{"id":14176,"date":"2026-09-16T13:01:15","date_gmt":"2026-09-16T13:01:15","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14176"},"modified":"2026-09-16T13:01:15","modified_gmt":"2026-09-16T13:01:15","slug":"fortinet-fcp_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part-15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part-15-q281-300\/","title":{"rendered":"Fortinet FCP_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part 15 Q281-300"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fgt-ad-7-6-exam-dumps\"><b>Fortinet FCP_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 281. Which FortiGate feature can identify the type of endpoint connected to the network?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Device identification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> IPsec selector<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Device identification<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device identification helps FortiGate determine information about endpoints connected to the network. The firewall can use available network characteristics and observed traffic to identify devices or device categories. This information can improve visibility and can also be used in supported security policies and monitoring functions. Device identification is particularly useful in environments where administrators need to understand what types of systems are accessing network resources. It should not be confused with user authentication, because identifying a device does not necessarily identify the person using it. Combining device information with authentication and policy controls can provide more precise access management.<\/span><\/p>\n<h3><b>Question 282. What is the purpose of a FortiGate security policy using a device group?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define routing protocol neighbors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To configure DNS forwarding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To apply policy controls based on identified endpoint devices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To create an HA heartbeat<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. To apply policy controls based on identified endpoint devices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A device-based firewall policy can use identified endpoint information to apply specific security controls to particular device types or groups. This can help administrators distinguish between different classes of endpoints when designing access policies. For example, an organization may want different controls for managed workstations, printers, or other network devices. Device-based matching should be combined with appropriate source, destination, service, and security-profile requirements. Device identification is not the same as user authentication, so administrators should select the appropriate matching method for the security requirement. Proper policy ordering remains important when multiple policies could match the same traffic.<\/span><\/p>\n<h3><b>Question 283. Which FortiGate feature allows a firewall policy to authenticate users through an external identity source?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identity-based policy with an authentication server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> IP pool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Interface zone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Traffic shaper<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Identity-based policy with an authentication server<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An identity-based firewall policy can associate network access decisions with authenticated users or groups. FortiGate can integrate with supported external identity services so that users can be authenticated and matched against appropriate groups. This allows policies to distinguish access based on user identity instead of relying only on source IP addresses. Identity-based controls are useful in environments where multiple users share network segments or where access requirements differ by organizational role. Administrators should ensure that authentication, group membership, and policy matching are correctly configured so that users receive the intended access.<\/span><\/p>\n<h3><b>Question 284. What is the main purpose of a firewall address group?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To combine multiple address objects for easier policy management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To create an IPsec tunnel<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To monitor CPU usage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To assign DHCP reservations<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To combine multiple address objects for easier policy management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall address group allows multiple address objects to be referenced as a logical collection. This simplifies policy configuration when the same group of networks or hosts needs to appear in multiple policies. Instead of adding every individual address object repeatedly, administrators can reference the group as a single policy object. Address groups can make configurations easier to read and maintain, especially in environments with many internal networks or application servers. The group does not itself perform routing or NAT. It is primarily an object-management feature used to simplify the definition of policy sources and destinations.<\/span><\/p>\n<h3><b>Question 285. Which FortiGate feature can restrict access to management services based on the interface through which the connection arrives?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Local-in policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IP pool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> SD-WAN rule<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Local-in policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local-in policies control traffic destined for services running directly on the FortiGate itself. This can include administrative access and other local services depending on the configuration. Administrators can use local-in policies to restrict which sources, interfaces, services, or other supported criteria may reach the device. This is different from normal firewall policies, which primarily control traffic passing through the FortiGate between networks. Proper local-in policy design can reduce the exposure of management services and other device-local functions. Administrators should carefully review the policies to avoid unintentionally blocking required administrative or network services.<\/span><\/p>\n<h3><b>Question 286. What is the purpose of a firewall policy schedule?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine when a policy is active<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To configure BGP neighbors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To monitor certificate expiration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To create VLAN tags<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To determine when a policy is active<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy schedule defines the time period during which a policy can be used to process matching traffic. This allows administrators to create time-based access controls instead of keeping a policy active continuously. For example, an organization can permit certain traffic only during business hours or restrict access outside approved periods. Schedules can improve policy precision and reduce unnecessary exposure. Administrators should ensure that the schedule uses the correct time settings and that overlapping policies are considered. A schedule controls policy availability; it does not replace the source, destination, service, or security conditions defined in the policy.<\/span><\/p>\n<h3><b>Question 287. What is the primary purpose of a firewall policy comment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To change packet forwarding behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To provide administrative documentation about the policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To create an IPsec tunnel<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To enable DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To provide administrative documentation about the policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy comment provides descriptive information for administrators about why a policy exists or what it is intended to control. Comments can document business purposes, application dependencies, change references, or other useful operational details. Clear documentation becomes increasingly valuable as firewall configurations grow and are managed by multiple administrators. A comment does not affect packet forwarding, authentication, or security inspection. Instead, it improves maintainability and helps administrators understand configuration intent during troubleshooting or review. Good policy documentation can also make future audits and configuration changes more efficient.<\/span><\/p>\n<h3><b>Question 288. Which FortiGate feature can limit bandwidth consumed by an individual source IP address?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Per-IP traffic shaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Certificate inspection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNS Filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> OSPF<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Per-IP traffic shaper<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A per-IP traffic shaper controls bandwidth usage based on individual source IP addresses. This can prevent one host from consuming a disproportionate amount of available network capacity. It is useful in environments where administrators need to distribute bandwidth more fairly among users or devices. Traffic shaping is different from security inspection because its primary purpose is controlling traffic rates rather than detecting malicious content. Administrators should select appropriate limits based on available bandwidth and application requirements. Proper monitoring is useful after deployment because overly restrictive shaping can negatively affect legitimate applications that require higher throughput.<\/span><\/p>\n<h3><b>Question 289. What is the purpose of an application control sensor on FortiGate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define IPsec Phase 1 authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To identify and control applications in network traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To assign DNS addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To create HA heartbeat interfaces<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To identify and control applications in network traffic<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications within network traffic and allows administrators to apply actions based on the detected applications or application categories. This provides more granular control than relying solely on IP addresses and ports. Administrators can use application control to monitor, allow, or restrict applications according to the organization&#8217;s security requirements. Detection depends on the traffic characteristics and available FortiGuard application signatures or related mechanisms. Application Control is commonly applied through firewall policies using a security profile. It should be configured carefully so that legitimate applications are not unintentionally blocked.<\/span><\/p>\n<h3><b>Question 290. Which FortiGate feature helps prevent sensitive information from leaving the organization through inspected traffic?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DLP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Link aggregation<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. DLP<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention, or DLP, is designed to identify and control sensitive information as it moves through monitored traffic. Administrators can define data patterns or rules that help detect information requiring special handling. Depending on the configured policy and supported inspection methods, FortiGate can log, block, or otherwise respond when matching content is identified. DLP is useful for protecting information such as confidential business data or regulated records. Effective DLP configuration requires carefully designed patterns and actions because overly broad rules can generate unnecessary alerts, while overly narrow rules may fail to detect relevant information.<\/span><\/p>\n<h3><b>Question 291. What is the purpose of a FortiGate IPS sensor?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To configure DNS records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To define intrusion prevention signatures and actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To create SD-WAN zones<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. To define intrusion prevention signatures and actions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPS sensor defines how FortiGate handles intrusion prevention signatures detected in inspected traffic. Administrators can select relevant signatures or signature categories and configure actions according to the security requirements. Depending on the configuration, detected traffic may be logged, blocked, or handled through another supported action. IPS helps identify attempts to exploit vulnerabilities or perform other malicious activities. Administrators should keep signatures updated and review IPS events to identify false positives or emerging threats. Carefully tuning the sensor helps maintain security while reducing unnecessary disruption to legitimate traffic.<\/span><\/p>\n<h3><b>Question 292. What is the main purpose of an antivirus profile on FortiGate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To inspect traffic for malware and unwanted files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To establish BGP sessions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To create VLAN interfaces<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To assign administrator privileges<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To inspect traffic for malware and unwanted files<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A FortiGate antivirus profile defines how the firewall handles supported traffic when scanning for malicious files or malware. The profile can be applied through a firewall policy so that matching traffic receives antivirus inspection according to the configured settings. Depending on the traffic type and inspection method, FortiGate can identify suspicious or malicious content and take an appropriate action. Antivirus protection relies on current detection information and correct policy placement. Administrators should also consider performance and inspection requirements when enabling antivirus scanning because deeper inspection can require additional system resources.<\/span><\/p>\n<h3><b>Question 293. What is the purpose of a Web Filter static URL filter?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To configure OSPF areas<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To define specific URLs or domains that should receive a configured filtering action<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To assign DHCP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To synchronize HA sessions<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To define specific URLs or domains that should receive a configured filtering action<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A static URL filter allows administrators to define specific web addresses or domains and assign an appropriate filtering action. This can provide more direct control than relying solely on category-based web filtering. For example, an organization may need to explicitly block or allow a particular website regardless of its broader category classification. Static URL filters are useful for implementing organization-specific web access requirements. Administrators should review these entries periodically because websites can change domains, URLs, or content. The configured action should also be tested to ensure that it produces the intended behavior.<\/span><\/p>\n<h3><b>Question 294. What is the purpose of a DNS Filter on FortiGate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To control DNS requests based on configured security and filtering criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To increase physical interface speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To configure HA priorities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To create firewall address groups<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To control DNS requests based on configured security and filtering criteria<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS filtering allows FortiGate to evaluate DNS requests and apply security or access-control decisions based on configured filtering mechanisms. It can help prevent users from resolving domains associated with unwanted or potentially harmful content. DNS filtering can work with category information and other supported controls to improve visibility and policy enforcement at the domain-resolution level. Administrators should ensure that client DNS traffic is actually passing through the intended FortiGate service; otherwise, filtering may not be applied. DNS filtering complements, rather than replaces, other controls such as Web Filter, Application Control, and IPS.<\/span><\/p>\n<h3><b>Question 295. What is the primary purpose of FortiGate IP reputation information?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine administrator password length<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To identify IP addresses associated with known malicious or suspicious activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To configure DHCP reservations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To calculate interface bandwidth<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To identify IP addresses associated with known malicious or suspicious activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP reputation information provides threat intelligence about IP addresses that may be associated with malicious, suspicious, or otherwise undesirable activity. FortiGate can use reputation information as part of supported security controls to help identify potentially risky communication. Reputation data is generally based on threat intelligence sources and may change as new information becomes available. Administrators should understand that reputation is one security signal rather than proof that every connection from an address is malicious. Combining reputation-based controls with IPS, antivirus, web filtering, and appropriate firewall policies provides broader protection.<\/span><\/p>\n<h3><b>Question 296. Which FortiGate feature can provide a centralized view of security and network activity over time?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiView<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP reservation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Interface zone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Loopback interface<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. FortiView<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides graphical and analytical views of network and security information collected by FortiGate. It can help administrators examine traffic sources, destinations, applications, services, security events, and other operational information depending on the available data and configuration. FortiView can be useful for quickly identifying trends and investigating unusual activity without manually reviewing every individual log entry. Administrators can often drill down into information to obtain greater detail. FortiView is primarily a visibility and analysis capability; it does not replace firewall policies or security profiles that actually enforce traffic controls.<\/span><\/p>\n<h3><b>Question 297. What is the purpose of FortiGate replacement messages?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To modify routing tables<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To customize messages presented when certain firewall or security actions affect a user request<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To create VPN peers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To assign VLAN IDs<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To customize messages presented when certain firewall or security actions affect a user request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Replacement messages allow administrators to customize the content displayed to users when certain FortiGate functions take an action on their traffic. Depending on the feature involved, a user may receive a message indicating that a website was blocked, authentication is required, or another security action occurred. Customized messages can provide clearer guidance and organizational information while maintaining the intended security control. Administrators should ensure that customized content does not expose unnecessary security details. Replacement messages affect user-facing communication; they do not change the fundamental routing or security decision that caused the message to be displayed.<\/span><\/p>\n<h3><b>Question 298. What is the primary purpose of a FortiGate virtual server?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide a front-end address that distributes or forwards traffic to backend servers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To configure administrator passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To create DNS categories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To monitor CPU usage<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To provide a front-end address that distributes or forwards traffic to backend servers<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A FortiGate virtual server can provide a front-end virtual IP and service that receives incoming connections and handles them according to the configured load-balancing or forwarding behavior. Backend real servers can then receive traffic based on the selected configuration and health status. This can provide application availability and distribute client connections across multiple servers. Virtual server functionality should be configured with appropriate listener settings, real-server definitions, health checks, and firewall policies. It is different from a simple static NAT rule because it can provide additional server-selection and availability functionality.<\/span><\/p>\n<h3><b>Question 299. Which feature determines whether a real server behind a FortiGate virtual server is available to receive traffic?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Security profile group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Real-server health check<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Traffic log<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Real-server health check<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A real-server health check determines whether a backend server is responding appropriately before the FortiGate sends traffic to it through a virtual server configuration. Health checks can help prevent client requests from being forwarded to a server that is unavailable or not responding as expected. The exact check method depends on the configuration and supported protocols. Reliable health checks improve application availability because the virtual server can make forwarding decisions based on backend status. Administrators should choose a check that accurately represents application availability rather than simply confirming that the server responds at a basic network level.<\/span><\/p>\n<h3><b>Question 300. Which FortiGate feature provides logical separation of multiple independent firewall environments on one physical appliance?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> VDOM<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IPS sensor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Address group<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. VDOM<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virtual Domains, or VDOMs, allow a FortiGate to operate multiple logically separated firewall environments on the same physical appliance. Each VDOM can have its own interfaces, routing configuration, firewall policies, administrators, and security settings according to the deployment design. This capability is useful when different departments, customers, or network environments require separation while sharing the same hardware. VDOMs provide administrative and configuration isolation, although shared physical resources still exist at the appliance level. Resource controls and appropriate inter-VDOM connections can be used when controlled communication or resource management is required between virtual domains.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps &nbsp; Question 281. Which FortiGate feature can identify the type of endpoint connected to the network? Traffic shaping 2. Device identification 3. Static routing 4. IPsec selector Answer: 2. Device identification Explanation: Device identification helps FortiGate determine information about endpoints connected to the network. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14176"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14176"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14176\/revisions"}],"predecessor-version":[{"id":14188,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14176\/revisions\/14188"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}