{"id":15785,"date":"2026-09-18T09:48:25","date_gmt":"2026-09-18T09:48:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15785"},"modified":"2026-09-18T09:48:25","modified_gmt":"2026-09-18T09:48:25","slug":"fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcss-efw-ad-7-6-exam-dumps\"><b>Fortinet FCSS_EFW_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>Which FortiGate feature allows an administrator to divide a physical FortiGate into multiple independent virtual firewall instances?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VDOM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Virtual Domains, or VDOMs, allow a FortiGate to operate as multiple logical firewall environments on the same physical device. Each VDOM can have its own interfaces, routing tables, firewall policies, and administrative configuration depending on the deployment. This separation is useful when different departments, customers, or security environments require independent administration. VDOMs can also help isolate configurations and traffic. Administrators should plan resource allocation and inter-VDOM communication carefully because improper configuration can affect connectivity or security boundaries between virtual domains.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>Which FortiGate feature is commonly used to provide redundancy by using multiple WAN connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate SD-WAN can use multiple WAN connections and select paths according to configured rules and link-performance conditions. This can improve resilience because traffic can move to another available path when a preferred link fails or no longer meets the required performance criteria. Administrators can define health checks and performance thresholds based on latency, jitter, packet loss, or availability. SD-WAN therefore provides more intelligent WAN path management than relying solely on a fixed static route. Proper rule ordering and link monitoring are essential for predictable behavior.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>What does an SD-WAN performance SLA primarily measure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrator privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link performance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus signatures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN performance SLA measures characteristics of WAN paths to determine whether they meet configured performance requirements. Common measurements include latency, jitter, packet loss, and availability. FortiGate can use these measurements when making SD-WAN path-selection decisions. For example, a voice application may require a path with low latency and jitter, while another application may tolerate higher latency. Proper SLA configuration helps ensure that traffic is directed through links that satisfy the intended application requirements rather than simply selecting a path based on basic reachability.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>A WAN link is reachable but has excessive packet loss. Which SD-WAN measurement can identify this condition?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet loss<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CPU usage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Packet loss measures the percentage of packets that fail to reach their destination or return successfully during an SD-WAN health check. A high packet-loss value indicates that a WAN path may be unreliable even though the link remains technically reachable. FortiGate can use packet-loss thresholds as part of SD-WAN performance monitoring and traffic-steering decisions. This allows applications to avoid paths that meet basic connectivity requirements but do not provide acceptable reliability. Administrators should evaluate packet loss together with latency, jitter, and link availability.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>Which IPsec parameter is negotiated during IKE Phase 1?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 2 traffic selectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption and authentication parameters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy sequence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP address range<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IKE Phase 1 establishes a secure management or negotiation channel between IPsec VPN peers. During this phase, peers negotiate parameters such as encryption algorithms, authentication methods, hashing or integrity algorithms, and Diffie-Hellman settings. Successful Phase 1 negotiation establishes the secure context needed to proceed with later IPsec negotiations. If Phase 1 fails, the VPN tunnel cannot be established normally. When troubleshooting, administrators should compare IKE settings on both peers and verify authentication credentials, peer addresses, proposals, and related configuration.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>Which IPsec phase establishes the security associations used to protect actual VPN data traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 1<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication portal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec Phase 2 establishes the security associations used to protect the actual data traffic traveling through the VPN. During this stage, peers negotiate parameters such as encryption, integrity, and traffic selectors for the protected networks. A VPN may show an established IKE Phase 1 while still failing to pass traffic if Phase 2 settings do not match or routing and firewall policies are incorrect. Troubleshooting should therefore examine both phases along with traffic selectors, routes, firewall policies, and tunnel status.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>Which FortiGate feature can translate an internal private source address into a public address for outbound traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Destination NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Source NAT changes the source address of traffic as it leaves the private network. FortiGate can translate internal private addresses to the outgoing interface address or use an IP pool containing one or more public addresses. This allows internal clients to access external networks without exposing their private IP addresses directly. Source NAT is commonly used for Internet access and other outbound connections. Administrators should distinguish it from destination NAT, which changes the destination address and is commonly associated with publishing internal services.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>Which FortiGate object is commonly used for destination NAT and port forwarding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Virtual IP, or VIP, is commonly used to perform destination NAT and port forwarding on FortiGate. It can map an external IP address and, when required, an external port to an internal server address and port. A firewall policy is then used to control whether traffic matching the VIP is allowed. Administrators should expose only necessary services and restrict the source of incoming traffic whenever practical. Logging and additional security profiles can provide further visibility and protection for publicly accessible services.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>Which FortiGate feature can restrict access to a firewall policy based on a recurring time period?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address object<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A schedule can determine when a firewall policy is active. Administrators can configure recurring time periods so that a policy applies only during defined hours or days. This can be useful for temporary access, business-hour services, maintenance activities, or limiting nonessential traffic outside working periods. A schedule does not itself identify users or services; it acts as one of the matching conditions for the firewall policy. Administrators should verify time settings and system clock synchronization so scheduled policies activate at the expected times.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which FortiGate feature allows multiple network interfaces to be grouped logically for policy configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface zone allows multiple interfaces to be grouped logically so that firewall policies can reference the zone instead of individually listing every member interface. This can simplify policy configuration when several interfaces share similar security requirements. Zones can make policies easier to maintain, particularly in environments with multiple VLANs or network segments. Administrators should understand the traffic relationships between member interfaces before grouping them because a zone can affect how policies are matched and how access is controlled between different network connections.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>Which FortiGate feature is responsible for determining the next hop for a destination IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Routing determines how FortiGate forwards packets toward their destination. The routing table contains information about available networks, next hops, interfaces, and route preferences. When traffic arrives, FortiGate uses routing information to determine where the packet should be sent after policy processing. Incorrect or missing routes can cause connectivity failures even when firewall policies are correctly configured. Administrators can inspect the routing table and use diagnostic tools such as ping, traceroute, and debug flow to understand forwarding behavior.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>A FortiGate has several possible routes to the same destination. Which route-selection attribute can influence which route is preferred?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative distance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSL certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus signature<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative distance is one factor FortiGate can use when selecting between routes learned from different sources. Generally, a route with a lower administrative distance is preferred over one with a higher value when comparing otherwise applicable routes from different routing sources. Other factors can also influence route selection, depending on the routing protocol and configuration. Administrators should examine the actual routing table rather than assuming which route will be used. Understanding route preference is important when troubleshooting unexpected forwarding behavior.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>Which routing protocol is commonly used inside an organization to exchange link-state routing information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OSPF is a link-state interior gateway protocol commonly used within organizational networks. Routers exchange link-state information and build a topology database from which routes are calculated. OSPF supports hierarchical designs through areas and can converge efficiently when network changes occur. FortiGate can participate in OSPF routing with other compatible routers. Administrators should configure appropriate areas, interfaces, authentication, and network statements according to the network design. OSPF troubleshooting often involves checking neighbor relationships, routing information, interface status, and route installation.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>What is the primary purpose of BGP route policies on FortiGate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control route advertisement and selection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt HTTPS traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign DHCP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scan files for malware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP route policies can control which routes are accepted, rejected, modified, or advertised to BGP peers. This provides administrators with control over routing information exchanged between autonomous systems or within more complex BGP environments. Route policies can use match conditions and actions to influence routing behavior. Because incorrect BGP policies can significantly affect reachability, administrators should test and review changes carefully. Route-policy design should reflect the intended routing architecture and should prevent accidental advertisement or acceptance of inappropriate network prefixes.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which FortiGate feature can authenticate an administrator against an external LDAP directory?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">LDAP integration allows FortiGate to communicate with an external directory service for user authentication and identity-related functions. Instead of maintaining every user account locally, administrators can reference directory users or groups when configuring supported authentication workflows. This can simplify centralized account management in organizations that already use directory services. Correct LDAP server settings, credentials, search parameters, and network connectivity are required. Administrators should also ensure that directory access is protected and that FortiGate receives the expected user or group information.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>Which authentication server commonly uses a shared secret between FortiGate and the authentication server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS commonly uses a shared secret to establish trust between the network device and the RADIUS server. FortiGate can send authentication requests to a configured RADIUS server, which validates the supplied credentials according to its authentication system. The shared secret must match on both sides for communication to succeed. RADIUS can centralize authentication for administrators and network users. When troubleshooting, administrators should verify the server address, UDP ports, shared secret, authentication configuration, and network connectivity between FortiGate and the RADIUS server.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>Which FortiGate security profile can control applications such as social media, streaming, and peer-to-peer services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications and allows administrators to define actions for them. This can be used to monitor, allow, restrict, or block categories and individual applications such as social media, streaming platforms, messaging services, and peer-to-peer applications. Application identification can provide more granular control than relying only on destination IP addresses or port numbers. FortiGuard application signatures help FortiGate recognize applications. Administrators should review application behavior and policy requirements because some applications may use multiple protocols or change their communication methods.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>Which FortiGate security profile is designed to detect and block known malicious files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Antivirus profile inspects supported traffic for malicious files and other malware indicators. FortiGate can use updated signatures and detection mechanisms to identify known malicious content and apply configured actions. Depending on the traffic and inspection configuration, the system can block or log detected threats. Antivirus protection is more effective when definitions and FortiGuard services remain current. It should also be combined with IPS, web filtering, application control, endpoint protection, and secure configuration because no single security control can address every type of threat.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>Which FortiGate security profile can identify malicious or suspicious URLs and web destinations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can evaluate requested websites and URLs using FortiGuard categorization, reputation information, and configured filtering rules. It can identify destinations associated with malicious, phishing, inappropriate, or otherwise restricted content and apply configured actions. Web filtering is particularly useful for controlling Internet access from user networks. HTTPS traffic may require suitable inspection to obtain additional visibility into encrypted sessions. Administrators should regularly review filtering policies and exceptions because website classifications and application behavior can change over time.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>Which FortiGate security profile can identify network-based exploitation attempts against vulnerable services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System detects network-based attacks and exploitation attempts using security signatures and other inspection mechanisms. IPS can identify patterns associated with known vulnerabilities, malicious protocols, and suspicious network activity and can take configured actions such as blocking or logging. FortiGate IPS signatures are updated through FortiGuard services to improve coverage against emerging threats. Administrators should tune IPS policies according to the environment and combine them with patch management, segmentation, endpoint protection, and secure configuration for a layered security strategy.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 141 Which FortiGate feature allows an administrator to divide a physical FortiGate into multiple independent virtual firewall instances? SD-WAN VDOM VIP FortiView Correct Answer: 2 Explanation Virtual Domains, or VDOMs, allow a FortiGate to operate as multiple logical firewall environments on the same [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15785"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15785"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15785\/revisions"}],"predecessor-version":[{"id":15850,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15785\/revisions\/15850"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}