Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part16 Q301-320

View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 301

Which FortiGate feature can limit administrative access based on the source IP address of the administrator?

  1. Trusted hosts
  2. Traffic shaping
  3. Application Control
  4. Service group

Correct Answer: 1

Explanation

Trusted hosts restrict where an administrator account can connect from by defining approved source IP addresses or networks. This adds an access-control layer beyond username and password authentication. For example, management accounts can be limited to a dedicated administrative subnet rather than being accessible from general user networks. Administrators should configure trusted hosts carefully because an incorrect address can prevent legitimate management access. Trusted hosts work alongside administrator profiles, authentication controls, and interface management settings to provide stronger protection for FortiGate administrative services.

Question 302

Which FortiGate feature can identify applications and apply different actions to them?

  1. NTP
  2. Application Control
  3. DHCP
  4. IP pool

Correct Answer: 2

Explanation

Application Control identifies network applications using traffic characteristics and application signatures. Administrators can create Application Control profiles that monitor, allow, or block selected applications and categories. This provides more granular control than simply filtering traffic by TCP or UDP port because applications may use shared or nonstandard ports. Application Control is normally associated with firewall policies so that the selected profile is applied to matching traffic. Administrators should verify inspection requirements and application detection when troubleshooting traffic that is not being identified as expected.

Question 303

What is the primary purpose of FortiGuard services in a FortiGate security deployment?

  1. Provide threat intelligence and security updates
  2. Assign VLAN identifiers
  3. Configure static routes
  4. Synchronize administrator passwords

Correct Answer: 1

Explanation

FortiGuard services provide security intelligence and updates that support multiple Fortinet security features. Depending on the service, this intelligence can include information used for web categorization, application identification, antivirus protection, intrusion prevention, DNS filtering, and other security functions. Keeping relevant FortiGuard services current helps FortiGate make security decisions using updated information. Administrators should verify licensing, connectivity, and update status when a security profile does not appear to have current intelligence. FortiGuard complements locally configured security policies rather than replacing them.

Question 304

A FortiGate policy should permit users to access a service only during business hours. What should the administrator configure?

  1. Service group
  2. Address object
  3. Policy schedule
  4. IP pool

Correct Answer: 3

Explanation

A policy schedule allows administrators to define when a firewall policy is active. A schedule can specify recurring periods during which matching traffic is permitted or otherwise handled by the policy. This is useful for business-hour access, temporary services, maintenance windows, or time-based restrictions. Administrators should verify the FortiGate system clock when troubleshooting schedule behavior because an incorrect device time can cause policies to become active or inactive unexpectedly. Policy order should also be reviewed because another rule may handle the same traffic.

Question 305

Which feature allows FortiGate to authenticate administrators or users through a centralized RADIUS server?

  1. RADIUS
  2. OSPF
  3. VIP
  4. NTP

Correct Answer: 1

Explanation

RADIUS provides centralized authentication services that FortiGate can use for supported administrator or user authentication workflows. Instead of maintaining authentication information only on FortiGate, credentials can be validated through an external RADIUS server. This can simplify account management and integrate FortiGate with an organization’s existing authentication infrastructure. Correct server addressing, shared secrets, authentication settings, and network connectivity are required. When authentication fails, administrators should examine both FortiGate authentication logs and the RADIUS server configuration to determine where the request is being rejected.

Question 306

Which feature can help FortiGate identify users logged into a Windows domain environment?

  1. IP pool
  2. FSSO
  3. SD-WAN
  4. Traffic shaping

Correct Answer: 2

Explanation

Fortinet Single Sign-On, or FSSO, provides FortiGate with user identity information from supported Windows and directory environments. This information can then be used in identity-based firewall policies, allowing access decisions to be associated with users or groups instead of only IP addresses. FSSO can reduce the need for users to repeatedly authenticate directly to the firewall in supported deployments. Administrators should verify collector configuration, directory integration, and current user-to-IP mappings when troubleshooting identity-based access decisions.

Question 307

Which feature can protect FortiGate management services from unauthorized connections directed at the firewall itself?

  1. Local-in policy
  2. Web Filter
  3. Service group
  4. IP pool

Correct Answer: 1

Explanation

Local-in policies control traffic destined for the FortiGate itself rather than traffic being forwarded through it. They can be used to restrict access to services exposed on FortiGate interfaces, including management-related services and other local services. This provides an additional security layer for protecting the firewall as a device. Administrators can define appropriate sources, interfaces, services, and actions according to the environment. Careful testing is important because an overly restrictive local-in policy can block legitimate administrative or operational traffic required to manage the firewall.

Question 308

Which FortiGate feature can inspect web traffic and enforce URL-category restrictions?

  1. Application Control
  2. Web Filter
  3. DHCP
  4. OSPF

Correct Answer: 2

Explanation

Web Filter provides controls for managing access to websites using URL categories and filtering rules. FortiGate can use FortiGuard web-category information to classify websites and apply configured actions to matching requests. Administrators can also configure specific filtering rules where required. The Web Filter profile must be attached to the appropriate firewall policy, and the relevant traffic must be handled through a compatible inspection configuration. Web filtering is useful for controlling access to categories such as malicious, phishing, or inappropriate websites while allowing required business content.

Question 309

Which feature is designed to detect malicious network activity by comparing traffic against intrusion signatures?

  1. Antivirus
  2. IPS
  3. DNS Filter
  4. Web Filter

Correct Answer: 2

Explanation

Intrusion Prevention System, or IPS, analyzes network traffic for patterns associated with known attacks, exploits, and suspicious behavior. FortiGate IPS uses signatures and related detection mechanisms to identify potentially malicious traffic and can apply configured actions such as blocking or logging. IPS is different from Antivirus, which primarily focuses on malicious files and malware content. Administrators should maintain current security intelligence and select appropriate IPS settings for the environment. IPS logs can provide details about detected signatures and help determine whether further investigation is necessary.

Question 310

Which NAT mechanism is commonly used to allow external clients to reach an internal web server?

  1. Source NAT
  2. IP pool
  3. VIP
  4. Traffic shaping

Correct Answer: 3

Explanation

A Virtual IP, or VIP, is commonly used to map a public-facing address and port to an internal server. This destination NAT mechanism allows external clients to access a selected internal service without directly exposing the server’s private address. An appropriate firewall policy must permit the incoming traffic, and administrators should restrict published services to only those that are required. Security inspection can also be applied where appropriate. When troubleshooting VIP access, administrators should verify the VIP mapping, firewall policy, routing, and service port configuration.

Question 311

Which FortiGate feature provides centralized control of policies across multiple managed FortiGate devices?

  1. FortiWeb
  2. FortiAnalyzer
  3. FortiManager
  4. FortiEDR

Correct Answer: 3

Explanation

FortiManager provides centralized management for multiple FortiGate devices. It allows administrators to organize managed devices, maintain policy packages, manage configuration revisions, and deploy changes from a central platform. This is especially useful when an organization operates many FortiGate appliances and needs consistent policy administration. FortiManager has a different primary role from FortiAnalyzer, which focuses on log collection, analysis, and reporting. Because centralized changes can affect multiple devices, administrators should use appropriate change-control procedures and validate policy deployments carefully.

Question 312

Which feature provides centralized collection and analysis of logs from Fortinet devices?

  1. FortiManager
  2. FortiAnalyzer
  3. FortiWeb
  4. FortiToken

Correct Answer: 2

Explanation

FortiAnalyzer provides centralized log collection, analysis, reporting, and security-event visibility for supported Fortinet products. Instead of examining each FortiGate individually, administrators can use centralized records to investigate historical activity, correlate events, and generate reports. FortiAnalyzer is particularly valuable for security monitoring and incident investigation where long-term log information is required. Its role differs from FortiManager, which focuses primarily on configuration and policy management. Effective use requires appropriate log forwarding, storage, retention, and access-control configuration.

Question 313

A network contains several departments that must remain logically separated. Which technology can provide the required segmentation?

  1. VLAN
  2. RADIUS
  3. NTP
  4. FortiToken

Correct Answer: 1

Explanation

VLANs provide logical Layer 2 segmentation by separating traffic into different broadcast domains. Organizations can use separate VLANs for departments, servers, guests, voice systems, or other security zones. FortiGate can provide VLAN interfaces and enforce firewall policies between these segments. Segmentation reduces unnecessary direct communication and can limit the spread of threats between network areas. Administrators should ensure that VLAN identifiers, switch trunk configuration, addressing, routing, and firewall policies are consistent. Proper segmentation is especially effective when combined with least-privilege access rules.

Question 314

Which SD-WAN measurement indicates how much traffic is being lost on a network path?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Availability

Correct Answer: 3

Explanation

Packet loss measures the percentage or amount of traffic that fails to reach its intended destination during a network test. High packet loss can significantly affect applications, particularly voice, video, and interactive services. FortiGate SD-WAN Performance SLAs can monitor packet loss along with other link characteristics such as latency and jitter. Administrators can configure thresholds that determine whether a path meets the requirements of an SD-WAN rule. Packet loss should be considered together with other performance measurements because a single metric does not always represent overall link quality.

Question 315

Which IPsec component specifies the source and destination networks protected by a VPN security association?

  1. Traffic selectors
  2. Administrator profile
  3. Service group
  4. Policy schedule

Correct Answer: 1

Explanation

IPsec traffic selectors define the source and destination traffic that should be protected by the Phase 2 security association. They identify the network ranges or addresses that are permitted to use the negotiated IPsec protection. Compatible selectors are required between the VPN peers for the intended traffic to pass. If a tunnel appears established but particular networks cannot communicate, administrators should verify selectors along with routing and firewall policies. Incorrect selectors can result in only some traffic being protected or in the expected traffic failing to use the VPN.

Question 316

Which FortiGate function can display currently active sessions between network endpoints?

  1. FortiView
  2. Session monitor
  3. FortiAnalyzer
  4. Web Filter

Correct Answer: 2

Explanation

The session monitor provides information about active sessions currently handled by FortiGate. Administrators can use it to examine live connections and understand which hosts are communicating through the firewall. This can help verify whether traffic is currently passing and assist with troubleshooting unexpected connections. Session monitoring focuses on current session state, whereas FortiAnalyzer is intended for centralized historical log analysis. Administrators can combine session information with policy lookup, routing information, packet capture, or debug flow when more detailed troubleshooting is required.

Question 317

Which diagnostic method captures the actual packets seen by a FortiGate interface?

  1. Policy lookup
  2. Packet capture
  3. Debug flow
  4. Routing table

Correct Answer: 2

Explanation

Packet capture allows administrators to inspect actual packets observed on a FortiGate interface. Captured packets can reveal source and destination addresses, protocols, ports, flags, and other information useful for diagnosing connectivity problems. This can help determine whether traffic reaches FortiGate and whether responses return as expected. Administrators should normally apply filters to capture only relevant traffic and should handle captured data securely because it may contain sensitive information. Packet capture complements tools such as debug flow, which provides information about firewall packet processing.

Question 318

Which troubleshooting tool provides detailed information about how FortiGate processes selected packets?

  1. FortiView
  2. Packet capture
  3. Debug flow
  4. Web Filter

Correct Answer: 3

Explanation

Debug flow provides detailed diagnostic information about how selected traffic is processed by FortiGate. It can help administrators examine policy matching, routing decisions, and other processing stages when a connection behaves unexpectedly. Administrators can filter the debug operation to specific traffic so that the output remains focused and useful. Debug flow differs from packet capture because packet capture shows the actual packets observed, while debug flow explains aspects of FortiGate’s internal packet-processing path. Debugging should be stopped after the required information has been collected.

Question 319

Which FortiGate feature can provide graphical visibility into applications, traffic sources, and destinations?

  1. FortiManager
  2. FortiAuthenticator
  3. FortiView
  4. FortiWeb

Correct Answer: 3

Explanation

FortiView provides interactive visibility into traffic and security activity directly through the FortiGate management interface. It can display information such as applications, sources, destinations, sessions, and traffic volumes, helping administrators identify patterns and investigate unusual activity. FortiView is primarily an operational monitoring and visualization feature rather than a replacement for centralized historical logging. When deeper historical analysis across multiple devices is required, FortiAnalyzer may be more appropriate. Administrators can use FortiView together with logs and diagnostic tools during active troubleshooting.

Question 320

Which Fortinet product protects endpoints by providing detection and response capabilities on endpoint systems?

  1. FortiAnalyzer
  2. FortiManager
  3. FortiWeb
  4. FortiEDR

Correct Answer: 4

Explanation

FortiEDR provides endpoint detection and response capabilities designed to monitor endpoint activity and help organizations detect and respond to threats on endpoint systems. It complements network security controls by providing visibility into activity occurring directly on workstations and servers. FortiEDR has a different primary role from FortiGate, FortiManager, and FortiAnalyzer, which focus on network security, centralized management, and centralized log analysis respectively. Effective endpoint protection requires appropriate deployment, policies, monitoring, and response procedures to address suspicious endpoint activity.