{"id":14171,"date":"2026-09-16T13:02:19","date_gmt":"2026-09-16T13:02:19","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14171"},"modified":"2026-09-16T13:02:19","modified_gmt":"2026-09-16T13:02:19","slug":"fortinet-fcp_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Fortinet FCP_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fgt-ad-7-6-exam-dumps\"><b>Fortinet FCP_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 181. Which FortiGate feature can apply different NAT behavior by using a pool of public IP addresses?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP pool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. IP pool<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IP pool allows FortiGate to use a defined range of public or translated IP addresses for source NAT. Instead of translating all sessions to the outgoing interface address, the firewall can select addresses from the configured pool. This is useful when an organization owns multiple public addresses and wants outbound connections to use those addresses. Depending on the configuration, IP pools can provide one-to-one, overload, or other translation behaviors. The pool is referenced by firewall policies that permit the relevant traffic. Proper sizing and address assignment are important because insufficient available addresses can affect how new sessions are translated.<\/span><\/p>\n<h3><b>Question 182. What is the primary purpose of a PAC file when using an explicit web proxy?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt firewall configuration backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Define which proxy server a client should use<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Configure IPsec encryption parameters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Create antivirus signatures<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Define which proxy server a client should use<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Proxy Auto-Configuration (PAC. file provides browser or client-side instructions for selecting a proxy server. It can specify conditions that determine whether traffic should go through a particular proxy or connect directly. In environments using FortiGate explicit proxy services, a PAC file can simplify client configuration by distributing proxy settings without manually configuring every workstation. PAC files can also support different proxy choices based on destination or network conditions. They do not perform encryption or antivirus inspection themselves. The actual traffic inspection and policy enforcement are performed by the configured proxy and security controls on FortiGate.<\/span><\/p>\n<h3><b>Question 183. Which FortiGate capability allows administrators to authenticate users against a certificate-based identity?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Certificate-based authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Certificate-based authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate-based authentication uses digital certificates to verify an identity instead of relying only on a username and password. FortiGate can use certificates as part of authentication mechanisms when a suitable PKI infrastructure is available. The client presents a certificate, and FortiGate validates the certificate according to the configured trust relationship and authentication requirements. This approach can provide strong identity verification and is particularly useful for controlled enterprise environments. Administrators must ensure that trusted certificate authorities, certificate validity, revocation considerations, and appropriate identity mappings are correctly configured. Certificate-based authentication is different from ordinary password authentication and requires suitable certificate infrastructure.<\/span><\/p>\n<h3><b>Question 184. What should FortiGate verify when validating a client certificate chain?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The certificate is issued by a trusted CA<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The client has the correct DHCP lease<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The firewall has an active SD-WAN rule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The destination uses a VIP<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. The certificate is issued by a trusted CA<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate chain validation confirms that a presented certificate can be traced to a trusted certificate authority. FortiGate checks the certificate relationship and relevant validity information before accepting the certificate for authentication or another certificate-based function. A trusted CA certificate must therefore be available in the appropriate trust store. Other checks can include expiration, subject information, and certificate usage depending on the authentication scenario. DHCP leases, SD-WAN rules, and VIP configurations are unrelated to certificate-chain trust. Proper certificate management helps prevent unauthorized certificates from being accepted and supports a stronger authentication framework.<\/span><\/p>\n<h3><b>Question 185. Which IPsec VPN type is commonly used when remote clients have dynamic or unknown public IP addresses?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Site-to-site static VPN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> GRE tunnel<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Dial-up VPN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Dedicated VLAN<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Dial-up VPN<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dial-up IPsec VPN is designed for peers whose public IP addresses are not known in advance or may change over time. This makes it suitable for remote users, branch devices, or other clients connecting from dynamic Internet addresses. Instead of requiring a predefined static peer address, FortiGate can authenticate the connecting peer using configured identification and authentication methods. Once the tunnel is established, appropriate policies and routing determine what resources the remote client can access. Dial-up VPNs are especially useful for remote-access scenarios where maintaining static public addressing for every endpoint would be impractical.<\/span><\/p>\n<h3><b>Question 186. What is the purpose of a peer ID in an IPsec VPN configuration?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign a DHCP address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To select an antivirus profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To define a traffic-shaping queue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To identify or distinguish the VPN peer<\/span><\/li>\n<\/ol>\n<p><b>Answer: 4. To identify or distinguish the VPN peer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPsec peer ID provides an identity value that can help FortiGate identify a connecting VPN peer. This is especially useful when multiple peers connect to the same VPN gateway but have different identities or authentication requirements. Depending on the configuration, the identity can be associated with authentication and phase 1 settings. Peer identification is separate from the peer&#8217;s IP address, which is important when remote endpoints use dynamic addressing. Correct peer-ID configuration helps FortiGate select the appropriate authentication and VPN parameters and can prevent an otherwise valid connection from matching the wrong phase 1 configuration.<\/span><\/p>\n<h3><b>Question 187. Which IPv6 mechanism helps hosts discover neighboring devices and routers on the local network?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Neighbor Discovery Protocol<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> OSPFv2<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Neighbor Discovery Protocol<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPv6 Neighbor Discovery Protocol (NDP. is used for several important local-network functions, including discovering neighboring devices and routers. It operates through ICMPv6 messages and supports functions such as neighbor discovery, router discovery, address resolution, and reachability detection. Unlike IPv4 ARP, IPv6 does not use ARP for resolving neighboring addresses. NDP therefore plays an important role in normal IPv6 communication. Security policies and network controls should account for required ICMPv6 traffic because blocking essential messages can interfere with IPv6 connectivity. NDP is distinct from DHCP and traditional IPv4 routing protocols.<\/span><\/p>\n<h3><b>Question 188. Which feature can provide IPv6 address configuration through a DHCPv6 service?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPv6<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> NAT64 only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> VLAN trunking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> IP pool<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. DHCPv6<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCPv6 provides dynamic IPv6 configuration services to clients. Depending on the deployment, it can provide IPv6 addressing and additional network configuration information. It is different from traditional IPv4 DHCP because IPv6 hosts can also use mechanisms such as Router Advertisements and Stateless Address Autoconfiguration. FortiGate can participate in IPv6 network configurations involving DHCPv6 where appropriate. Administrators should determine whether the environment requires stateful DHCPv6, stateless configuration assistance, or another IPv6 addressing approach. Correctly configuring IPv6 services ensures clients receive the information necessary to communicate on the network.<\/span><\/p>\n<h3><b>Question 189. What can a DNS Filter policy use to enforce safer web-search behavior?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec peer IDs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP reservations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Safe Search enforcement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static routes<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Safe Search enforcement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS filtering can include controls that help enforce safer search behavior for supported search engines. Safe Search enforcement reduces exposure to certain categories of search results by directing supported queries through safer search configurations. This can be useful in environments such as schools, businesses, and managed networks where administrators want additional control over web content. The feature works alongside DNS-based filtering rather than replacing full web-content inspection. Administrators should understand the limitations of DNS filtering because it primarily controls name resolution and category-based access rather than inspecting every aspect of encrypted web traffic.<\/span><\/p>\n<h3><b>Question 190. Which IPS capability can temporarily isolate a source that repeatedly triggers configured security signatures?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS forwarding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Route redistribution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Quarantine<\/span><\/li>\n<\/ol>\n<p><b>Answer: 4. Quarantine<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPS quarantine action can help isolate a source that repeatedly generates suspicious or malicious traffic according to configured security rules. When a quarantine mechanism is triggered, FortiGate can restrict communication from the identified source for a configured period or according to the relevant policy behavior. This can reduce the risk of continued malicious activity while administrators investigate the endpoint. Quarantine should be configured carefully because legitimate systems can sometimes trigger security controls due to unusual traffic patterns. Appropriate thresholds, exception handling, and monitoring help ensure that automated isolation supports security without unnecessarily disrupting valid users or devices.<\/span><\/p>\n<h3><b>Question 191. Which DLP capability can identify sensitive information based on configured data patterns?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec DPD<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DLP data patterns<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> OSPF adjacency<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. DLP data patterns<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DLP data patterns allow security policies to identify information that matches defined characteristics of sensitive data. Patterns can be designed around specific formats or recognizable content, depending on the organization&#8217;s requirements. FortiGate DLP controls can then use these detections to apply configured actions to matching traffic or files. This can help organizations reduce accidental or unauthorized transmission of sensitive information. Administrators should design patterns carefully to balance detection accuracy and performance. A well-configured DLP policy typically combines appropriate patterns, traffic scope, logging, and actions so that sensitive information can be monitored and controlled consistently.<\/span><\/p>\n<h3><b>Question 192. Which traffic-shaping configuration can provide a bandwidth limit specifically for each source IP?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Per-IP shaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Security Fabric connector<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Address group<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Per-IP shaper<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A per-IP traffic shaper applies bandwidth control separately to individual source IP addresses. This is useful when an administrator wants each user or endpoint to receive its own configured bandwidth allowance rather than having all users share one common limit. For example, a network can restrict excessive consumption by individual clients while allowing multiple clients to operate independently within their assigned limits. This differs from a shared traffic shaper, where multiple sessions or users may compete for the same bandwidth allocation. Proper shaping configuration can improve fairness and help prevent one endpoint from consuming disproportionate network capacity.<\/span><\/p>\n<h3><b>Question 193. Which DoS policy setting is specifically relevant to detecting excessive TCP SYN requests?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web category rating<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Certificate authority<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> SYN flood threshold<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP lease duration<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. SYN flood threshold<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A SYN flood threshold is used to identify unusually high rates of TCP connection initiation attempts. During a normal TCP connection, a client begins the handshake by sending a SYN packet. A large volume of SYN requests can consume server resources and may indicate a denial-of-service attempt. FortiGate DoS policies can use configured thresholds to detect abnormal traffic rates and apply protective actions. Threshold values should be selected based on normal traffic patterns because overly aggressive settings may identify legitimate bursts as attacks. Monitoring and tuning are important to maintain effective protection without unnecessarily affecting valid connections.<\/span><\/p>\n<h3><b>Question 194. In an automation stitch, what determines when the configured actions should execute?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The firewall hostname<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The trigger condition<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The administrator password<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The DNS cache<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. The trigger condition<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An automation stitch uses a trigger to determine when one or more configured actions should execute. The trigger can be associated with an event or condition recognized by FortiGate. When that condition occurs, FortiGate performs the actions linked to the automation stitch. This allows administrators to automate responses to selected operational or security events instead of handling every event manually. For example, an automation workflow may respond to a detected condition by sending a notification or taking another predefined action. Careful trigger selection is important because an overly broad condition can cause unnecessary automated responses.<\/span><\/p>\n<h3><b>Question 195. Which FortiView capability is most useful for investigating why a particular application is consuming bandwidth?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing the administrator password<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Drilling down into application traffic details<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Creating a new VDOM<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Replacing a certificate<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Drilling down into application traffic details<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides graphical and interactive visibility into network activity. When investigating application bandwidth usage, administrators can drill down into application-related traffic information to identify which applications, users, destinations, or sessions are contributing to consumption. This makes it easier to move from a high-level overview to more specific traffic details. The resulting information can help administrators determine whether traffic is expected, excessive, or potentially unwanted. FortiView is primarily a monitoring and analysis capability; it does not itself replace firewall policies or security profiles. Administrators can use the findings to guide subsequent policy or traffic-management changes.<\/span><\/p>\n<h3><b>Question 196. Which administrator setting can require stronger password complexity for local FortiGate accounts?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Route monitor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNS database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Interface alias<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Password policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An administrator password policy establishes requirements for passwords used by local administrative accounts. Depending on the configured options, the policy can enforce characteristics such as minimum length and complexity requirements. Strong password rules reduce the likelihood that easily guessed passwords will be accepted for privileged accounts. Administrators should also combine password controls with other protections such as multi-factor authentication, trusted management sources, appropriate administrative profiles, and secure management protocols. Password policy is specifically concerned with credential requirements, while unrelated features such as routing and DNS configuration do not determine whether an administrator&#8217;s password satisfies security requirements.<\/span><\/p>\n<h3><b>Question 197. Which virtual server load-balancing method distributes connections sequentially among available real servers?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source IP persistence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Least sessions only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Round robin<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Round robin<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Round-robin load balancing distributes incoming connections sequentially across the available real servers. For example, requests can be directed to server A, then server B, then server C, before returning to server A. This method is straightforward and can work well when backend servers have similar capabilities and workloads. It does not necessarily account for the current number of active sessions or differences in server capacity. Other load-balancing methods can use different criteria. The selected method should therefore match the application&#8217;s traffic pattern and the characteristics of the backend servers.<\/span><\/p>\n<h3><b>Question 198. Why is administrator login timeout useful on FortiGate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It increases VPN encryption strength<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It changes routing metrics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It creates additional firewall policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It automatically ends inactive administrative sessions<\/span><\/li>\n<\/ol>\n<p><b>Answer: 4. It automatically ends inactive administrative sessions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An administrator login timeout automatically terminates an administrative session after the configured period of inactivity. This reduces the risk associated with an unattended management session remaining open on a workstation. A shorter timeout can provide stronger protection in environments where administrative consoles may be exposed to unauthorized physical or local access. The setting does not modify VPN encryption, routing metrics, or firewall policy behavior. Administrators should select a practical timeout that balances security with operational convenience. Combined with strong authentication and restricted management access, session timeout controls provide an additional layer of protection for privileged administration.<\/span><\/p>\n<h3><b>Question 199. What is the main purpose of static one-to-one NAT for an internal server?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign multiple DHCP leases<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To map a public address consistently to an internal address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To create an OSPF neighbor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To filter DNS categories<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To map a public address consistently to an internal address<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static one-to-one NAT provides a consistent translation between a public IP address and a private internal address. This is commonly useful when an internal server needs to be reachable through a predictable public address. The translation itself does not automatically determine which services are allowed; appropriate firewall policies and service restrictions are still required. One-to-one NAT differs from overload NAT, where many internal hosts can share one public address using different source ports. Administrators should also consider exposure carefully and permit only the services that are actually required for the published server.<\/span><\/p>\n<h3><b>Question 200. Which FortiGate behavior occurs when traffic does not match any explicit firewall policy?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The traffic is denied by the implicit policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The traffic is automatically forwarded<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The traffic is converted to IPv6<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The traffic is sent to the DNS server<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. The traffic is denied by the implicit policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate uses an implicit deny behavior when traffic does not match an applicable explicit firewall policy. This provides a default security boundary by preventing unmatched traffic from being automatically permitted. Administrators can create explicit policies for legitimate traffic and place the appropriate security profiles and logging settings on those policies. When unexpected traffic is denied, policy configuration, source and destination interfaces, addresses, services, schedules, and routing should be reviewed to determine why no intended policy matched. Understanding implicit deny behavior is fundamental to troubleshooting connectivity while maintaining a controlled firewall security posture.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps &nbsp; Question 181. Which FortiGate feature can apply different NAT behavior by using a pool of public IP addresses? Static routing 2. DHCP relay 3. IP pool 4. DNS forwarding Answer: 3. IP pool Explanation: An IP pool allows FortiGate to use a defined range [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14171"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14171"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14171\/revisions"}],"predecessor-version":[{"id":14193,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14171\/revisions\/14193"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}