View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 321
Which FortiGate feature can authenticate users through an external LDAP directory?
- LDAP
- NTP
- SD-WAN
- IP pool
Correct Answer: 1
Explanation
LDAP integration allows FortiGate to communicate with a supported directory service for user authentication and identity information. Administrators configure the directory server details and authentication parameters so that FortiGate can validate user credentials against the external directory. This is useful when organizations already maintain centralized user accounts and do not want to create separate credentials on every FortiGate. Correct network connectivity, directory permissions, and configuration are required. Troubleshooting should include both FortiGate authentication logs and the LDAP server when authentication attempts fail.
Question 322
Which FortiGate feature can use a user’s identity when deciding whether to permit network access?
- Policy schedule
- Identity-based policy
- IP pool
- Service group
Correct Answer: 2
Explanation
An identity-based policy allows FortiGate to make access decisions using authenticated user or group information. This provides more granular control than policies based only on source IP addresses. For example, administrators can permit a particular user group to access selected internal services while restricting other groups. Identity information may come from supported authentication methods or integrations such as FSSO. Correct identity mapping is important because a stale or incorrect user-to-IP association can cause unexpected policy behavior. Administrators should review authentication and identity information when troubleshooting these policies.
Question 323
Which security profile is intended to control access to websites according to URL categories?
- Web Filter
- IPS
- Antivirus
- Traffic Shaping
Correct Answer: 1
Explanation
Web Filter controls web access according to URL categories and configured filtering rules. FortiGate can use FortiGuard web-category information to classify websites and apply actions such as allowing, blocking, or monitoring access. Administrators can also configure specific URL-related rules when category-based filtering is not sufficient. The Web Filter profile must be attached to the firewall policy handling the relevant traffic. Inspection configuration and FortiGuard connectivity can affect filtering behavior, so those settings should be checked when a website is not categorized or handled as expected.
Question 324
Which feature can prevent access to domains known to be malicious based on DNS information?
- Application Control
- DNS Filter
- VLAN
- NTP
Correct Answer: 2
Explanation
DNS Filter examines DNS requests and can block domains according to configured filtering rules and reputation information. It can help prevent users from resolving known malicious, phishing, or otherwise unwanted domains before connections are established. FortiGate can use FortiGuard DNS intelligence together with local filtering policies. DNS filtering provides an additional layer of protection alongside Web Filter, IPS, and other security controls. Administrators should verify that client DNS requests pass through the expected FortiGate-controlled path and that required FortiGuard services are available.
Question 325
Which security feature can detect and block malicious files transmitted through supported traffic?
- Antivirus
- OSPF
- SD-WAN
- RADIUS
Correct Answer: 1
Explanation
The Antivirus security profile examines supported traffic for malicious files and malware patterns. When a file matches a detected threat, FortiGate can apply the action configured in the Antivirus profile, such as blocking or logging the event. Antivirus protection works alongside other controls because different security profiles address different threat types. Administrators should verify that the relevant firewall policy has Antivirus enabled and that the inspection method provides visibility into the traffic. Current security intelligence is also important for detecting newly identified threats and maintaining effective protection.
Question 326
Which FortiGate feature detects network attacks using intrusion prevention signatures?
- Web Filter
- IPS
- DHCP
- NTP
Correct Answer: 2
Explanation
The Intrusion Prevention System, or IPS, examines network traffic for known attack patterns, exploits, and suspicious behavior. FortiGate IPS uses signatures and related detection mechanisms to identify potentially harmful traffic and can take configured actions such as blocking or logging. IPS protection is applied through suitable firewall policies and should be configured according to the traffic being protected. Administrators should keep security intelligence current and monitor IPS logs for detected events. Reviewing the triggering signature can help determine the nature of the activity and whether additional investigation is required.
Question 327
Which feature can detect an application even when it uses a port that is not normally associated with that application?
- DHCP
- Application Control
- NTP
- Address group
Correct Answer: 2
Explanation
Application Control can identify applications by analyzing traffic characteristics and application signatures rather than depending exclusively on standard TCP or UDP port numbers. This is useful because some applications may use nonstandard ports, dynamic ports, or shared services. Administrators can then apply application-specific policies even when traditional service-based filtering would not accurately identify the traffic. Proper inspection configuration is important for reliable application identification. Application Control can be combined with firewall policies and other security profiles to provide more granular control over network activity.
Question 328
Which FortiGate feature can identify devices connected to a network and provide device information for visibility?
- Device detection
- Traffic shaping
- IP pool
- Policy schedule
Correct Answer: 1
Explanation
Device detection provides visibility into endpoints observed by FortiGate and can identify characteristics such as device type or operating-system information when sufficient data is available. This helps administrators discover devices and investigate unexpected endpoints on network segments. Detection information can support broader network-access and security decisions, although it should not automatically be considered a definitive identity proof. Administrators should validate important access decisions using appropriate authentication or endpoint controls. Regularly reviewing detected devices can also help identify unmanaged systems or unexpected network activity.
Question 329
Which feature can prevent users from accessing a particular category of websites while allowing other categories?
- Web Filter
- BGP
- IPsec Phase 2
- NTP
Correct Answer: 1
Explanation
Web Filter allows administrators to control website access based on URL categories and filtering rules. A Web Filter profile can be configured to block selected categories while allowing other website categories required for business operations. FortiGuard category information can help classify destinations, while local rules can provide additional control. The profile must be attached to the firewall policy handling the relevant traffic. Administrators should consider inspection settings and category classification when investigating unexpected access. Logging can help identify which websites were blocked and which filtering rule produced the decision.
Question 330
Which FortiGate feature can provide a logical interface for traffic belonging to a specific VLAN?
- VLAN interface
- Service group
- IP pool
- FortiToken
Correct Answer: 1
Explanation
A VLAN interface provides a logical Layer 3 interface associated with a configured VLAN identifier. FortiGate can use these interfaces to route traffic between VLANs and apply separate firewall policies to each logical network. VLAN interfaces are commonly used for segmentation, allowing departments, servers, guests, or other network groups to have different access controls. The VLAN ID, parent interface, switch configuration, and addressing must be consistent. If communication fails, administrators should verify VLAN tagging, interface status, routing, and the firewall policies controlling traffic between the segments.
Question 331
Which routing protocol is commonly used for dynamic routing within a single autonomous system?
- OSPF
- BGP
- RADIUS
- LDAP
Correct Answer: 1
Explanation
OSPF is an interior gateway protocol commonly used for dynamic routing within an organization’s autonomous system. It is a link-state protocol that exchanges topology information between neighboring routers and calculates suitable paths through the network. FortiGate can participate in OSPF and advertise or learn routes dynamically. Proper neighbor relationships, interface configuration, area assignment, and network reachability are important for successful operation. Administrators troubleshooting OSPF should examine neighbor status and routing information to determine whether routes are being exchanged as expected.
Question 332
Which routing protocol is designed to exchange routing information between autonomous systems?
- DHCP
- OSPF
- BGP
- NTP
Correct Answer: 3
Explanation
BGP is the routing protocol designed for exchanging routing information between autonomous systems. It uses routing attributes and policies to control which routes are accepted, preferred, or advertised. FortiGate can participate in BGP environments where controlled route exchange is required. Administrators must carefully configure neighbors, authentication where applicable, network advertisements, and route policies. Incorrect BGP configuration can result in unexpected route propagation or loss of connectivity. Reviewing received and advertised routes is an important troubleshooting step when a BGP session is established but routing does not behave as expected.
Question 333
Which FortiGate feature can monitor WAN link latency, jitter, and packet loss?
- Performance SLA
- Address group
- Web Filter
- Administrator profile
Correct Answer: 1
Explanation
Performance SLA provides health measurements for SD-WAN members and can evaluate characteristics such as latency, jitter, packet loss, and availability depending on the configured probe and criteria. These measurements help FortiGate determine whether a WAN path meets the requirements defined by an SD-WAN rule. Administrators should configure thresholds that reflect actual application needs rather than choosing arbitrary values. When a path repeatedly fails an SLA, the administrator can investigate the underlying WAN connection or allow SD-WAN to select another suitable member according to the configured strategy.
Question 334
A company wants voice traffic to use a WAN path with low jitter. Which FortiGate feature can help enforce this requirement?
- Address group
- SD-WAN rule
- DNS Filter
- Administrator profile
Correct Answer: 2
Explanation
An SD-WAN rule can identify voice traffic and associate it with appropriate WAN path-selection requirements. When combined with a Performance SLA that measures jitter, the rule can favor a WAN member that meets the configured performance conditions. This helps maintain better consistency for real-time applications that are sensitive to variable packet delay. Administrators should also consider latency, packet loss, and link availability when designing the SLA. Correct application identification and SD-WAN rule ordering are important so that voice traffic receives the intended path-selection behavior.
Question 335
Which component of an IPsec VPN is negotiated after the initial IKE security channel is established?
- Phase 2
- DHCP
- RADIUS
- NTP
Correct Answer: 1
Explanation
IPsec Phase 2 is negotiated after the initial IKE Phase 1 exchange has successfully established a secure management channel. Phase 2 creates the security association used to protect actual data traffic and negotiates parameters such as encryption, authentication, and traffic selectors. If Phase 1 is established but protected traffic does not pass, administrators should inspect Phase 2 configuration as well as routing and firewall policies. Both peers need compatible settings for the intended traffic. Troubleshooting should also confirm that the required networks are included in the traffic selectors.
Question 336
Which VPN technology provides encrypted connectivity between two fixed network locations?
- Remote-access VPN
- Site-to-site IPsec VPN
- Web Filter
- Traffic shaping
Correct Answer: 2
Explanation
A site-to-site IPsec VPN creates an encrypted connection between two network gateways, allowing private networks at different locations to communicate securely over an untrusted network. FortiGate can establish these tunnels using IKE and IPsec security associations. Administrators need compatible Phase 1 and Phase 2 settings, correct traffic selectors, routing, and firewall policies. Site-to-site VPNs are different from remote-access VPNs, which are designed to connect individual users or devices to an organization’s network. Monitoring tunnel status and protected traffic helps verify reliable connectivity.
Question 337
Which FortiGate feature can map an external address and port to an internal server?
- VIP
- NTP
- OSPF
- Service group
Correct Answer: 1
Explanation
A Virtual IP, or VIP, can map a public-facing address and port to an internal server and service. This allows selected services such as web applications to be accessed from outside the network while the server continues using a private address internally. The VIP normally works together with a firewall policy that permits the required incoming traffic. Administrators should publish only necessary services and restrict sources where practical. When troubleshooting a VIP, the address mapping, port configuration, firewall policy, routing, and server availability should all be checked.
Question 338
Which feature can translate multiple private client addresses to a public address for Internet access?
- Source NAT
- IPS
- VLAN
- LDAP
Correct Answer: 1
Explanation
Source NAT changes the source address of outbound traffic, commonly translating private internal addresses to an external address used for Internet access. FortiGate can perform source NAT using the outgoing interface address or configured address resources such as an IP pool, depending on policy requirements. This allows many internal clients to communicate with external destinations without exposing their private addresses directly. Source NAT does not encrypt traffic, so it should not be confused with VPN protection. Administrators should verify policy NAT settings and return routing when troubleshooting outbound connectivity.
Question 339
Which feature can provide multiple public addresses for source NAT instead of using only the outgoing interface address?
- IP pool
- Service group
- VLAN
- Policy schedule
Correct Answer: 1
Explanation
An IP pool provides a configured range or collection of addresses that can be used for source NAT. This is useful when an organization has multiple public addresses and wants translated traffic to use specific addresses rather than relying solely on the outgoing interface address. The IP pool can be associated with suitable firewall policy NAT configuration. Administrators should ensure that the public addresses are correctly routed and that return traffic can reach the FortiGate. The choice of IP pool behavior should match the organization’s addressing and application requirements.
Question 340
Which feature can prevent a firewall administrator from modifying settings outside the permissions assigned to the account?
- Administrator profile
- Performance SLA
- DNS Filter
- IP pool
Correct Answer: 1
Explanation
Administrator profiles control the permissions assigned to FortiGate administrator accounts. A profile can limit access to specific configuration areas and provide read-only or read-write privileges according to the administrator’s role. This supports role-based access control and the principle of least privilege. For example, a monitoring administrator may be allowed to view information without changing firewall policies. Restricting privileges reduces the risk of unauthorized or accidental configuration changes. Administrators should regularly review profiles and remove unnecessary permissions when responsibilities change.