{"id":14182,"date":"2026-09-16T13:00:24","date_gmt":"2026-09-16T13:00:24","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14182"},"modified":"2026-09-16T13:00:24","modified_gmt":"2026-09-16T13:00:24","slug":"fortinet-fcp_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fgt_ad-7-6-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Fortinet FCP_FGT_AD-7.6 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fgt-ad-7-6-exam-dumps\"><b>Fortinet FCP_FGT_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 361. What is the primary purpose of the FortiManager Install Preview feature?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To restart all managed FortiGate devices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To replace the FortiManager database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To generate antivirus signatures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To review proposed configuration changes before installation<\/span><\/li>\n<\/ol>\n<p><b>Answer: 4. To review proposed configuration changes before installation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiManager Install Preview allows administrators to review the configuration changes that will be sent to a managed FortiGate before the installation operation is performed. This is useful for identifying unexpected policy, object, routing, or other configuration differences before they reach the production device. The preview helps administrators validate the intended changes and reduce configuration mistakes. It does not restart devices, generate security signatures, or replace the FortiManager database. In controlled environments, reviewing the installation preview is an important step when managing multiple FortiGate devices through centralized configuration management.<\/span><\/p>\n<h3><b>Question 362. Which FortiGate HA setting determines whether a higher-priority device can automatically regain the primary role after recovering?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Override<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Session pickup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Gratuitous ARP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Heartbeat interval<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Override<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HA override setting controls whether device priority is used to determine which cluster member should become the primary unit after a device rejoins the cluster. When override is enabled, a device with a higher configured priority can regain the primary role after recovery, depending on the HA configuration. This behavior is different from heartbeat communication, which is used to monitor cluster members, and from session pickup, which concerns maintaining sessions during failover. Administrators should consider the effect of override when designing HA behavior because repeated role changes can affect traffic handling and operational stability.<\/span><\/p>\n<h3><b>Question 363. In a FortiGate HA cluster, what is the purpose of session pickup?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign IP addresses to cluster members<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To help preserve active sessions during failover<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To synchronize firmware images<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To select the default route<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To help preserve active sessions during failover<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session pickup is an HA capability designed to reduce disruption when the primary FortiGate fails and another cluster member takes over. It allows relevant session information to be synchronized so that established traffic flows can continue with less interruption. Without appropriate session synchronization and pickup behavior, existing sessions may need to be re-established after failover. Session pickup is therefore related to traffic continuity rather than IP address assignment, firmware synchronization, or route selection. Its usefulness depends on the session types and HA configuration being used in the FortiGate environment.<\/span><\/p>\n<h3><b>Question 364. Which setting can help protect an IPsec VPN from replayed packets?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT traversal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Dead Peer Detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replay detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Peer ID<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Replay detection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec replay detection helps protect VPN traffic against attackers attempting to capture valid packets and transmit them again later. The mechanism uses sequence information associated with IPsec packets to identify packets that have already been processed or fall outside the acceptable sequence window. This provides an additional security control for encrypted VPN communications. NAT traversal addresses VPN connectivity through NAT devices, Dead Peer Detection checks peer availability, and Peer ID helps identify the remote VPN peer. Replay detection is specifically associated with preventing repeated use of previously observed IPsec packets.<\/span><\/p>\n<h3><b>Question 365. Which condition commonly causes an IPsec tunnel to fail during Phase 2 negotiation?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mismatched Phase 2 selectors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Incorrect NTP timezone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Missing DHCP reservation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Incorrect SNMP community<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Mismatched Phase 2 selectors<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phase 2 negotiation establishes the IPsec security associations and defines which traffic should be protected. If the local and remote Phase 2 selectors do not match appropriately, the peers may be unable to establish the required security association. Administrators troubleshooting this problem should compare the local and remote source and destination networks, protocol settings, and related Phase 2 parameters. NTP, DHCP reservations, and SNMP settings generally do not determine whether Phase 2 selectors match. Reviewing VPN event logs and comparing both peers&#8217; configurations can help identify the exact mismatch.<\/span><\/p>\n<h3><b>Question 366. What is the purpose of NAT Traversal (NAT-T. in an IPsec VPN?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign VPN user groups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To convert IPv4 addresses into IPv6<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To improve DNS filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To allow IPsec traffic to traverse NAT devices<\/span><\/li>\n<\/ol>\n<p><b>Answer: 4. To allow IPsec traffic to traverse NAT devices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NAT Traversal, commonly called NAT-T, allows IPsec VPN traffic to pass through devices performing Network Address Translation. Certain IPsec protocols can have difficulty traversing NAT because address and port information may be modified by the intermediary device. NAT-T encapsulates the relevant IPsec traffic in UDP so that it can pass through the NAT environment more reliably. This feature is particularly useful when one or both VPN peers are behind a NAT device. NAT-T is unrelated to DNS filtering, user-group assignment, or IPv4-to-IPv6 address conversion.<\/span><\/p>\n<h3><b>Question 367. In FortiGate ZTNA, what can a ZTNA tag be used for?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identifying endpoint attributes for policy decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Creating a physical switch connection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replacing the FortiGate routing table<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Configuring an NTP server<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. Identifying endpoint attributes for policy decisions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ZTNA tags can provide information about endpoint characteristics that can be used when applying access policies. Depending on the integration and configuration, tags can represent endpoint-related conditions or classifications and help FortiGate make more contextual access decisions. This supports a zero-trust approach in which access is evaluated using more than simply a source IP address. ZTNA tags do not replace routing functions, create physical switch connections, or configure time synchronization. Administrators can use endpoint information together with authentication and policy controls to apply more specific access requirements.<\/span><\/p>\n<h3><b>Question 368. What is the primary role of the FortiGate Security Fabric root device?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Provide DHCP to every endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Act as the central coordinating device for the Security Fabric<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Replace all FortiSwitch devices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store every endpoint&#8217;s local files<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Act as the central coordinating device for the Security Fabric<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Security Fabric root device serves as the central coordinating point for a Fortinet Security Fabric deployment. It provides visibility into connected Fabric devices and supports centralized monitoring and coordination of security information across the environment. The root device does not replace FortiSwitch hardware or function as a general file repository for endpoints. Although a FortiGate may provide DHCP services, that is not the defining purpose of the Security Fabric root role. Proper root-device configuration helps administrators maintain a consolidated view of the interconnected security infrastructure.<\/span><\/p>\n<h3><b>Question 369. Which FortiManager operation lets an administrator compare configuration differences before committing changes to a managed device?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device reboot<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Log forwarding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Configuration revision or diff review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Antivirus quarantine<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Configuration revision or diff review<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration comparison allows administrators to identify differences between configuration states before changes are committed or installed. In centralized management environments, reviewing configuration differences helps confirm that only intended modifications will be applied to a managed FortiGate. This is especially useful when multiple administrators are working with policy packages, device settings, or revisions. Device rebooting, log forwarding, and antivirus quarantine perform different functions and do not provide configuration comparison. Reviewing revisions and differences can therefore improve change control and help identify accidental modifications before deployment.<\/span><\/p>\n<h3><b>Question 370. Which FortiGate routing attribute can influence which route is preferred when multiple routes exist for the same destination?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter category<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Administrative distance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Antivirus signature<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DHCP lease duration<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Administrative distance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative distance is used to evaluate the preference of routes learned from different routing sources. When multiple routes can reach the same destination, the route with the lower administrative distance is generally preferred over a route with a higher administrative distance, assuming other relevant routing conditions are satisfied. This helps FortiGate select between routing sources such as static routes and dynamic routing protocols. Web filtering, antivirus signatures, and DHCP lease durations do not determine route preference. Understanding administrative distance is useful when troubleshooting unexpected routing behavior.<\/span><\/p>\n<h3><b>Question 371. What is the main benefit of using a FortiGate loopback interface for routing or management functions?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It provides an interface that remains logically available independent of a physical port state<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It automatically replaces all firewall policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It disables dynamic routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It creates a new physical Ethernet port<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. It provides an interface that remains logically available independent of a physical port state<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A loopback interface is a logical interface that is not directly tied to a specific physical network port. Because of this characteristic, it can provide a stable IP address for certain routing, management, monitoring, or VPN-related functions even when individual physical interfaces change state. Loopback interfaces are also useful in dynamic routing designs because they can provide stable endpoint addresses. They do not create physical hardware ports, disable dynamic routing, or automatically replace firewall policies. Administrators should still ensure that appropriate routes and security policies exist for traffic using the loopback address.<\/span><\/p>\n<h3><b>Question 372. Which FortiAnalyzer feature can automatically react when a defined event or condition occurs?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ADOM<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Log archive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Event handler<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Storage quota<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Event handler<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer event handlers can identify defined events or conditions within collected security information and can support automated responses or notifications depending on the configured workflow. This allows administrators to monitor important events without manually reviewing every individual log entry. ADOMs are used to organize devices and administrative data, while log archives and storage quotas concern log storage and management. Event handlers therefore provide a mechanism for identifying significant conditions and initiating an appropriate action. Their configuration should be carefully designed to avoid excessive alerts and to focus attention on meaningful security or operational events.<\/span><\/p>\n<h3><b>Question 373. What is the purpose of FortiGate certificate revocation checking?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To increase DHCP lease duration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To determine whether a certificate has been revoked by its issuing authority<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To create firewall address groups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To assign VLAN identifiers<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To determine whether a certificate has been revoked by its issuing authority<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate revocation checking helps determine whether a digital certificate is still considered valid by its issuing certificate authority. A certificate can be revoked before its normal expiration date for reasons such as key compromise or other security concerns. Depending on the configured certificate validation method, FortiGate can use revocation information such as certificate revocation lists or supported online validation mechanisms. This improves certificate-based security by checking more than just the certificate&#8217;s expiration date. DHCP, VLAN, and firewall address-group functions do not provide certificate revocation validation.<\/span><\/p>\n<h3><b>Question 374. Which FortiGate feature can identify and control applications even when different applications use common network ports?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Application Control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> NTP<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Application Control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications based on application signatures and traffic characteristics rather than relying solely on TCP or UDP port numbers. This is important because multiple applications can use the same standard ports, while some applications may use dynamic or nonstandard ports. Application Control allows administrators to monitor or apply policy actions to recognized applications. Static routing determines packet paths, DHCP relay forwards DHCP requests, and NTP provides time synchronization. Application Control therefore provides a more application-aware method of controlling traffic within FortiGate security policies.<\/span><\/p>\n<h3><b>Question 375. What is the primary purpose of an IPsec VPN replay window?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine acceptable packet sequence numbers and help detect replayed packets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To assign IP addresses to remote users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To select the VPN encryption algorithm automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To provide DNS resolution<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To determine acceptable packet sequence numbers and help detect replayed packets<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPsec replay window defines an acceptable range of packet sequence numbers used when checking incoming protected traffic. This helps FortiGate recognize packets that are duplicated or arrive outside the permitted sequence range. The mechanism is designed to provide protection against replay attacks while allowing legitimate packets to arrive slightly out of order. It does not assign addresses, provide DNS resolution, or automatically choose encryption algorithms. Proper replay-window behavior is especially important in environments where network conditions can cause packet reordering while security against duplicated traffic remains necessary.<\/span><\/p>\n<h3><b>Question 376. Which FortiGate setting can restrict an administrator account from accessing the device from unapproved source addresses?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic shaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trusted hosts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Service group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> VIP<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. Trusted hosts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted hosts allow administrators to restrict management access for an administrator account to specified source IP addresses or networks. When trusted hosts are configured, login attempts from addresses outside the approved ranges can be denied. This provides an additional layer of protection for administrative interfaces because a valid username and password alone may not be sufficient when the request originates from an unauthorized location. Traffic shapers control bandwidth, service groups organize firewall services, and VIPs provide address translation or inbound publishing. Trusted hosts are therefore specifically useful for limiting administrative access by source network.<\/span><\/p>\n<h3><b>Question 377. What is a key advantage of using an SD-WAN volume-based strategy?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It disables all secondary WAN links<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It converts dynamic routes into static routes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It can distribute traffic based on link usage or volume<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It creates encrypted IPsec tunnels automatically<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. It can distribute traffic based on link usage or volume<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN volume-based strategy can make forwarding decisions according to traffic volume across available SD-WAN members. This can help distribute traffic more effectively when multiple WAN links are available and the administrator wants to consider utilization rather than simply selecting one fixed path. SD-WAN strategies operate within the broader SD-WAN rule and health-check framework. They do not automatically create IPsec tunnels, disable secondary links, or convert dynamic routes into static routes. The exact behavior depends on the configured SD-WAN members, rules, and performance criteria.<\/span><\/p>\n<h3><b>Question 378. What is the purpose of a FortiSwitch device authorization process when managed through FortiLink?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To allow the FortiGate to recognize and manage the switch as an authorized device<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To create an Internet service database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To configure external DNS filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To replace the FortiGate administrator account<\/span><\/li>\n<\/ol>\n<p><b>Answer: 1. To allow the FortiGate to recognize and manage the switch as an authorized device<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When FortiSwitch devices are managed through FortiLink, authorization establishes that the switch is permitted to participate in the managed network environment. After authorization, the FortiGate can provide centralized management and configuration functions for the connected FortiSwitch. This supports simplified administration and visibility across the Fortinet network. Device authorization does not create the Internet Service Database, configure DNS filtering, or replace administrator accounts. Administrators should verify the correct switch identity before authorizing a device, especially in environments where multiple switches may be connected or discovered.<\/span><\/p>\n<h3><b>Question 379. Which configuration is most appropriate when an administrator wants a FortiGate policy to use only a specific TCP service rather than allowing all services?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Select ALL services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable policy logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Select the required service object or service group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Configure an NTP server<\/span><\/li>\n<\/ol>\n<p><b>Answer: 3. Select the required service object or service group<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy can restrict permitted traffic by specifying the required service object or service group. For example, an administrator can create or select a service representing a particular TCP port and then use that service in the policy. This limits the policy to the intended application protocol instead of allowing every service. Selecting ALL would broaden the policy unnecessarily, while disabling logging does not control which services are permitted. NTP configuration is unrelated to firewall service restrictions. Precise service selection is an important part of implementing least-privilege firewall policies.<\/span><\/p>\n<h3><b>Question 380. What is a useful reason to maintain multiple FortiGate configuration revisions?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To increase interface bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To provide historical configuration states that can be reviewed or restored<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To replace antivirus scanning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To automatically create VLAN hardware<\/span><\/li>\n<\/ol>\n<p><b>Answer: 2. To provide historical configuration states that can be reviewed or restored<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration revisions provide historical versions of a FortiGate configuration. Maintaining revisions allows administrators to compare changes, investigate when a configuration difference was introduced, and restore a previous configuration when appropriate. This is especially valuable during controlled changes, troubleshooting, or recovery from an incorrect modification. Configuration revisions do not increase network bandwidth, replace antivirus inspection, or create physical VLAN hardware. Administrators should maintain an appropriate revision and backup strategy so that configuration history is available when operational or recovery requirements arise.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FGT_AD-7.6 Exam Dumps and Practice Test Dumps &nbsp; Question 361. What is the primary purpose of the FortiManager Install Preview feature? To restart all managed FortiGate devices 2. To replace the FortiManager database 3. To generate antivirus signatures 4. To review proposed configuration changes before installation Answer: 4. To review proposed configuration [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14182"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14182"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14182\/revisions"}],"predecessor-version":[{"id":14184,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14182\/revisions\/14184"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}