{"id":15789,"date":"2026-09-18T09:47:49","date_gmt":"2026-09-18T09:47:49","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15789"},"modified":"2026-09-18T09:47:49","modified_gmt":"2026-09-18T09:47:49","slug":"fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcss-efw-ad-7-6-exam-dumps\"><b>Fortinet FCSS_EFW_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which FortiGate feature is used to define a preferred route for traffic based on its destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy-based routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy-based routing allows FortiGate to make routing decisions using criteria beyond the normal destination-based routing table. Administrators can define policies that match characteristics such as source address, destination address, incoming interface, or other supported attributes and then specify the desired outgoing interface or gateway. This is useful when particular traffic needs to follow a different path than the standard routing decision. Policy-based routing should be configured carefully because its rules can change the expected path of selected traffic and affect connectivity or security.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>An administrator wants to prevent a user from accessing websites categorized as gambling. Which FortiGate security profile should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Web Filter security profile can control access to websites according to URL categories and configured filtering policies. Administrators can use FortiGuard web-category information and local filtering settings to restrict categories such as gambling, malicious websites, or other unwanted content. The profile is then applied to an appropriate firewall policy so that matching web traffic is inspected. Web filtering may depend on traffic inspection and connectivity to required FortiGuard services. Administrators should verify category behavior and policy order when troubleshooting unexpected website access.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which security profile is primarily designed to detect and block known malicious files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-in Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Antivirus security profile examines traffic for malicious files and known malware patterns. When applied to an appropriate firewall policy, it can inspect supported traffic and take configured actions when a threat is detected. Antivirus protection is different from IPS, which focuses more broadly on detecting and preventing network attacks and exploit patterns. Effective antivirus operation also depends on appropriate inspection settings and current security intelligence. Administrators should review logs when files are blocked to determine the detected threat and verify that the relevant firewall policy is handling the traffic.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>Which feature can control access to applications even when users access them through nonstandard ports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control can identify applications based on traffic characteristics rather than relying only on destination port numbers. This allows FortiGate to apply application-specific controls even when an application uses a nonstandard or unexpected port. Administrators can create application control profiles that allow, block, monitor, or otherwise handle selected applications according to the organization&#8217;s policy. Application identification may require suitable inspection and sufficient traffic information. This capability is useful when traditional service-based filtering cannot reliably identify the actual application generating network traffic.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>What is the primary purpose of a firewall policy on FortiGate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store historical logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign administrator roles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Determine how matching traffic is handled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synchronize system time<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A FortiGate firewall policy defines how traffic matching specified conditions should be handled. Conditions can include source and destination interfaces, addresses, users, services, schedules, and other supported criteria. The policy can permit or deny traffic and can also apply security profiles, logging, NAT, and related controls. Policies are evaluated according to their configured order, so an earlier matching policy can affect which rule handles traffic. Administrators should design policies carefully and regularly review unused, overly broad, or conflicting rules.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which routing protocol is commonly used to exchange routes between different autonomous systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Border Gateway Protocol, or BGP, is designed to exchange routing information between autonomous systems. It is widely used for inter-domain routing and can also be deployed within large organizational networks where advanced routing control is required. BGP uses attributes and routing policies to influence route selection and advertisement. FortiGate can participate in BGP routing when configured appropriately. Administrators should carefully control which prefixes are advertised or accepted because incorrect BGP policies can cause unwanted route propagation or connectivity problems.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which OSPF component groups routers and helps limit the scope of link-state information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Areas<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLANs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zones<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address groups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OSPF uses areas to organize the routing domain and limit the amount of link-state information that must be maintained throughout the network. Area 0 is the backbone area, and other areas can connect to it through appropriate OSPF routers. This hierarchical structure can improve scalability and reduce unnecessary routing information. FortiGate can participate in OSPF and exchange routes with neighboring routers. Correct interface configuration, network statements, areas, and neighbor relationships are important when troubleshooting OSPF route exchange.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which setting can restrict an administrator account so that it can connect only from approved IP addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trusted hosts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted hosts can restrict administrative access to FortiGate by specifying permitted source IP addresses or networks for an administrator account. This provides an additional security layer because valid credentials alone are not sufficient when the connection originates outside the configured trusted locations. Administrators can use trusted hosts to limit management access to dedicated management networks or approved workstations. The configured addresses should be maintained carefully because an incorrect trusted-host configuration can prevent legitimate administrators from accessing the device.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>A company wants to give a network administrator permission to view configuration settings but not change them. Which concept should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based administrator profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec Phase 2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A role-based administrator profile can provide restricted permissions to an administrator account. FortiGate administrator profiles allow organizations to define which areas an administrator can access and whether those areas are available with read-only or read-write permissions, depending on the configured profile. Providing view-only access is useful for monitoring or auditing personnel who do not need configuration privileges. This follows the principle of least privilege and reduces the possibility of accidental or unauthorized changes. Administrator permissions should be reviewed whenever a user&#8217;s responsibilities change.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>Which feature can prioritize or limit network traffic to manage available bandwidth?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic shaping allows FortiGate to control how available bandwidth is allocated among network traffic. Administrators can configure shaping policies or profiles to limit bandwidth consumption or prioritize important traffic according to the network&#8217;s requirements. This can help prevent bandwidth-intensive applications from consuming resources needed by business-critical services. Traffic shaping should be planned around actual link capacity and application requirements. Monitoring traffic before and after configuration can help determine whether the configured limits or priorities are producing the intended network behavior.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which FortiGate feature provides graphical visibility into traffic, applications, and network activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides graphical and interactive visibility into various aspects of FortiGate activity, including traffic, applications, sources, destinations, and security-related information. Administrators can use FortiView to identify traffic patterns, investigate unusual activity, and obtain a quick operational view of the firewall. It is primarily a visibility and analysis feature rather than a replacement for firewall policies or security profiles. More detailed historical analysis and reporting may require other Fortinet components, depending on the deployment and logging architecture.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>Which Fortinet product is designed primarily for centralized log analysis, reporting, and security event visibility?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAuthenticator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiWeb<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is designed for centralized collection, analysis, reporting, and management of logs from supported Fortinet devices and services. It can help security teams investigate events, identify trends, and generate reports from centralized data. This differs from FortiManager, which primarily focuses on centralized device and configuration management. FortiAnalyzer is especially useful when administrators need historical visibility that extends beyond what can conveniently be reviewed directly on an individual FortiGate. Proper logging configuration and storage planning are important for effective analysis.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which Fortinet product provides centralized identity and authentication services for network access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAuthenticator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAuthenticator provides centralized identity and authentication capabilities within Fortinet environments. It can support authentication services and integrate with identity sources, helping organizations centralize user authentication rather than configuring every network device independently. It can also support functions associated with Fortinet authentication architectures and token-based authentication. When deployed with FortiGate, administrators must configure appropriate communication, authentication methods, and identity integration. Centralized authentication can simplify account management while providing a consistent foundation for access-control policies across the network.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which Fortinet product is specifically designed to protect web applications from attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiEDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiWeb<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiWeb is Fortinet&#8217;s web application firewall platform, designed to protect web applications from application-layer attacks and malicious HTTP or HTTPS requests. It can inspect web traffic and apply security controls designed specifically for web applications. FortiWeb differs from FortiGate because FortiGate primarily provides network security and firewall functions, while FortiWeb focuses on protecting web applications. Deployments should place the appropriate protection layer in the traffic path and configure policies according to the application&#8217;s architecture and legitimate request patterns.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>Which feature can restrict administrative access to specific management services such as HTTPS or SSH?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative access settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec traffic selectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative access settings determine which management services are available on FortiGate interfaces. Depending on the configuration, administrators can permit services such as HTTPS, SSH, ping, or other supported management functions on selected interfaces. Limiting management services reduces the number of exposed administrative entry points. For example, an organization may permit HTTPS and SSH only on a dedicated management interface while disabling unnecessary access on user-facing interfaces. These settings should be combined with strong authentication, trusted hosts, and appropriate administrator permissions.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>Which protocol is used by network devices to synchronize their clocks with a time source?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Time Protocol, or NTP, synchronizes the system clock of network devices with an authoritative or configured time source. Accurate time is important for security logging, event correlation, authentication mechanisms, certificates, and troubleshooting. FortiGate can use configured NTP servers to maintain consistent system time. If device clocks differ significantly, timestamps in logs from different systems may be difficult to correlate. Administrators should configure reliable time sources and verify that the FortiGate can communicate with them through the required network path.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which FortiGate function can automatically provide IP addresses and related network parameters to clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A DHCP server automatically provides clients with network configuration information such as IP addresses, subnet masks, default gateways, and DNS server information. FortiGate can operate as a DHCP server on suitable interfaces, reducing the need for a separate DHCP service in smaller or specific network segments. Administrators can configure address ranges and lease parameters according to network requirements. DHCP configuration should avoid overlapping address ranges with static assignments or another DHCP server, because conflicting address allocation can create connectivity problems.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>What does source NAT typically accomplish for outbound private network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Changes the destination port<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Converts a private source address to a translated address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Creates an OSPF area<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypts the traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Source NAT changes the source address of outgoing traffic as it passes through FortiGate. A common use is translating private internal addresses to a public address so that internal clients can access external networks. FortiGate can perform source NAT using the outgoing interface address or other supported translation mechanisms, depending on policy configuration. Source NAT does not provide encryption; VPN technologies are used when confidentiality is required. Administrators should also consider return traffic, routing, and available translated addresses when troubleshooting NAT behavior.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which security feature can detect known network attack patterns and take configured preventive action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Intrusion Prevention System, or IPS, examines network traffic for patterns associated with known attacks, exploits, and other suspicious behavior. FortiGate IPS uses signatures and related detection mechanisms to identify potentially malicious traffic and can take actions such as blocking or logging according to the configured profile. IPS differs from Antivirus, which primarily focuses on malicious files and malware detection. Administrators should keep security intelligence current and tune IPS settings appropriately to balance protection with legitimate application traffic and minimize unnecessary false positives.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>A firewall policy permits traffic, but the connection still fails because FortiGate has no valid route to the destination. Which area should be investigated first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrator profiles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Routing should be investigated when FortiGate does not have a valid path to the destination. A firewall policy can permit traffic, but policy permission alone does not create a route. Administrators should examine the routing table and verify that an appropriate route, gateway, or interface exists for the destination. They should also check route preference and any policy-based routing that may influence the forwarding decision. Once routing is confirmed, firewall policy matching, NAT, and security profiles can be investigated if the connection still fails.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 221 Which FortiGate feature is used to define a preferred route for traffic based on its destination? Traffic shaping Policy-based routing Web Filter FortiView Correct Answer: 2 Explanation Policy-based routing allows FortiGate to make routing decisions using criteria beyond the normal destination-based routing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15789"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15789"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15789\/revisions"}],"predecessor-version":[{"id":15847,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15789\/revisions\/15847"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}