View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps.
Question 141. Which requirement must be met for FortiClient Anti-Exploit to function?
- Web Filter must be enabled
- FortiSandbox must be reachable
- Real-Time Protection must be enabled
- The endpoint must be connected to SSL VPN
Correct Answer: 3. Real-Time Protection must be enabled
Explanation:
FortiClient Anti-Exploit detects suspicious payloads or processes launched from legitimate applications and is intended to defend against exploit techniques, including attacks targeting unpatched or zero-day vulnerabilities. Fortinet specifically states that Real-Time Protection must be enabled for the Anti-Exploit feature to function. Anti-Exploit complements normal antivirus scanning because it focuses on suspicious application behavior rather than only matching malicious files to known signatures. Administrators who enable Anti-Exploit in an EMS Malware Protection profile but leave Real-Time Protection disabled should therefore expect the exploit-protection function not to operate as intended.
Question 142. What is a key characteristic of FortiClient Anti-Exploit detection?
- It can detect suspicious exploit behavior without relying exclusively on traditional malware signatures
- It scans only removable media devices
- It works only when a FortiGate performs SSL deep inspection
- It is designed only to identify missing Windows patches
Correct Answer: 1. It can detect suspicious exploit behavior without relying exclusively on traditional malware signatures
Explanation:
FortiClient Anti-Exploit is designed to identify exploit behavior targeting legitimate applications such as web browsers and Microsoft Office programs. Fortinet describes it as a signature-less protection mechanism capable of detecting both known and unknown exploit techniques, including memory-based attacks and drive-by downloads. When suspicious exploitation is detected, FortiClient can terminate the compromised application process. This is different from Vulnerability Scan, which identifies software or operating-system vulnerabilities, and from standard antivirus, which primarily evaluates files for malicious content. Anti-Exploit focuses on exploitation behavior occurring through legitimate applications.
Question 143. Which platform limitation applies to FortiClient Anti-Ransomware in the 7.4 documentation?
- It is supported only on Android
- It requires a FortiGate hardware appliance
- It is available only when Web Filter is disabled
- It is not supported on FortiClient macOS**
Correct Answer: 4. It is not supported on FortiClient macOS
Explanation:
Fortinet documents an important platform limitation for the Anti-Ransomware feature: it is not supported on FortiClient macOS. Anti-Ransomware protects selected folders or file types from suspicious modifications and can terminate malicious ransomware behavior, quarantine modified files, and optionally restore files from FortiClient backups. Platform support should always be verified when designing EMS profiles because not every feature available in a Windows-oriented profile is supported identically across macOS, Linux, Android, or other endpoints. Administrators should avoid assuming that centrally configured EMS settings automatically provide identical endpoint functionality on every operating system.
Question 144. What must be enabled for FortiClient Anti-Ransomware to restore files that ransomware encrypted?
- SSL VPN Auto Connect
- Enable File Backup
- FortiAnalyzer Event Upload
- Web Filter HTTPS inspection
Correct Answer: 2. Enable File Backup
Explanation:
FortiClient Anti-Ransomware can terminate suspicious ransomware processes and quarantine modified files, but file recovery depends on the Enable File Backup option. When backup is enabled, FortiClient periodically backs up eligible files in protected locations and can restore those files after ransomware behavior is detected. If backup is disabled, Fortinet states that FortiClient cannot recover the affected files even though it may still detect and stop the ransomware activity. Administrators should therefore distinguish ransomware detection from ransomware recovery. Recovery requires that file backup be enabled and appropriately configured before the attack occurs.
Question 145. What happens when Anti-Ransomware is configured with “Monitor only with Anti-Ransomware detection”?
- FortiClient logs the suspicious activity but does not terminate the process based on that setting
- FortiClient immediately deletes the endpoint user account
- EMS quarantines the endpoint from the network automatically
- FortiClient restores every file regardless of whether backup is enabled
Correct Answer: 1. FortiClient logs the suspicious activity but does not terminate the process based on that setting
Explanation:
The Anti-Ransomware profile provides several responses to suspicious ransomware behavior. Monitor only with Anti-Ransomware detection records the detected activity rather than automatically terminating the suspicious process. Other modes can terminate the ransomware behavior immediately or temporarily suspend the process while asking the endpoint user whether the process should be terminated. Monitor-only mode can be useful during evaluation or tuning when administrators want visibility into potential detections before enforcing remediation. However, because suspicious processes are not automatically stopped in monitor-only mode, this setting provides less active protection than termination-based enforcement.
Question 146. What does “Bypass Valid Signer” do in an Anti-Ransomware configuration?
- It blocks every digitally signed application
- It sends all signed applications to FortiSandbox
- It can exclude a process from the selected Anti-Ransomware action when it has a valid trusted digital signature
- It disables Anti-Ransomware signature updates
Correct Answer: 3. It can exclude a process from the selected Anti-Ransomware action when it has a valid trusted digital signature
Explanation:
Bypass Valid Signer allows FortiClient to exclude processes from the selected Anti-Ransomware action when the process has a valid digital signature issued by a trusted certificate authority. Fortinet notes that enabling this capability may reduce false positives and speed file analysis. The feature does not mean that all signed software is automatically safe in every security context, but it lets administrators reduce unnecessary Anti-Ransomware intervention for trusted signed applications. As with other exclusions, the setting should be used carefully because overly broad trust decisions can weaken endpoint protection.
Question 147. How does FortiClient Cloud-Based Malware Detection initially check a high-risk file against FortiGuard?
- It uploads the complete disk image to FortiGuard
- It generates a SHA1 checksum and queries the FortiGuard checksum library
- It compares only the file name
- It sends the endpoint’s IP address for reputation scoring
Correct Answer: 2. It generates a SHA1 checksum and queries the FortiGuard checksum library
Explanation:
When a high-risk file is downloaded or executed, FortiClient Cloud-Based Malware Detection calculates a SHA1 checksum for that file. FortiClient sends the checksum to FortiGuard and checks it against FortiGuard’s checksum library. If the checksum is identified as malicious, FortiGuard returns that verdict to FortiClient, and the default response is to quarantine the file. This approach reduces the need to transmit every complete file merely to determine whether it matches a known malicious sample. Fortinet limits the feature to high-risk file types such as executable, document, PDF, and DLL files.
Question 148. By default, what does FortiClient do when FortiGuard identifies a file checked by Cloud-Based Malware Detection as malicious?
- Allows the file permanently
- Sends the file to Active Directory
- Restarts EMS
- Quarantines the file**
Correct Answer: 4. Quarantines the file
Explanation:
Fortinet documents Quarantine as the default behavior when Cloud-Based Malware Detection receives a malicious verdict from FortiGuard. The Malware Protection profile can also provide an Alert & Notify option depending on configuration. Cloud-Based Malware Detection is intended to provide additional protection against high-risk files originating from sources such as the internet or network drives. Administrators can configure whether FortiClient should wait for cloud-scan results before allowing access and whether file access should be denied when no cloud verdict is available. These settings let organizations choose between stronger enforcement and greater availability.
Question 149. What is the effect of enabling “Deny Access to File When There is No Cloudscan Result”?
- FortiClient deletes every file not already in the local antivirus database
- FortiClient disables FortiGuard queries
- FortiClient denies access to the downloaded file if it cannot obtain a cloud-scan result
- EMS automatically quarantines the entire endpoint
Correct Answer: 3. FortiClient denies access to the downloaded file if it cannot obtain a cloud-scan result
Explanation:
The Deny Access to File When There is No Cloudscan Result option provides a more restrictive response when FortiClient cannot obtain a verdict from the cloud malware-scanning service. Instead of allowing access simply because no malicious verdict was returned, FortiClient denies access to the file. A missing result may occur when FortiClient cannot reach FortiGuard. This setting can improve security in environments that prefer fail-closed behavior, but administrators should understand that FortiGuard connectivity problems could then affect users’ ability to access legitimate downloaded files.
Question 150. What does “Exclude Files from Trusted Sources” do in Cloud-Based Malware Protection?
- Excludes qualifying files signed with a valid certificate issued by a trusted CA from cloud submission
- Excludes every file downloaded through HTTPS
- Excludes all Microsoft Office files
- Disables real-time antivirus protection
Correct Answer: 1. Excludes qualifying files signed with a valid certificate issued by a trusted CA from cloud submission
Explanation:
When Exclude Files from Trusted Sources is enabled, FortiClient can exclude files from Cloud-Based Malware Protection submission when the files are digitally signed with valid certificates issued by trusted certificate authorities. Fortinet notes that this feature can reduce false positives and improve analysis speed. Administrators should nevertheless apply trusted-source exclusions carefully. A broad exclusion can reduce the number of files undergoing cloud analysis, so trust should be based on valid signatures and appropriate enterprise policy rather than simply assuming all downloaded software is harmless.
Question 151. What actions can be configured as the default removable-media access behavior in a FortiClient Malware Protection profile?
- Allow, Block, or Monitor
- Encrypt, Archive, or Delete
- Scan, Route, or Proxy
- Approve, Deny, or Quarantine EMS
Correct Answer: 4. Allow, Block, or Monitor
Explanation:
The Removable Media Access section of the Malware Protection profile allows administrators to define what FortiClient should do when removable media does not match a more specific rule. The available default actions are Allow, Block, and Monitor. Allow permits device access, Block prevents access, and Monitor records the device connection without blocking it. On supported Windows endpoints, administrators can also create more granular removable-media rules based on device characteristics. Removable-media controls help organizations reduce the risk of malware introduction and unauthorized data transfer through USB and similar devices.
Question 152. What limitation applies to removable-media access rules on FortiClient macOS and Linux?
- They support only per-device serial-number rules
- They support only the configured default removable-media access action, not the other granular EMS rules
- They always block every USB device
- They require FortiAnalyzer before they function
Correct Answer: 2. They support only the configured default removable-media access action, not the other granular EMS rules
Explanation:
Fortinet documents that FortiClient macOS and Linux support only the action configured for Default removable media access. They do not support the more detailed removable-media access rules received from EMS that can be applied on supported Windows endpoints. This is another example of platform differences within the same centrally managed EMS profile. Administrators should review operating-system support before relying on device-specific policies, especially in mixed endpoint environments. A profile may contain granular Windows device rules while macOS and Linux endpoints enforce only the broader default Allow, Block, or Monitor behavior.
Question 153. Why does Fortinet recommend keeping the antivirus exclusion list as short as possible?
- A longer exclusion list can negatively affect antivirus performance
- EMS supports only one exclusion
- Exclusions automatically disable FortiClient Telemetry
- Large exclusion lists consume VPN licenses
Correct Answer: 1. A longer exclusion list can negatively affect antivirus performance
Explanation:
Fortinet explicitly advises administrators to keep antivirus exclusion lists as short as possible because longer lists can affect antivirus performance. Each exclusion introduces additional path, file, extension, or wildcard logic that FortiClient must evaluate during scanning. Exclusions also reduce the security coverage of antivirus scanning, so unnecessary entries can introduce both performance and security concerns. Administrators should create exclusions only where applications have a documented compatibility requirement and should periodically review whether old exclusions are still necessary. A focused exclusion list is easier to troubleshoot, audit, and maintain than a large collection of broad wildcard rules.
Question 154. Which statement about FortiClient antivirus exclusion lists is correct?
- Exclusions are never case sensitive
- Exclusions can be used only for file extensions
- Network shares cannot be excluded
- Exclusion lists are case-sensitive**
Correct Answer: 4. Exclusion lists are case-sensitive
Explanation:
Fortinet notes that Malware Protection antivirus exclusion lists are case-sensitive. Administrators should therefore enter paths, filenames, variables, and patterns with attention to the actual case expected by the endpoint environment. EMS supports several exclusion methods, including fully qualified files and folders, file extensions, wildcards, and supported path variables. Network shares may also be excluded using mapped drive letters or UNC paths. Incorrect case or overly broad wildcard logic can result in an exclusion not matching as expected—or matching more than intended—so exclusions should be tested carefully.
Question 155. Which syntax is valid for excluding all files with the .jrs extension from antivirus scanning?
- *.jrs
- jrs/*
- %jrs%
- all:jrs
Correct Answer: 2. *.jrs
Explanation:
FortiClient EMS supports wildcard syntax in antivirus exclusions. Fortinet gives *.jrs as an example for excluding all files with the specified extension. Administrators can also combine wildcards with supported path variables such as %systemroot%, %userprofile%, %appdata%, or %localappdata%. Wildcards are powerful because one exclusion can match many files, but they should be used carefully to avoid creating excessively broad antivirus bypasses. Exclusion patterns should be limited to known application requirements and reviewed when software is upgraded or decommissioned.
Question 156. Which Malware Protection exclusion option affects Real-Time Protection but does not necessarily exclude the same extension from on-demand scanning?
- Paths to Excluded Folders
- File Extensions Excluded from Real-Time Protection
- Paths to Excluded Files
- Default Removable Media Access
Correct Answer: 3. File Extensions Excluded from Real-Time Protection
Explanation:
EMS provides separate settings for extensions excluded from Real-Time Protection and extensions excluded from On Demand Scanning. This separation lets administrators exclude a file type from continuous RTP inspection while still allowing scheduled or manually initiated antivirus scans to inspect that file type, or vice versa. Folder and file path exclusions generally apply more broadly to relevant scanning modes. Understanding the distinction prevents administrators from accidentally assuming that an RTP extension exclusion also removes the same files from all future on-demand scans.
Question 157. What is the main difference between a Quick antivirus scan and a Full antivirus scan in an EMS Malware Protection profile?
- Quick scans only removable media, while Full scans only network drives
- Quick scan performs no rootkit detection
- Full scan works only on macOS
- Quick scans currently running executables, DLLs, and drivers, while Full scans the broader system file set in addition to rootkit detection**
Correct Answer: 4. Quick scans currently running executables, DLLs, and drivers, while Full scans the broader system file set in addition to rootkit detection
Explanation:
Fortinet’s Malware Protection scheduling options distinguish Quick and Full scans by scope. A Quick scan runs the rootkit detection engine and examines executable files, DLLs, and drivers that are currently running. A Full scan also performs rootkit detection but then scans the wider system file set, including files, executables, DLLs, and drivers. Full scans therefore provide more comprehensive coverage but require more endpoint resources and time. Administrators can use scan priority and scheduling to balance protection with the performance impact on end users.
Question 158. When are “Scan Removable Media” and “Scan Network Drives” available in scheduled Malware Protection scanning?
- Only when Scan Type is Full
- Only when Scan Type is Quick
- Only when Anti-Ransomware is disabled
- Only when FortiSandbox is unavailable
Correct Answer: 1. Only when Scan Type is Full
Explanation:
Fortinet documents Scan Removable Media and Scan Network Drives as options available when the scheduled antivirus Scan Type is Full. A Full scan performs a broader system scan, while a Quick scan focuses on currently running executables, DLLs, and drivers. Scanning connected removable media and network drives can increase the scope and duration of a scheduled scan, so administrators should consider endpoint performance, network load, and the business need for those additional locations. The settings are not general toggles for every scheduled scan type.
Question 159. On FortiClient Android, what limitation applies to Malware Protection?
- Real-time scanning is not supported because of Android platform restrictions, though scheduled scans can be pushed from EMS
- Malware scanning is completely unsupported
- Only FortiSandbox scans are allowed
- EMS cannot configure any Android scan schedule
Correct Answer: 3. Real-time scanning is not supported because of Android platform restrictions, though scheduled scans can be pushed from EMS
Explanation:
Fortinet documents that FortiClient Android does not support real-time malware scanning because of platform-level restrictions. EMS can still push scheduled antivirus scans to Android devices, including Quick and Full scans at configured times. The endpoint displays scan status and history, including the last scan, files scanned, and detected threats. Android also has additional platform limitations; for example, exclusions are not supported in the documented Android malware-scanning workflow. Administrators should therefore avoid assuming that an EMS Malware Protection profile provides identical real-time capabilities across Windows, macOS, Linux, and Android.
Question 160. An organization wants to prevent unauthorized USB use, detect ransomware, block exploit behavior, query FortiGuard for high-risk downloaded files, and keep antivirus exclusions narrowly controlled. Which EMS configuration is BEST?
- Use only a Remote Access profile
- Use only a Web Filter profile
- Build an appropriately licensed Malware Protection profile with removable-media controls, Anti-Ransomware, Real-Time Protection plus Anti-Exploit, cloud malware detection, and carefully scoped exclusions
- Configure the features only in FortiAnalyzer
Correct Answer: 2. Build an appropriately licensed Malware Protection profile with removable-media controls, Anti-Ransomware, Real-Time Protection plus Anti-Exploit, cloud malware detection, and carefully scoped exclusions
Explanation:
These endpoint-security requirements belong primarily in the EMS Malware Protection profile. Removable Media Access controls USB and similar devices. Anti-Ransomware can protect selected folders and file types and optionally restore files when backup is enabled. Anti-Exploit requires Real-Time Protection and monitors legitimate applications for exploit behavior. Cloud-Based Malware Detection checks high-risk files against FortiGuard, while antivirus exclusions let administrators handle known application compatibility needs. Because many of these capabilities are license dependent, the organization must also verify that the installed EMS entitlement supports the required features.