-user and per-endpoint licensing models, but Fortinet specifies that they cannot be mixed on the same EMS instance. An organization must therefore decide which model best fits its deployment. Per-endpoint licensing is straightforward when devices are the primary management unit, while per-user licensing can be useful when individuals use multiple managed devices. Under per-user licensing, identity verification becomes especially important because EMS uses user identity to calculate license consumption. License architecture should be planned before a large deployment because switching models can affect capacity planning and administrative procedures.
Question 25. Which statement accurately describes the FortiClient EMS free trial license?
- It supports unlimited production endpoints
- It includes every EPP feature and full Fortinet technical support
- It expires automatically after seven days
- It manages a small number of endpoints for evaluation and provides ZTNA-level functionality without Sandbox Cloud support
Correct Answer: 4. It manages a small number of endpoints for evaluation and provides ZTNA-level functionality without Sandbox Cloud support
Explanation:
The EMS free trial license is intended for evaluation rather than production use. Fortinet documents that it can manage three supported Windows, macOS, Linux, iOS, and Android endpoints as well as three Chromebooks. Its functionality corresponds broadly to the ZTNA license and does not include Sandbox Cloud support. The trial also does not provide normal Fortinet technical-support entitlement and has additional limitations, including restrictions involving installers from the FortiGuard distribution server. For a more formal evaluation requiring support, Fortinet recommends contacting sales for an evaluation license instead of relying on the free trial.
Question 26. What is the PRIMARY licensing method for FortiClient EMS 7.4?
- Log in to FortiCloud and synchronize the EMS license
- Upload a text file generated by FortiAnalyzer
- Enter a FortiGate serial number into EMS
- Activate each endpoint individually through FortiGuard
Correct Answer: 1. Log in to FortiCloud and synchronize the EMS license
Explanation:
Fortinet identifies FortiCloud licensing as the primary method for activating, upgrading, or renewing FortiClient EMS. Administrators add their FortiCloud account through the License Information area and synchronize available licenses with EMS. A license-file upload mechanism also exists as a backup method for certain scenarios, but FortiCloud is the preferred workflow. EMS must be successfully licensed before endpoint management and provisioning are available. This licensing step should therefore be completed and verified during system setup, alongside server readiness, required services and ports, and other installation prerequisites.
Question 27. An organization must deploy FortiClient EMS in a network completely isolated from the internet. Which licensing option is designed for this requirement?
- Trial license only
- Air-Gap license
- FortiAnalyzer entitlement
- SAML license
Correct Answer: 2. Air-Gap license
Explanation:
Fortinet supports an Air-Gap license for EMS installations operating in environments that are completely isolated from the internet. Organizations requiring this deployment model should contact Fortinet Customer Service and Support to obtain the appropriate license. This is different from ordinary FortiCloud licensing, which relies on communication with Fortinet cloud services. Air-gapped environments often exist in highly restricted or sensitive networks where outbound internet connectivity is intentionally prohibited. Administrators should plan both licensing and update procedures carefully because normal cloud-based licensing, FortiGuard communication, and other online services may not function in the same manner.
Question 28. Which list contains only FortiClient EMS endpoint profile categories?
- DNS, DHCP, BGP, and OSPF
- FortiGate HA, SD-WAN, IPS, and routing
- Remote Access, Web Filter, Vulnerability Scan, Malware Protection, Firewall, and System Settings
- ADOM, Device Manager, Policy Package, and FortiView
Correct Answer: 3. Remote Access, Web Filter, Vulnerability Scan, Malware Protection, Firewall, and System Settings
Explanation:
FortiClient EMS provides separate endpoint profile types for major FortiClient features. These include Remote Access, ZTNA-related configuration, Web Filter, Video Filter, Vulnerability Scan, Malware Protection, Sandbox, Firewall, and System Settings. Administrators can create different configurations within each profile category and combine the desired profiles through endpoint policies. This modular architecture allows different groups to receive different VPN, web filtering, vulnerability, malware, firewall, or system configurations without creating one monolithic configuration. Features such as routing protocols, FortiManager ADOMs, and FortiGate HA are not FortiClient EMS endpoint profile categories.
Question 29. What happens to FortiClient settings that EMS supplies through an endpoint profile?
- They are automatically updated on the endpoint and are normally locked as read-only for the user
- They remain completely unmanaged and editable by any local user
- FortiClient ignores them until the next operating-system upgrade
- They are applied only to the EMS server itself
Correct Answer: 1. They are automatically updated on the endpoint and are normally locked as read-only for the user
Explanation:
EMS endpoint profiles define centrally managed FortiClient configuration. When an endpoint receives configuration from its assigned endpoint policy, FortiClient automatically updates the relevant settings. Fortinet documents that settings supplied through EMS profiles are locked and read-only in FortiClient, helping prevent local users from bypassing centrally enforced security configuration. This behavior is fundamental to centrally managed endpoint security: administrators define security requirements once and EMS distributes them consistently. If users need different settings, the administrator should normally adjust the applicable EMS profile or policy rather than asking users to change managed settings locally.
Question 30. An endpoint qualifies for two enabled endpoint policies. Which policy does EMS apply?
- The policy created most recently
- Both policies simultaneously
- The policy with the longest name
- The eligible policy with the highest priority
Correct Answer: 4. The eligible policy with the highest priority
Explanation:
An endpoint can sometimes match more than one EMS endpoint policy because of group membership or other assignment criteria. EMS first considers only enabled policies and then applies the eligible policy with the highest configured priority. Administrators can change policy priority from the Manage Policies interface. This behavior is critical when troubleshooting an endpoint that receives an unexpected profile. The configuration itself may be valid, but another matching policy may have higher priority. Administrators should therefore examine both matching criteria and policy ordering instead of assuming EMS merges all eligible endpoint policies together.
Question 31. What happens when an EMS endpoint policy is disabled?
- It becomes the highest-priority policy automatically
- EMS does not apply that policy to endpoints
- All profiles contained in the policy are deleted
- Managed FortiClient endpoints are uninstalled
Correct Answer: 2. EMS does not apply that policy to endpoints
Explanation:
EMS applies only endpoint policies that are enabled. Disabling a policy removes it from consideration when EMS determines which policy should apply to an endpoint. The policy itself is not deleted, and the profiles referenced by that policy remain available. This gives administrators a useful way to temporarily stop using a configuration without permanently removing its settings. If an endpoint no longer receives the expected policy, checking whether the intended policy is enabled should be one of the first troubleshooting steps, along with verifying policy eligibility, priority, endpoint group membership, and Telemetry connectivity.
Question 32. What is the purpose of on-fabric detection rules in FortiClient EMS?
- To calculate EMS licensing consumption
- To scan endpoint disks for ransomware
- To determine whether an endpoint is on- or off-fabric so EMS can apply the appropriate configuration
- To generate FortiAnalyzer reports
Correct Answer: 3. To determine whether an endpoint is on- or off-fabric so EMS can apply the appropriate configuration
Explanation:
On-fabric detection rules allow EMS to determine whether an endpoint is connected within the organization’s trusted network environment or is operating off-fabric. Endpoint policies can then apply different profiles according to that status. For example, a remote endpoint may need a specific VPN or security configuration while an on-premises endpoint can use a different profile. This mechanism makes FortiClient configuration context aware. Administrators should validate on-fabric detection logic when endpoints unexpectedly receive off-site or on-site settings because incorrect detection can cause the wrong profile to be applied even when the endpoint policy itself is otherwise correct.
Question 33. An on-fabric detection rule set contains rules of several different detection types. What must happen for the endpoint to satisfy the complete rule set?
- Any one rule may match
- Only the first configured rule is evaluated
- EMS randomly selects a rule
- The endpoint must satisfy all configured rules in that rule set
Correct Answer: 4. The endpoint must satisfy all configured rules in that rule set
Explanation:
Fortinet documents that when a single on-fabric detection rule set contains rules using multiple detection types, the endpoint must satisfy all configured rules for the entire rule set to evaluate successfully. This AND-style behavior is important when administrators combine multiple characteristics to identify the trusted network environment. A rule set can therefore be made more specific by requiring several conditions simultaneously. If an endpoint is unexpectedly considered off-fabric, administrators should test each detection condition independently because failure of one required rule can cause the complete rule set to fail.
Question 34. An administrator manually starts a vulnerability scan for an endpoint from EMS. When does scanning normally begin?
- Immediately before EMS saves the request
- At the endpoint’s next FortiClient Telemetry communication with EMS
- Only after the endpoint reboots twice
- During the next monthly license synchronization
Correct Answer: 2. At the endpoint’s next FortiClient Telemetry communication with EMS
Explanation:
When an administrator initiates a vulnerability scan from the EMS Endpoints interface, the scan begins after the endpoint next communicates with EMS through FortiClient Telemetry. The same principle applies when a scan is started for endpoints in a domain or workgroup. This means the action may not be instantaneous if the endpoint is offline or currently unable to communicate with EMS. When troubleshooting a scan that appears not to start, the administrator should therefore verify endpoint connectivity and Telemetry status before assuming the vulnerability-scanning feature itself is malfunctioning.
Question 35. What is the PRIMARY way FortiClient Web Filter determines how to handle a website?
- It obtains the website’s FortiGuard category and applies the configured action, subject to custom URL filtering rules
- It blocks every HTTPS site automatically
- It relies only on the local DNS cache
- It sends the website to FortiAnalyzer for approval before every connection
Correct Answer: 1. It obtains the website’s FortiGuard category and applies the configured action, subject to custom URL filtering rules
Explanation:
FortiClient Web Filter can block, allow, warn, or monitor web traffic based on FortiGuard URL categories and custom URL filters. When a domain is detected, FortiClient obtains categorization information from FortiGuard and applies the action configured for that category. Administrators can also create custom URL exclusions that override normal category handling. FortiClient inspects web traffic from applications beyond conventional browsers, so web filtering can influence traffic generated by programs such as email clients. This central category-based model lets EMS administrators enforce consistent browsing controls across managed endpoints.
Question 36. By default, what does FortiClient Web Filter do if it cannot contact FortiGuard for web categorization?
- It disables FortiClient entirely
- It automatically trusts all websites
- It blocks all web traffic unless the behavior is changed through configuration
- It uninstalls Web Filter
Correct Answer: 3. It blocks all web traffic unless the behavior is changed through configuration
Explanation:
Fortinet documents that if FortiClient Web Filter cannot contact FortiGuard, the default behavior is to block web traffic. Administrators can change this behavior through the appropriate FortiClient XML configuration if organizational requirements favor availability over the default restrictive posture. This behavior is important when diagnosing widespread web-access failures: loss of FortiGuard connectivity may cause browsing disruption even though ordinary network connectivity still exists. Administrators should examine DNS, firewall rules, FortiGuard reachability, proxy configuration, and Web Filter settings before concluding that individual websites or browsers are the source of the problem.
Question 37. Why might some Malware Protection settings not appear when an administrator edits a FortiClient EMS endpoint profile?
- Malware Protection is available only on Chromebook
- EMS displays only features supported by the applied license
- The endpoint must be quarantined first
- Malware Protection settings appear only after FortiAnalyzer integration
Correct Answer: 2. EMS displays only features supported by the applied license
Explanation:
The Malware Protection endpoint profile includes options such as antivirus, anti-ransomware, anti-exploit, cloud-based malware detection, removable-media controls, and exclusions. However, Fortinet specifies that only features covered by the EMS license are available for configuration. This is particularly relevant when comparing ZTNA and EPP licensing because EPP includes advanced endpoint-protection capabilities that are not part of the basic ZTNA feature set. If an expected security control is missing from the profile interface, administrators should check the installed EMS licensing and entitlement before treating the absence as a software defect.
Question 38. An administrator wants an EMS-provisioned VPN tunnel to use certificate-only authentication. What configuration is appropriate?
- Disable Require Certificate and enable Prompt for Username
- Remove the VPN tunnel from the endpoint profile
- Enable Require Certificate and disable Prompt for Username
- Enable Web Filter instead of Remote Access
Correct Answer: 4. Enable Require Certificate and disable Prompt for Username
Explanation:
Fortinet documents a certificate-only VPN configuration in which the administrator enables Require Certificate for the VPN tunnel and disables Prompt for Username. This configuration allows authentication to rely on the appropriate certificate instead of asking the user to supply username credentials through FortiClient. EMS centrally provisions the VPN configuration through a Remote Access endpoint profile, which is then associated with the applicable endpoint policy. Certificate deployment and FortiGate-side authentication configuration must also be correct. If the required certificate is missing or invalid, the tunnel will fail even though the EMS configuration is syntactically correct.
Question 39. What information can an EMS diagnostic logs package contain for troubleshooting?
- EMS CPU and memory snapshots, PostgreSQL logs, performance information, and optionally a partial database backup
- Only FortiGate routing tables
- Only endpoint browser histories
- Only FortiAnalyzer incident reports
Correct Answer: 3. EMS CPU and memory snapshots, PostgreSQL logs, performance information, and optionally a partial database backup
Explanation:
EMS can generate a diagnostic package specifically intended to assist troubleshooting and Fortinet technical support. Fortinet documents that the package can include information such as snapshots of EMS CPU and memory usage, PostgreSQL logs, and performance-related data. Administrators can optionally include a partial database backup and protect that backup with a password. The diagnostic backup is not intended to replace normal EMS database backup procedures. Generating this package can be useful when problems involve server performance, database behavior, or EMS services and ordinary GUI troubleshooting does not provide enough information to determine the cause.
Question 40. An organization is preparing a new FortiClient EMS production server. Which approach BEST follows Fortinet’s deployment guidance?
- Install EMS together with many unrelated business applications to reduce server count
- Install EMS on a dedicated server in a controlled environment and verify required services, ports, licensing, and server readiness before onboarding endpoints
- Deploy endpoints first and license EMS later
- Disable all EMS communication ports until FortiClient installation is complete
Correct Answer: 1. Install EMS on a dedicated server in a controlled environment and verify required services, ports, licensing, and server readiness before onboarding endpoints
Explanation:
Fortinet recommends installing FortiClient EMS on a dedicated server in a controlled environment because unrelated software can interfere with normal EMS operation. Administrators should review licensing, system requirements, required services and ports, and the server-readiness checklist before installation and production onboarding. EMS communication depends on specific services and ports, so network and firewall configuration also must allow required traffic. After installation, EMS should be properly licensed before it begins managing and provisioning endpoints. A disciplined deployment reduces troubleshooting complexity and gives administrators a stable foundation for policies, profiles, endpoint Telemetry, and Security Fabric integration.