Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part5 Q81-100

View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 81

Which FortiGate feature allows administrators to inspect traffic and determine which applications are being used?

  1. Application Control
  2. DHCP
  3. IP pool
  4. Static route

Correct Answer: 1

Explanation

Application Control identifies network applications based on FortiGate application signatures and inspection capabilities. It allows administrators to monitor, allow, block, or otherwise control applications according to organizational requirements. This provides more granular visibility than simply filtering traffic by port because applications may use dynamic or nonstandard ports. Application Control can be combined with traffic shaping and other security profiles to manage application usage. Administrators should ensure that appropriate inspection is enabled and that FortiGuard application signatures remain current for accurate identification.

Question 82

Which FortiGate feature can detect and block malicious domains at the DNS level?

  1. DNS Filter
  2. IPS
  3. Antivirus
  4. Traffic Shaping

Correct Answer: 1

Explanation

DNS Filter allows FortiGate to inspect DNS requests and apply filtering decisions based on domain categories, reputation, and configured policies. When a client requests a domain identified as malicious or prohibited, FortiGate can block the request or apply another configured action. This provides an additional security layer before a connection to the destination is established. DNS filtering is useful against phishing, malware, and unwanted content, but it does not inspect all content within an established session. It should therefore complement other web and security controls.

Question 83

What is the main purpose of an SSL inspection profile on FortiGate?

  1. Inspect encrypted traffic
  2. Assign IP addresses
  3. Create VLANs
  4. Manage administrators

Correct Answer: 1

Explanation

SSL inspection enables FortiGate to inspect encrypted SSL/TLS traffic according to the configured inspection mode. Without suitable inspection, security controls may have limited visibility into encrypted sessions. Depending on the mode, FortiGate can inspect certificates or decrypt traffic for deeper content inspection. Deep inspection requires appropriate certificate deployment and can affect applications that use certificate pinning or other security mechanisms. Administrators should balance security requirements with privacy, legal, performance, and compatibility considerations when deploying SSL inspection.

Question 84

Which SSL inspection mode primarily examines the certificate information of an encrypted session without decrypting the complete application content?

  1. Deep inspection
  2. Certificate inspection
  3. Full proxy inspection
  4. Content inspection

Correct Answer: 2

Explanation

Certificate inspection examines information contained in SSL/TLS certificates without performing full decryption of the application payload. It can provide visibility into certificate properties and help enforce certain certificate-based policies while avoiding some of the complexity associated with deep inspection. Because the encrypted content remains protected from full inspection, certificate inspection provides less visibility than deep inspection. Administrators should select the inspection mode according to the required security visibility, application compatibility, privacy considerations, and organizational policy.

Question 85

Which inspection mode allows FortiGate to decrypt HTTPS traffic and inspect its contents?

  1. Certificate inspection
  2. Deep inspection
  3. DNS inspection
  4. Header inspection

Correct Answer: 2

Explanation

Deep inspection allows FortiGate to decrypt and inspect encrypted traffic so that security profiles can analyze the underlying content. After inspection, traffic can be re-encrypted toward the destination. This provides greater visibility for antivirus, web filtering, application control, and other security mechanisms. Deep inspection requires careful certificate management because client devices must trust the certificate authority used by FortiGate for inspection. Administrators should also consider privacy requirements, application compatibility, performance impact, and exceptions for services that cannot operate correctly under deep inspection.

Question 86

Which FortiGate feature can identify and control websites based on their content category?

  1. Web Filter
  2. IPsec
  3. SD-WAN
  4. DHCP

Correct Answer: 1

Explanation

Web Filter provides category-based control over web resources. FortiGate can use FortiGuard web categorization and administrator-defined rules to allow, monitor, or block websites based on categories and reputation. Common categories can include malicious sites, phishing, social media, streaming, or other content types. Web filtering can be combined with SSL inspection when deeper visibility into encrypted web traffic is required. Administrators should review category decisions and configure exceptions carefully because some legitimate websites may contain content that falls into broad or changing categories.

Question 87

Which security control can detect malicious files transmitted through supported network traffic?

  1. Antivirus
  2. DNS Filter
  3. SD-WAN
  4. Traffic Shaping

Correct Answer: 1

Explanation

The Antivirus security profile scans supported network traffic and files for malicious content. FortiGate can use malware signatures and other detection techniques to identify known threats and take configured actions. Antivirus protection is an important layer of defense but should not be used alone. Combining antivirus with web filtering, IPS, application control, endpoint protection, and secure configuration provides broader coverage. Administrators should keep antivirus definitions and related FortiGuard services current because new malware variants appear frequently and older signatures alone may not provide adequate protection.

Question 88

Which FortiGate security profile detects attacks by comparing network traffic against intrusion signatures?

  1. Web Filter
  2. IPS
  3. DNS Filter
  4. Antivirus

Correct Answer: 2

Explanation

The Intrusion Prevention System compares inspected traffic against security signatures and other detection mechanisms to identify known attacks, exploits, and suspicious network behavior. FortiGate IPS can take actions such as blocking, monitoring, or logging matching traffic depending on the configured signature and policy. Administrators should keep signatures updated and tune IPS settings to the organization’s environment. IPS can provide protection against exploitation attempts targeting vulnerable services, but it should operate alongside secure system configuration, patch management, endpoint protection, and other defensive controls.

Question 89

What does a FortiGate local-in policy control?

  1. Traffic destined for the FortiGate itself
  2. Traffic between two internal hosts
  3. Only outgoing Internet traffic
  4. DHCP leases

Correct Answer: 1

Explanation

Local-in policies control traffic destined for the FortiGate device itself rather than traffic being forwarded through it. This includes traffic such as administrative access, routing protocols, and other services running on FortiGate interfaces. Local-in policies can provide additional control over which sources are permitted to access specific FortiGate services. They are particularly useful for protecting management and device-level services. Administrators should carefully define local-in policies because overly restrictive rules can interrupt required management, routing, or security functions.

Question 90

Which FortiGate feature can restrict access to administrative services on specific interfaces?

  1. Administrative access settings
  2. Web Filter
  3. Application Control
  4. Traffic shaping

Correct Answer: 1

Explanation

Administrative access settings determine which management protocols and services are available on FortiGate interfaces. Administrators can enable or disable services such as HTTPS, SSH, or other supported management protocols according to operational requirements. Limiting administrative access to dedicated management interfaces or trusted networks reduces exposure to unauthorized access attempts. This control should be combined with trusted hosts, strong authentication, MFA, and appropriate administrator profiles. Management services that are not required should generally remain disabled to reduce the device’s exposed attack surface.

Question 91

Which FortiGate feature allows administrators to create a secure connection between a branch office and headquarters over the Internet?

  1. Site-to-site IPsec VPN
  2. DNS Filter
  3. Web Filter
  4. Application Control

Correct Answer: 1

Explanation

A site-to-site IPsec VPN creates an encrypted connection between two networks over an untrusted network such as the Internet. FortiGate devices at each location can establish a VPN tunnel and securely exchange traffic between protected networks. Administrators must configure compatible IKE parameters, IPsec settings, routing, and firewall policies. Monitoring tunnel status and traffic is also important to ensure reliable connectivity. Site-to-site VPNs can reduce the need for dedicated private circuits while providing cryptographic protection for traffic traveling across public infrastructure.

Question 92

Which IPsec mode is commonly used for site-to-site VPN tunnels between network gateways?

  1. Tunnel mode
  2. Transport mode
  3. Broadcast mode
  4. Bridge mode

Correct Answer: 1

Explanation

IPsec tunnel mode is commonly used for site-to-site VPN connections between security gateways. In tunnel mode, the original IP packet is encapsulated within a new IP packet, allowing the gateways to protect communication between networks across an untrusted infrastructure. This differs from transport mode, which generally protects the payload of an IP packet while preserving the original IP header. FortiGate site-to-site IPsec deployments commonly use tunnel mode because it provides an effective way to securely connect separate networks.

Question 93

Which FortiGate VPN component determines which traffic is protected by an IPsec tunnel?

  1. Traffic selectors
  2. DNS records
  3. Security profiles
  4. Address groups only

Correct Answer: 1

Explanation

Traffic selectors define the source and destination traffic that should be protected by an IPsec Phase 2 security association. They identify the networks or address ranges that participate in the VPN tunnel. If traffic selectors do not match between VPN peers, the tunnel may establish successfully while expected traffic fails to pass. Administrators should verify selectors alongside routing and firewall policies when troubleshooting VPN connectivity. Modern deployments may use more specific selectors to support multiple protected networks or granular VPN requirements.

Question 94

Which FortiGate feature can automatically select the best available WAN path based on performance measurements?

  1. SD-WAN
  2. VDOM
  3. FortiAnalyzer
  4. DHCP

Correct Answer: 1

Explanation

FortiGate SD-WAN can select WAN paths according to configured rules and link-performance measurements. It can evaluate characteristics such as latency, jitter, packet loss, and availability to determine whether a path satisfies application requirements. Administrators can create rules that prioritize particular links for important applications while using other links for less-sensitive traffic. This can improve resilience and application performance when multiple WAN connections are available. Effective SD-WAN operation depends on correctly configured health checks, performance thresholds, and traffic-steering rules.

Question 95

A company has two WAN links. One has lower latency, while the other has higher latency but more available bandwidth. Which FortiGate feature can use application requirements to select between them?

  1. SD-WAN rules
  2. DNS Filter
  3. Antivirus
  4. VIP

Correct Answer: 1

Explanation

SD-WAN rules can use application and link-performance requirements to influence WAN path selection. Administrators can configure rules that prioritize a particular link for latency-sensitive applications while directing other traffic toward a link with greater available bandwidth. Performance measurements such as latency, jitter, packet loss, and link availability can be used to evaluate path quality. This allows organizations to make routing decisions based on application requirements rather than simply using one fixed route. Proper rule ordering and health-check configuration are important for predictable behavior.

Question 96

Which FortiGate feature provides a virtual interface for connecting a VPN tunnel to routing and firewall policies?

  1. IPsec tunnel interface
  2. Physical switch
  3. DHCP interface
  4. Loopback policy

Correct Answer: 1

Explanation

An IPsec tunnel interface provides a logical interface associated with an IPsec VPN connection. Administrators can use the interface in routing and firewall policies, allowing VPN traffic to be handled similarly to other network interfaces. This approach can simplify routing and policy design, particularly in route-based VPN deployments. Administrators can define routes through the tunnel interface and apply security policies between the VPN and internal or external networks. Correct routing, firewall rules, and tunnel configuration are still required for successful communication.

Question 97

Which FortiGate feature allows multiple internal devices to share a public IPv4 address for Internet access?

  1. Source NAT
  2. Destination NAT
  3. IPsec
  4. DNS Filter

Correct Answer: 1

Explanation

Source NAT allows internal devices using private addresses to communicate with external networks through a public address. FortiGate can translate the source address to the outgoing interface address or to an address from a configured IP pool. Multiple internal clients can therefore share public IPv4 addressing for outbound connections. Source NAT helps conserve public IPv4 addresses and hides private internal addressing from external destinations. It should not be confused with destination NAT, which is commonly used to publish internal services through mechanisms such as VIPs.

Question 98

Which FortiGate object is commonly used to publish an internal server to an external network?

  1. VIP
  2. Service group
  3. Address group
  4. Schedule

Correct Answer: 1

Explanation

A Virtual IP, or VIP, is commonly used to map an external address or port to an internal server. This allows services hosted on private addresses to be accessed from an external network when permitted by an appropriate firewall policy. Administrators can use VIPs for services such as web servers, mail systems, or other applications. Only required services should be exposed, and firewall policies should restrict source addresses and ports whenever practical. Publicly accessible services should also receive appropriate security monitoring and vulnerability protection.

Question 99

Which FortiGate feature can prevent unauthorized devices from accessing a protected network based on device or user identity?

  1. Network Access Control
  2. NAT
  3. IPsec
  4. Traffic shaping

Correct Answer: 1

Explanation

Network Access Control helps determine whether a device or user should receive network access based on identity, authentication, device characteristics, or security posture. Fortinet solutions can integrate with FortiGate to provide visibility and enforcement for endpoints across network segments. NAC can place unknown or noncompliant devices into restricted areas while allowing trusted devices appropriate access. Effective NAC requires accurate endpoint identification and well-designed policies. It should be combined with segmentation, authentication, endpoint security, and monitoring to provide stronger control over network access.

Question 100

Which FortiGate feature can isolate a compromised endpoint from the rest of the network?

  1. Network segmentation or quarantine
  2. DNS caching
  3. NAT
  4. Traffic shaping

Correct Answer: 1

Explanation

Network segmentation or quarantine can isolate a compromised endpoint from sensitive network resources while allowing security teams to investigate and remediate the device. Fortinet environments can use access-control and endpoint integrations to place suspicious systems into restricted network segments. Isolation reduces the opportunity for lateral movement and limits the impact of a compromised device. Administrators should define quarantine policies before incidents occur and ensure that security teams can still reach the necessary management or remediation services without unnecessarily exposing the isolated endpoint.