{"id":15787,"date":"2026-09-18T09:48:03","date_gmt":"2026-09-18T09:48:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15787"},"modified":"2026-09-18T09:48:03","modified_gmt":"2026-09-18T09:48:03","slug":"fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcss-efw-ad-7-6-exam-dumps\"><b>Fortinet FCSS_EFW_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which FortiGate feature can distribute traffic across multiple servers providing the same service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual server can provide a front-end address for services hosted by multiple backend servers. FortiGate can use virtual server and load-balancing capabilities to distribute incoming connections among available servers according to the configured method. This can improve service availability and help prevent one backend server from receiving all incoming traffic. Administrators should configure appropriate health checks and backend members so unavailable servers are not selected unnecessarily. Load balancing should also be combined with suitable firewall policies and security controls to protect the published service.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>Which FortiGate feature can verify whether a backend server is still available before sending it client traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Health check<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A health check monitors the availability or responsiveness of a backend server so FortiGate can make informed load-balancing decisions. If a server fails the configured health-check criteria, FortiGate can avoid directing new connections to that server until it becomes healthy again. Health checks can use appropriate protocols or service tests depending on the configuration. Correct thresholds and intervals are important because overly aggressive settings can mark healthy servers unavailable, while weak checks may fail to detect service problems promptly.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>Which FortiGate feature can use a single public address to represent a group of backend servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Virtual Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual server can provide a public-facing address through which clients access services hosted by backend servers. FortiGate receives the incoming connection and can distribute it among configured real servers according to the selected load-balancing behavior. This architecture allows organizations to expose one service address while maintaining multiple backend systems. It can improve availability and scalability when several servers provide the same application. Administrators should configure the virtual server, backend members, service ports, health checks, and related firewall policies consistently.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>An administrator wants to prevent users from accessing a specific website while allowing other sites in the same category. Which FortiGate capability can provide a targeted exception?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter override or URL filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web filtering can use URL-specific rules or overrides to create more targeted decisions than broad category blocking. An administrator can configure a specific website or URL according to the organization&#8217;s access requirements while leaving other sites within the broader category unaffected. This is useful when a category contains both permitted and restricted destinations. Administrators should carefully define the matching pattern and action and test the result with the actual client traffic. HTTPS inspection requirements should also be considered when deeper URL visibility is needed.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>Which FortiGate capability can identify websites using FortiGuard category information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can use FortiGuard category information to classify requested websites and apply configured access decisions. Categories help administrators create broader web-access policies without maintaining a manual list of every website. For example, an organization can block categories associated with malicious or inappropriate content while allowing business-related categories. Administrators can also configure specific exceptions where necessary. Category-based filtering depends on current classification information and suitable traffic visibility, so FortiGuard updates and appropriate inspection settings are important for reliable policy enforcement.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>Which FortiGate feature can control access to network resources based on endpoint compliance information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Access Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control can use information about endpoints and their security or identity characteristics when making network-access decisions. Depending on the Fortinet deployment, endpoints can be identified and assigned appropriate access based on configured policies. Noncompliant or unknown devices can be restricted or placed into controlled network segments, while trusted devices can receive normal access. NAC is particularly useful for environments containing managed and unmanaged endpoints. Administrators should integrate endpoint visibility, authentication, segmentation, and enforcement carefully to achieve predictable access behavior.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which FortiGate capability can place traffic into a separate virtual routing and forwarding context?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VDOM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VDOMs provide separate logical firewall environments within a FortiGate. Each VDOM can maintain its own routing and security configuration, allowing organizations to isolate different networks or administrative environments on shared hardware. This separation can be useful for multi-tenant deployments, departmental environments, or situations requiring independent security policies. Administrators should understand resource allocation and communication requirements before creating VDOMs. Inter-VDOM communication, interface assignments, routing, and administrative permissions must be designed carefully to maintain the intended separation.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>Which FortiGate feature can use a dedicated interface for management traffic rather than normal production traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dedicated management interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dedicated management interface provides a separate network path for administrative access to FortiGate. Keeping management traffic separate from production traffic can reduce exposure and make administrative access easier to control. Administrators can combine a dedicated management interface with trusted hosts, secure protocols, MFA, and restrictive network policies. This architecture can also simplify monitoring and access-control requirements because management traffic is handled through a defined administrative network. The exact management-interface capabilities depend on the FortiGate model and deployment configuration.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>Which FortiGate feature can protect administrative access by limiting the protocols enabled on an interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative access settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative access settings determine which management services are available through a FortiGate interface. Administrators can enable only the protocols required for management, such as HTTPS or SSH, while disabling unnecessary services. Restricting management protocols reduces the number of exposed services and therefore limits opportunities for unauthorized access. This control should be combined with trusted hosts, strong authentication, MFA, and appropriate network segmentation. Management access should generally be provided only through interfaces and networks specifically intended for administration.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a centralized view of security events generated by multiple Fortinet devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiWeb<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiSwitch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized collection and analysis of logs and security events from supported Fortinet devices. By consolidating information from multiple FortiGate systems, it allows administrators to investigate events across a broader environment rather than examining each firewall separately. It can also support dashboards, reports, and historical analysis. Centralized event visibility is valuable for incident investigation and operational monitoring. Administrators should configure appropriate log forwarding and retention settings so important events are available for analysis when required.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which FortiGate feature can limit access to a service by specifying the permitted source and destination addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A firewall policy can define the source and destination addresses that are permitted to communicate through FortiGate. It can also include interfaces, services, schedules, users, and security profiles to create more detailed access rules. Restricting source and destination addresses helps enforce least-privilege network access by allowing communication only between required systems. Administrators should avoid unnecessarily broad address objects because they can expand the scope of permitted traffic. Policy order must also be considered because an earlier matching rule may handle the traffic.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>Which FortiGate feature can apply a security profile to traffic after it matches a firewall policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policy security profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security profiles can be attached to firewall policies to apply additional inspection and protection to permitted traffic. Depending on the policy and configuration, profiles can provide functions such as antivirus scanning, web filtering, application control, IPS, and other security services. This allows administrators to combine basic traffic control with deeper security inspection. The exact profiles used should match the traffic type and organizational requirements. Administrators should also verify that inspection settings provide the necessary visibility, particularly when traffic is encrypted.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>Which FortiGate feature can enforce different security inspection requirements for different types of traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall policies with security profiles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP reservations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static DNS entries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGate firewall policies can apply different security profiles and inspection settings to different traffic flows. For example, Internet browsing traffic may require web filtering and antivirus inspection, while another application may require IPS protection or application control. Creating policies according to traffic requirements allows administrators to apply appropriate security controls without treating every connection identically. Policy matching conditions such as interfaces, addresses, services, users, and schedules can help separate traffic types. Careful policy design reduces unnecessary inspection while maintaining the required security coverage.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>Which FortiGate capability can provide detailed records of actions taken by administrators?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative event logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative event logging records management activities and configuration-related events on FortiGate. These logs can help identify who performed an administrative action, what type of activity occurred, and when it happened. Such information is valuable for troubleshooting, accountability, and security investigations. Administrators should ensure that relevant event logging is enabled and that logs are retained appropriately. Centralized logging through FortiAnalyzer can provide additional visibility when multiple FortiGate devices are involved and can help correlate administrative actions with other security events.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a temporary access period without requiring a policy to remain active permanently?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A policy schedule can limit when a firewall policy is active, making it useful for temporary or recurring access requirements. For example, administrators can permit access during a defined maintenance window and automatically disable the policy outside that period. This reduces the need to manually modify or remove the rule after the approved access period ends. Schedules can also support recurring business-hour requirements. Administrators should verify system time and timezone configuration so the policy activates and expires at the intended times.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>Which FortiGate feature can help identify whether a firewall policy is being used by active sessions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session monitoring provides information about active network sessions handled by FortiGate. Administrators can use session information to examine current connections, including relevant source and destination details and associated traffic. This can help determine whether a policy is actively handling traffic and can support troubleshooting when a connection behaves unexpectedly. Session monitoring is different from historical logging because it focuses on active or current session information. Administrators can combine session information with policy lookup, logs, routing data, and debug tools for more complete analysis.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which FortiGate capability can help protect against unauthorized configuration changes by limiting administrator permissions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based administrator profiles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based administrator profiles allow FortiGate administrators to receive only the permissions necessary for their assigned responsibilities. Restricting configuration access reduces the chance that a compromised or misused account can make unauthorized changes to critical security settings. Different profiles can provide read-only, monitoring, or specific configuration privileges depending on the administrative role. Administrators should periodically review accounts and profiles and remove unnecessary permissions. Combining role-based access with MFA, trusted hosts, and administrative logging provides stronger protection for the firewall management plane.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>Which FortiGate feature can identify suspicious communication patterns that match known attack signatures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPS uses security signatures and inspection mechanisms to identify network activity associated with known attacks and suspicious patterns. When traffic matches a configured IPS signature, FortiGate can take an action such as blocking or logging the event according to the profile configuration. IPS signature updates help maintain protection against newly identified threats. Administrators should tune IPS policies to the environment and investigate significant detections rather than relying only on automatic blocking. Combining IPS with endpoint security, segmentation, patching, and access controls provides broader defense.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which FortiGate feature can make Internet access decisions based on the category or reputation of a requested domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Filter can evaluate DNS requests using category and reputation information and apply configured actions to requested domains. This can prevent users from resolving known malicious or restricted domains before they establish a connection to those destinations. It provides an early filtering layer that can complement web filtering and endpoint protection. Administrators should ensure that clients use the intended DNS path so requests can be inspected by the configured control. DNS filtering alone does not replace deeper inspection of application content or encrypted traffic.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>Which FortiGate feature can help administrators investigate why traffic is being denied by a firewall policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy lookup and traffic logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP reservations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy lookup and traffic logs provide complementary information when investigating denied traffic. Policy lookup can help determine which configured rule should match a particular traffic flow, while traffic logs can show actual sessions, actions, source and destination information, and other details depending on logging configuration. Administrators can use these tools to identify incorrect addresses, services, interfaces, schedules, or policy ordering. If the cause remains unclear, packet capture and debug flow can provide deeper information about packet processing and forwarding decisions.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 181 Which FortiGate feature can distribute traffic across multiple servers providing the same service? DNS Filter Virtual Server FortiAnalyzer FortiToken Correct Answer: 2 Explanation A virtual server can provide a front-end address for services hosted by multiple backend servers. FortiGate can use virtual [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15787"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15787"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15787\/revisions"}],"predecessor-version":[{"id":15848,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15787\/revisions\/15848"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}