View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps
Question 141. What is the primary purpose of a FortiGate automation stitch?
- To replace all firewall policies
2. To create physical network interfaces
3. To automatically perform an action when a configured event occurs
4. To provide DHCP addresses to clients
Answer: 3. To automatically perform an action when a configured event occurs
Explanation:
An automation stitch allows FortiGate to respond automatically when a specified trigger or event occurs. A trigger can be associated with an action, allowing the device to perform tasks without requiring an administrator to intervene manually each time. Depending on the configuration, actions can include sending notifications, executing commands, or interacting with external services. Automation stitches can therefore improve operational efficiency and response consistency. They do not replace firewall policies, create physical interfaces, or function as DHCP servers. Their main purpose is event-driven automation.
Question 142. Which action can be used by a FortiGate automation stitch to notify an external system?
- Webhook
2. VLAN tagging
3. Static routing
4. DHCP relay
Answer: 1. Webhook
Explanation:
A webhook action can send information from FortiGate to an external web service when a configured automation trigger occurs. This can be useful for integrating FortiGate events with external monitoring, notification, or automation platforms. The receiving service can then process the event according to its own configuration. Webhooks are therefore useful when network security events need to be communicated outside the FortiGate environment. VLAN tagging, static routing, and DHCP relay perform networking functions and do not provide the same event-notification mechanism.
Question 143. What is the purpose of FortiGate device identification?
- To assign administrator passwords
2. To identify devices connected to the network
3. To create IPsec encryption keys
4. To replace DNS filtering
Answer: 2. To identify devices connected to the network
Explanation:
FortiGate device identification helps administrators obtain information about devices communicating through the firewall. Depending on available traffic information and configuration, FortiGate can identify device characteristics that can support more granular security policies and monitoring. Device awareness can be particularly useful in environments where administrators need to distinguish different endpoint types or categories. This information can contribute to access control and security visibility. Device identification is separate from administrator authentication, IPsec key exchange, and DNS filtering because its primary purpose is understanding connected endpoints.
Question 144. Which FortiGate capability can be used to control access based on a user’s membership in an identity group?
- User group-based firewall policy
2. Interface speed setting
3. Static ARP entry
4. System time zone
Answer: 1. User group-based firewall policy
Explanation:
FortiGate firewall policies can use authenticated users or user groups as part of their matching criteria. This allows administrators to apply different access rules depending on group membership. For example, one group may be permitted to access specific internal applications while another group receives different restrictions. User-based policies require appropriate authentication or identity integration so FortiGate can determine the user’s identity. Interface speed, ARP entries, and time-zone settings serve different purposes and do not provide user-group-based access control.
Question 145. What is the main purpose of FortiGate’s ARP table?
- To store mappings between IPv4 addresses and MAC addresses
2. To store administrator passwords
3. To configure antivirus signatures
4. To define web-filter categories
Answer: 1. To store mappings between IPv4 addresses and MAC addresses
Explanation:
The ARP table contains mappings between IPv4 addresses and corresponding Layer 2 MAC addresses that FortiGate has learned or configured. These mappings help the device determine where Ethernet frames should be delivered on directly connected networks. Examining the ARP table can be useful when troubleshooting local connectivity, duplicate addresses, or unexpected Layer 2 behavior. It is not a database for administrator passwords, antivirus signatures, or web-filter categories. Understanding ARP is particularly important when diagnosing situations where routing appears correct but local communication still fails.
Question 146. What is the purpose of administrator trusted hosts on FortiGate?
- To define networks from which a specific administrator account is permitted to log in
2. To create VPN encryption algorithms
3. To inspect application traffic
4. To assign DHCP addresses
Answer: 1. To define networks from which a specific administrator account is permitted to log in
Explanation:
Administrator trusted hosts restrict administrative access based on the source IP address or network from which a login attempt originates. This provides an additional security layer because valid credentials alone may not be sufficient if the connection comes from an unauthorized network. Trusted hosts can be configured for administrator accounts according to the organization’s management architecture. This control is separate from VPN encryption, application inspection, and DHCP services. Restricting management access to known administrative networks can reduce exposure of the FortiGate management interface.
Question 147. What is the purpose of a FortiGate file filter security profile?
- To identify and control files based on configured file characteristics or types
2. To calculate routing metrics
3. To create IPsec tunnels
4. To synchronize system clocks
Answer: 1. To identify and control files based on configured file characteristics or types
Explanation:
A file filter security profile can help administrators control file transfers according to configured criteria. Organizations may use file filtering to restrict certain file types or reduce the risk associated with unwanted content being transferred through network traffic. The feature can complement other security controls such as antivirus and web filtering. Routing metrics, IPsec tunnels, and NTP synchronization address entirely different functions. File filtering is therefore useful when an organization wants an additional layer of control over files transferred through inspected traffic.
Question 148. Which FortiGate feature provides a visual representation of network topology and connected Fortinet devices?
- Security Fabric topology
2. DHCP server
3. IP pool
4. Service object
Answer: 1. Security Fabric topology
Explanation:
Security Fabric topology provides visibility into connected Fortinet devices and their relationships within a Security Fabric environment. It can help administrators understand how participating security devices are connected and identify components that may require attention. This centralized visibility is useful in environments containing multiple Fortinet products. A DHCP server provides IP configuration, an IP pool supplies addresses for specific translation requirements, and service objects define protocol or port information. None of these functions primarily provides a graphical representation of the Security Fabric environment.
Question 149. What does FortiGate conserve mode indicate?
- The device is operating under high memory pressure
2. The firewall has no active interfaces
3. All VPN tunnels have been permanently deleted
4. The device has disabled routing
Answer: 1. The device is operating under high memory pressure
Explanation:
Conserve mode is associated with high memory usage on a FortiGate. When available memory becomes critically low, FortiGate can take protective measures intended to preserve system stability. Administrators should investigate the source of the memory pressure, which may involve traffic levels, processes, sessions, logs, or other system conditions. Conserve mode does not mean that interfaces have necessarily failed or that routing has been disabled. Monitoring system resources and identifying unusual memory consumption are important steps when a FortiGate enters a memory-constrained state.
Question 150. What is the purpose of FortiGate system resource monitoring?
- To configure user passwords automatically
2. To monitor CPU, memory, sessions, and other system resources
3. To replace firewall policies
4. To generate IPsec certificates automatically
Answer: 2. To monitor CPU, memory, sessions, and other system resources
Explanation:
System resource monitoring provides information about the operational condition of the FortiGate. Administrators can examine resources such as CPU utilization, memory usage, active sessions, and other relevant system statistics. This information can help identify resource constraints and investigate performance-related issues. High utilization does not automatically identify a specific root cause, so administrators may need to correlate resource information with traffic, logs, and configuration. Resource monitoring is a diagnostic and operational visibility function rather than a replacement for firewall policies or a certificate-generation mechanism.
Question 151. What is the primary purpose of FortiGate application control?
- To identify and control applications in network traffic
2. To assign IP addresses to interfaces
3. To synchronize administrator accounts
4. To create physical network cables
Answer: 1. To identify and control applications in network traffic
Explanation:
Application Control allows FortiGate to identify applications within network traffic and apply configured actions to them. This enables administrators to create policies based on application behavior rather than relying only on IP addresses and ports. Organizations can use application control to allow, monitor, or restrict selected applications according to their security requirements. Proper inspection and policy configuration are important because application identification can depend on the traffic and inspection context. Application Control is therefore focused on application visibility and control, not address assignment or physical connectivity.
Question 152. Which FortiGate setting can be used to provide additional authentication protection for administrators?
- Administrator profile
2. Multi-factor authentication
3. Service group
4. Static route
Answer: 2. Multi-factor authentication
Explanation:
Multi-factor authentication adds an additional verification factor beyond a username and password. When enabled for supported administrator authentication workflows, users may need to provide another factor such as a token or verification code. This reduces reliance on passwords alone and can strengthen protection of administrative access. Administrator profiles control permissions after authentication, while service groups and static routes perform unrelated configuration functions. MFA should be combined with other administrative security controls, such as trusted hosts and least-privilege administrator profiles, where appropriate.
Question 153. What is the main purpose of a FortiGate service group?
- To combine multiple service objects into one reusable group
2. To combine multiple administrators into one account
3. To synchronize VPN certificates
4. To monitor CPU usage
Answer: 1. To combine multiple service objects into one reusable group
Explanation:
A service group allows multiple service objects to be grouped together so they can be referenced more conveniently in firewall policies. For example, an administrator may create a group containing several TCP or UDP services that are commonly permitted together. This reduces repetitive configuration and can make firewall policies easier to manage. Service groups are different from administrator groups because they represent network services rather than user identities. They also do not perform certificate synchronization or system monitoring. Reusable service objects can improve consistency in firewall policy design.
Question 154. What is the primary purpose of a GRE tunnel?
- To encapsulate one network protocol inside another IP tunnel
2. To provide antivirus scanning
3. To authenticate administrators
4. To allocate DHCP addresses
Answer: 1. To encapsulate one network protocol inside another IP tunnel
Explanation:
Generic Routing Encapsulation, or GRE, provides a mechanism for encapsulating network traffic inside an IP tunnel. GRE can be used to transport certain protocols or routing traffic between endpoints across an IP network. GRE itself does not provide encryption, so it may be combined with technologies such as IPsec when confidentiality and integrity protection are required. Antivirus scanning, administrator authentication, and DHCP address assignment are unrelated functions. Understanding GRE is useful when designing networks that require logical tunnels between geographically separated or otherwise connected networks.
Question 155. Which FortiGate feature can help identify and analyze high-volume traffic sources and destinations?
- FortiView
2. DHCP relay
3. Certificate store
4. IPsec Phase 2
Answer: 1. FortiView
Explanation:
FortiView provides visual analytics that can help administrators examine network traffic and security activity. Depending on the available data and configuration, administrators can review traffic by sources, destinations, applications, interfaces, and other categories. This can help identify high-volume traffic and investigate unusual patterns. FortiView is primarily intended for visibility and analysis rather than packet forwarding or encryption. DHCP relay handles DHCP requests, certificate stores manage certificates, and IPsec Phase 2 defines parameters for protected VPN traffic. These functions serve different purposes within FortiGate.
Question 156. What is the purpose of a FortiGate certificate authority (CA. certificate?
- To establish trust for certificates signed by the corresponding authority
2. To assign MAC addresses to clients
3. To calculate OSPF routes
4. To create VLAN identifiers
Answer: 1. To establish trust for certificates signed by the corresponding authority
Explanation:
A certificate authority certificate allows FortiGate to establish trust relationships for certificates issued or signed by that authority. Certificate validation is important for security functions involving encrypted communications, authentication, and inspection. When FortiGate trusts the appropriate CA, it can validate certificate chains according to the configured trust model. CA certificates do not assign MAC addresses, calculate routing paths, or create VLAN identifiers. Administrators should maintain an appropriate certificate trust store and ensure certificates are valid and properly managed for the security functions that depend on them.
Question 157. What does an IPS sensor primarily define on FortiGate?
- Rules and signatures used to detect and handle suspicious network activity
2. IP address assignments for DHCP clients
3. Physical interface speed
4. Administrator login names
Answer: 1. Rules and signatures used to detect and handle suspicious network activity
Explanation:
An Intrusion Prevention System sensor contains configuration that determines how FortiGate’s IPS engine handles detected signatures and related security events. Administrators can configure appropriate actions for traffic matching relevant intrusion signatures. The sensor is then applied through applicable security policies so traffic can be inspected. IPS configuration is separate from DHCP address assignment, interface speed settings, and administrator account management. A properly configured IPS sensor helps the firewall identify potentially malicious traffic and take the configured action, such as monitoring or blocking.
Question 158. Which diagnostic information is especially useful for determining whether a FortiGate route exists toward a destination?
- Routing table or route lookup information
2. Antivirus quarantine list
3. Administrator profile
4. Web-filter replacement message
Answer: 1. Routing table or route lookup information
Explanation:
The routing table and route lookup information show how FortiGate determines the next hop or outgoing interface for a destination. When troubleshooting connectivity, administrators can verify whether an appropriate route exists and whether the selected path matches the expected network design. If no suitable route exists, traffic may fail before firewall policy processing can provide the expected result. Antivirus quarantine lists, administrator profiles, and replacement messages do not determine the network path. Route verification is therefore an important early step when investigating destination reachability problems.
Question 159. What is the purpose of hardware acceleration on supported FortiGate platforms?
- To improve packet-processing efficiency by using specialized hardware
2. To create administrator accounts
3. To replace DNS services
4. To generate user passwords
Answer: 1. To improve packet-processing efficiency by using specialized hardware
Explanation:
Supported FortiGate platforms may use specialized processing hardware to accelerate certain network and security operations. Hardware acceleration can improve packet-processing efficiency and reduce the processing burden on the general-purpose CPU for supported traffic and functions. The exact acceleration behavior depends on the FortiGate platform, traffic type, inspection method, and configuration. Hardware acceleration is therefore primarily a performance-related capability. It does not create administrator accounts, provide DNS services, or generate passwords. Administrators should consider supported acceleration behavior when analyzing performance and troubleshooting traffic-processing issues.
Question 160. What is the purpose of object dependency checking when modifying FortiGate configuration objects?
- To identify configurations that reference an object before it is changed or removed
2. To increase Internet bandwidth automatically
3. To disable all firewall inspection
4. To reset administrator passwords
Answer: 1. To identify configurations that reference an object before it is changed or removed
Explanation:
Object dependency checking helps administrators determine whether an address, service, interface, or other configuration object is referenced by other parts of the FortiGate configuration. This is important before modifying or deleting an object because removing a referenced object can affect firewall policies or other dependent settings. Understanding dependencies reduces the risk of accidental configuration changes and unexpected traffic behavior. Dependency checking does not increase bandwidth, disable inspection, or reset administrator credentials. It is primarily a configuration-management aid that supports safer changes to an active firewall.