View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps
Question 361. What is the primary purpose of the FortiManager Install Preview feature?
- To restart all managed FortiGate devices
2. To replace the FortiManager database
3. To generate antivirus signatures
4. To review proposed configuration changes before installation
Answer: 4. To review proposed configuration changes before installation
Explanation:
FortiManager Install Preview allows administrators to review the configuration changes that will be sent to a managed FortiGate before the installation operation is performed. This is useful for identifying unexpected policy, object, routing, or other configuration differences before they reach the production device. The preview helps administrators validate the intended changes and reduce configuration mistakes. It does not restart devices, generate security signatures, or replace the FortiManager database. In controlled environments, reviewing the installation preview is an important step when managing multiple FortiGate devices through centralized configuration management.
Question 362. Which FortiGate HA setting determines whether a higher-priority device can automatically regain the primary role after recovering?
- Override
2. Session pickup
3. Gratuitous ARP
4. Heartbeat interval
Answer: 1. Override
Explanation:
The HA override setting controls whether device priority is used to determine which cluster member should become the primary unit after a device rejoins the cluster. When override is enabled, a device with a higher configured priority can regain the primary role after recovery, depending on the HA configuration. This behavior is different from heartbeat communication, which is used to monitor cluster members, and from session pickup, which concerns maintaining sessions during failover. Administrators should consider the effect of override when designing HA behavior because repeated role changes can affect traffic handling and operational stability.
Question 363. In a FortiGate HA cluster, what is the purpose of session pickup?
- To assign IP addresses to cluster members
2. To help preserve active sessions during failover
3. To synchronize firmware images
4. To select the default route
Answer: 2. To help preserve active sessions during failover
Explanation:
Session pickup is an HA capability designed to reduce disruption when the primary FortiGate fails and another cluster member takes over. It allows relevant session information to be synchronized so that established traffic flows can continue with less interruption. Without appropriate session synchronization and pickup behavior, existing sessions may need to be re-established after failover. Session pickup is therefore related to traffic continuity rather than IP address assignment, firmware synchronization, or route selection. Its usefulness depends on the session types and HA configuration being used in the FortiGate environment.
Question 364. Which setting can help protect an IPsec VPN from replayed packets?
- NAT traversal
2. Dead Peer Detection
3. Replay detection
4. Peer ID
Answer: 3. Replay detection
Explanation:
IPsec replay detection helps protect VPN traffic against attackers attempting to capture valid packets and transmit them again later. The mechanism uses sequence information associated with IPsec packets to identify packets that have already been processed or fall outside the acceptable sequence window. This provides an additional security control for encrypted VPN communications. NAT traversal addresses VPN connectivity through NAT devices, Dead Peer Detection checks peer availability, and Peer ID helps identify the remote VPN peer. Replay detection is specifically associated with preventing repeated use of previously observed IPsec packets.
Question 365. Which condition commonly causes an IPsec tunnel to fail during Phase 2 negotiation?
- Mismatched Phase 2 selectors
2. Incorrect NTP timezone
3. Missing DHCP reservation
4. Incorrect SNMP community
Answer: 1. Mismatched Phase 2 selectors
Explanation:
Phase 2 negotiation establishes the IPsec security associations and defines which traffic should be protected. If the local and remote Phase 2 selectors do not match appropriately, the peers may be unable to establish the required security association. Administrators troubleshooting this problem should compare the local and remote source and destination networks, protocol settings, and related Phase 2 parameters. NTP, DHCP reservations, and SNMP settings generally do not determine whether Phase 2 selectors match. Reviewing VPN event logs and comparing both peers’ configurations can help identify the exact mismatch.
Question 366. What is the purpose of NAT Traversal (NAT-T. in an IPsec VPN?
- To assign VPN user groups
2. To convert IPv4 addresses into IPv6
3. To improve DNS filtering
4. To allow IPsec traffic to traverse NAT devices
Answer: 4. To allow IPsec traffic to traverse NAT devices
Explanation:
NAT Traversal, commonly called NAT-T, allows IPsec VPN traffic to pass through devices performing Network Address Translation. Certain IPsec protocols can have difficulty traversing NAT because address and port information may be modified by the intermediary device. NAT-T encapsulates the relevant IPsec traffic in UDP so that it can pass through the NAT environment more reliably. This feature is particularly useful when one or both VPN peers are behind a NAT device. NAT-T is unrelated to DNS filtering, user-group assignment, or IPv4-to-IPv6 address conversion.
Question 367. In FortiGate ZTNA, what can a ZTNA tag be used for?
- Identifying endpoint attributes for policy decisions
2. Creating a physical switch connection
3. Replacing the FortiGate routing table
4. Configuring an NTP server
Answer: 1. Identifying endpoint attributes for policy decisions
Explanation:
ZTNA tags can provide information about endpoint characteristics that can be used when applying access policies. Depending on the integration and configuration, tags can represent endpoint-related conditions or classifications and help FortiGate make more contextual access decisions. This supports a zero-trust approach in which access is evaluated using more than simply a source IP address. ZTNA tags do not replace routing functions, create physical switch connections, or configure time synchronization. Administrators can use endpoint information together with authentication and policy controls to apply more specific access requirements.
Question 368. What is the primary role of the FortiGate Security Fabric root device?
- Provide DHCP to every endpoint
2. Act as the central coordinating device for the Security Fabric
3. Replace all FortiSwitch devices
4. Store every endpoint’s local files
Answer: 2. Act as the central coordinating device for the Security Fabric
Explanation:
The Security Fabric root device serves as the central coordinating point for a Fortinet Security Fabric deployment. It provides visibility into connected Fabric devices and supports centralized monitoring and coordination of security information across the environment. The root device does not replace FortiSwitch hardware or function as a general file repository for endpoints. Although a FortiGate may provide DHCP services, that is not the defining purpose of the Security Fabric root role. Proper root-device configuration helps administrators maintain a consolidated view of the interconnected security infrastructure.
Question 369. Which FortiManager operation lets an administrator compare configuration differences before committing changes to a managed device?
- Device reboot
2. Log forwarding
3. Configuration revision or diff review
4. Antivirus quarantine
Answer: 3. Configuration revision or diff review
Explanation:
Configuration comparison allows administrators to identify differences between configuration states before changes are committed or installed. In centralized management environments, reviewing configuration differences helps confirm that only intended modifications will be applied to a managed FortiGate. This is especially useful when multiple administrators are working with policy packages, device settings, or revisions. Device rebooting, log forwarding, and antivirus quarantine perform different functions and do not provide configuration comparison. Reviewing revisions and differences can therefore improve change control and help identify accidental modifications before deployment.
Question 370. Which FortiGate routing attribute can influence which route is preferred when multiple routes exist for the same destination?
- Web Filter category
2. Administrative distance
3. Antivirus signature
4. DHCP lease duration
Answer: 2. Administrative distance
Explanation:
Administrative distance is used to evaluate the preference of routes learned from different routing sources. When multiple routes can reach the same destination, the route with the lower administrative distance is generally preferred over a route with a higher administrative distance, assuming other relevant routing conditions are satisfied. This helps FortiGate select between routing sources such as static routes and dynamic routing protocols. Web filtering, antivirus signatures, and DHCP lease durations do not determine route preference. Understanding administrative distance is useful when troubleshooting unexpected routing behavior.
Question 371. What is the main benefit of using a FortiGate loopback interface for routing or management functions?
- It provides an interface that remains logically available independent of a physical port state
2. It automatically replaces all firewall policies
3. It disables dynamic routing
4. It creates a new physical Ethernet port
Answer: 1. It provides an interface that remains logically available independent of a physical port state
Explanation:
A loopback interface is a logical interface that is not directly tied to a specific physical network port. Because of this characteristic, it can provide a stable IP address for certain routing, management, monitoring, or VPN-related functions even when individual physical interfaces change state. Loopback interfaces are also useful in dynamic routing designs because they can provide stable endpoint addresses. They do not create physical hardware ports, disable dynamic routing, or automatically replace firewall policies. Administrators should still ensure that appropriate routes and security policies exist for traffic using the loopback address.
Question 372. Which FortiAnalyzer feature can automatically react when a defined event or condition occurs?
- ADOM
2. Log archive
3. Event handler
4. Storage quota
Answer: 3. Event handler
Explanation:
FortiAnalyzer event handlers can identify defined events or conditions within collected security information and can support automated responses or notifications depending on the configured workflow. This allows administrators to monitor important events without manually reviewing every individual log entry. ADOMs are used to organize devices and administrative data, while log archives and storage quotas concern log storage and management. Event handlers therefore provide a mechanism for identifying significant conditions and initiating an appropriate action. Their configuration should be carefully designed to avoid excessive alerts and to focus attention on meaningful security or operational events.
Question 373. What is the purpose of FortiGate certificate revocation checking?
- To increase DHCP lease duration
2. To determine whether a certificate has been revoked by its issuing authority
3. To create firewall address groups
4. To assign VLAN identifiers
Answer: 2. To determine whether a certificate has been revoked by its issuing authority
Explanation:
Certificate revocation checking helps determine whether a digital certificate is still considered valid by its issuing certificate authority. A certificate can be revoked before its normal expiration date for reasons such as key compromise or other security concerns. Depending on the configured certificate validation method, FortiGate can use revocation information such as certificate revocation lists or supported online validation mechanisms. This improves certificate-based security by checking more than just the certificate’s expiration date. DHCP, VLAN, and firewall address-group functions do not provide certificate revocation validation.
Question 374. Which FortiGate feature can identify and control applications even when different applications use common network ports?
- Static routing
2. DHCP relay
3. Application Control
4. NTP
Answer: 3. Application Control
Explanation:
Application Control identifies applications based on application signatures and traffic characteristics rather than relying solely on TCP or UDP port numbers. This is important because multiple applications can use the same standard ports, while some applications may use dynamic or nonstandard ports. Application Control allows administrators to monitor or apply policy actions to recognized applications. Static routing determines packet paths, DHCP relay forwards DHCP requests, and NTP provides time synchronization. Application Control therefore provides a more application-aware method of controlling traffic within FortiGate security policies.
Question 375. What is the primary purpose of an IPsec VPN replay window?
- To determine acceptable packet sequence numbers and help detect replayed packets
2. To assign IP addresses to remote users
3. To select the VPN encryption algorithm automatically
4. To provide DNS resolution
Answer: 1. To determine acceptable packet sequence numbers and help detect replayed packets
Explanation:
An IPsec replay window defines an acceptable range of packet sequence numbers used when checking incoming protected traffic. This helps FortiGate recognize packets that are duplicated or arrive outside the permitted sequence range. The mechanism is designed to provide protection against replay attacks while allowing legitimate packets to arrive slightly out of order. It does not assign addresses, provide DNS resolution, or automatically choose encryption algorithms. Proper replay-window behavior is especially important in environments where network conditions can cause packet reordering while security against duplicated traffic remains necessary.
Question 376. Which FortiGate setting can restrict an administrator account from accessing the device from unapproved source addresses?
- Traffic shaper
2. Trusted hosts
3. Service group
4. VIP
Answer: 2. Trusted hosts
Explanation:
Trusted hosts allow administrators to restrict management access for an administrator account to specified source IP addresses or networks. When trusted hosts are configured, login attempts from addresses outside the approved ranges can be denied. This provides an additional layer of protection for administrative interfaces because a valid username and password alone may not be sufficient when the request originates from an unauthorized location. Traffic shapers control bandwidth, service groups organize firewall services, and VIPs provide address translation or inbound publishing. Trusted hosts are therefore specifically useful for limiting administrative access by source network.
Question 377. What is a key advantage of using an SD-WAN volume-based strategy?
- It disables all secondary WAN links
2. It converts dynamic routes into static routes
3. It can distribute traffic based on link usage or volume
4. It creates encrypted IPsec tunnels automatically
Answer: 3. It can distribute traffic based on link usage or volume
Explanation:
An SD-WAN volume-based strategy can make forwarding decisions according to traffic volume across available SD-WAN members. This can help distribute traffic more effectively when multiple WAN links are available and the administrator wants to consider utilization rather than simply selecting one fixed path. SD-WAN strategies operate within the broader SD-WAN rule and health-check framework. They do not automatically create IPsec tunnels, disable secondary links, or convert dynamic routes into static routes. The exact behavior depends on the configured SD-WAN members, rules, and performance criteria.
Question 378. What is the purpose of a FortiSwitch device authorization process when managed through FortiLink?
- To allow the FortiGate to recognize and manage the switch as an authorized device
2. To create an Internet service database
3. To configure external DNS filtering
4. To replace the FortiGate administrator account
Answer: 1. To allow the FortiGate to recognize and manage the switch as an authorized device
Explanation:
When FortiSwitch devices are managed through FortiLink, authorization establishes that the switch is permitted to participate in the managed network environment. After authorization, the FortiGate can provide centralized management and configuration functions for the connected FortiSwitch. This supports simplified administration and visibility across the Fortinet network. Device authorization does not create the Internet Service Database, configure DNS filtering, or replace administrator accounts. Administrators should verify the correct switch identity before authorizing a device, especially in environments where multiple switches may be connected or discovered.
Question 379. Which configuration is most appropriate when an administrator wants a FortiGate policy to use only a specific TCP service rather than allowing all services?
- Select ALL services
2. Disable policy logging
3. Select the required service object or service group
4. Configure an NTP server
Answer: 3. Select the required service object or service group
Explanation:
A firewall policy can restrict permitted traffic by specifying the required service object or service group. For example, an administrator can create or select a service representing a particular TCP port and then use that service in the policy. This limits the policy to the intended application protocol instead of allowing every service. Selecting ALL would broaden the policy unnecessarily, while disabling logging does not control which services are permitted. NTP configuration is unrelated to firewall service restrictions. Precise service selection is an important part of implementing least-privilege firewall policies.
Question 380. What is a useful reason to maintain multiple FortiGate configuration revisions?
- To increase interface bandwidth
2. To provide historical configuration states that can be reviewed or restored
3. To replace antivirus scanning
4. To automatically create VLAN hardware
Answer: 2. To provide historical configuration states that can be reviewed or restored
Explanation:
Configuration revisions provide historical versions of a FortiGate configuration. Maintaining revisions allows administrators to compare changes, investigate when a configuration difference was introduced, and restore a previous configuration when appropriate. This is especially valuable during controlled changes, troubleshooting, or recovery from an incorrect modification. Configuration revisions do not increase network bandwidth, replace antivirus inspection, or create physical VLAN hardware. Administrators should maintain an appropriate revision and backup strategy so that configuration history is available when operational or recovery requirements arise.