{"id":15795,"date":"2026-09-18T09:46:14","date_gmt":"2026-09-18T09:46:14","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15795"},"modified":"2026-09-18T09:46:14","modified_gmt":"2026-09-18T09:46:14","slug":"fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcss_efw_ad-7-6-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcss-efw-ad-7-6-exam-dumps\"><b>Fortinet FCSS_EFW_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which FortiGate feature can control traffic based on the destination application or service while also applying security inspection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications from network traffic and allows FortiGate to apply configured actions to them. Administrators can use application signatures and categories to monitor or restrict applications, even when traditional port-based identification is insufficient. Application Control can be combined with other security profiles on a firewall policy to provide layered inspection. When an application is not detected as expected, administrators should verify the inspection configuration, traffic flow, and available application signatures. This provides more granular application visibility than relying solely on TCP or UDP service definitions.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which setting determines the IP address range assigned by a FortiGate DHCP server to clients?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP address range<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The DHCP address range defines the pool of IP addresses that FortiGate can lease to DHCP clients. When configuring a DHCP server, administrators specify the appropriate address range along with other parameters such as the default gateway, DNS information, and lease settings. The range should belong to the correct subnet and must not overlap with statically assigned addresses or another DHCP server. If clients receive unexpected or duplicate addresses, administrators should review the DHCP configuration and network topology. Proper address planning prevents conflicts and improves reliable client connectivity.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which feature can determine whether a FortiGate interface should accept administrative HTTPS connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative access settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative access settings determine which management services are enabled on FortiGate interfaces. HTTPS can be enabled on an appropriate management interface so administrators can access the FortiGate graphical interface securely. Organizations should avoid enabling management services on interfaces where they are unnecessary, especially interfaces exposed to untrusted networks. Administrative access settings work together with trusted hosts, administrator authentication, and administrator profiles. If an administrator cannot connect through HTTPS, the interface&#8217;s administrative access configuration should be checked along with network reachability and any local-in restrictions.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which security control can restrict management access to the FortiGate itself rather than forwarded traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-in policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A local-in policy controls traffic destined for the FortiGate itself. This differs from ordinary firewall policies, which primarily control traffic passing through FortiGate toward another network destination. Local-in policies can be used to restrict access to services exposed on FortiGate interfaces, including management services. Administrators can define permitted sources, interfaces, and services to reduce exposure. Because these policies directly affect access to the firewall, they should be configured carefully and tested before deployment to avoid unintentionally blocking legitimate administrative connections.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>A FortiGate administrator needs to determine whether a route exists for a remote subnet. What should be checked?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter categories<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Routing table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The routing table shows the routes currently available to FortiGate and helps determine how traffic toward a destination will be forwarded. When a remote subnet cannot be reached, administrators should verify that an appropriate route exists and points toward the correct next hop or interface. They should also consider route preference when multiple routes are available. If policy-based routing is configured, it should be reviewed as well because it can influence forwarding decisions. Routing should be confirmed before investigating higher-level security controls when basic connectivity is failing.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which feature can collect security logs from FortiGate devices for centralized investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiWeb<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAuthenticator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized collection and analysis of logs generated by supported Fortinet devices. Security teams can use it to investigate historical events, correlate activity, review traffic information, and generate reports. Centralized logging is especially useful when an organization operates multiple FortiGate devices because events can be reviewed from a common platform. FortiManager has a different primary role focused on configuration and policy management. Administrators should configure appropriate log forwarding, retention, and access controls to ensure that important security information remains available for investigation.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which FortiGate feature allows different firewall policies to use different inspection profiles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security profiles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security profiles can be attached to individual firewall policies, allowing administrators to apply different inspection controls to different traffic flows. One policy might use Antivirus and IPS, while another could additionally use Web Filter or Application Control according to its traffic requirements. This provides flexibility because not all traffic requires identical inspection. Administrators should ensure that the selected profiles are appropriate for the policy and inspection mode. Reviewing security-profile logs can help determine whether traffic was blocked by a specific inspection feature after being permitted by the firewall policy.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which feature can authenticate a user with a one-time password generated by a token?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken MFA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiToken-based multi-factor authentication can provide a one-time password as an additional authentication factor. The token can be used alongside a normal password to strengthen authentication for supported FortiGate access scenarios. This reduces reliance on a password alone because an attacker who obtains the password would still need the additional authentication factor. Administrators must correctly enroll tokens, associate them with users, and configure the relevant authentication method. Token synchronization, enrollment status, and user configuration should be checked when one-time-password authentication fails.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which FortiGate capability can inspect the contents of encrypted HTTPS sessions when configured appropriately?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deep inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Deep inspection allows FortiGate to decrypt and inspect supported encrypted traffic so that security profiles can analyze the application payload. This provides substantially more visibility than certificate inspection, which examines certificate and connection information without full payload decryption. Deep inspection requires careful certificate deployment because clients generally need to trust the inspection certificate. Administrators should also consider privacy, application compatibility, and appropriate exemptions. When deep inspection is enabled, security profiles such as Antivirus, IPS, Web Filter, or Application Control can gain greater visibility into protected traffic.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which FortiGate feature can determine whether a WAN member is meeting configured performance thresholds?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrator profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Performance SLA evaluates the condition of an SD-WAN member using configured health checks and performance thresholds. Depending on the configuration, measurements can include latency, jitter, packet loss, and availability. The results can be used by SD-WAN rules when selecting an appropriate path for traffic. Administrators should configure targets that reflect the requirements of the applications being protected. If an SLA frequently fails, the underlying WAN connection should also be investigated rather than simply increasing thresholds without understanding the cause of poor performance.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which protocol is primarily responsible for resolving hostnames into IP addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Domain Name System, or DNS, translates hostnames into IP addresses and supports other types of name-resolution information. Network devices and clients use DNS to locate services and destinations by name rather than requiring users to remember numerical addresses. FortiGate can use configured DNS servers for its own resolution and can also provide DNS-related security functions through features such as DNS Filter. When name-based connections fail while direct IP connectivity works, administrators should investigate DNS configuration, reachability, and filtering policies.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which FortiGate feature can group multiple interfaces into a common logical policy object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface zone allows multiple interfaces to be grouped for policy configuration. This can simplify firewall policies when several interfaces have similar security requirements and should be treated as a common logical group. Instead of creating separate policies for every interface, administrators can reference the zone where appropriate. However, grouping interfaces can broaden the scope of a policy, so all interfaces within the zone should have compatible security requirements. Careful interface organization and clear naming help prevent accidental access between networks that should remain separated.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>What does administrative distance help FortiGate determine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which security profile scans a file<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which route source is preferred<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which DNS category is blocked<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which administrator can log in<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative distance indicates the preference of routes learned from different routing sources. When multiple routing sources provide routes toward the same destination, administrative distance helps determine which source should be preferred before protocol-specific route-selection factors are considered. This allows administrators to establish relationships between static and dynamic routing information. It should not be confused with a routing protocol&#8217;s internal metric. When FortiGate selects an unexpected route, administrators should review available routes, their sources, administrative distances, and any policy-based routing configuration that may affect forwarding.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which FortiGate feature can identify a website category using FortiGuard information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec Phase 2<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter can use FortiGuard web-category information to classify websites and enforce configured access policies. Administrators can allow, block, monitor, or otherwise handle categories according to organizational requirements. This provides broad web-access control without requiring administrators to manually maintain every website address. The Web Filter profile must be applied to the appropriate firewall policy, and required FortiGuard connectivity should be available. If categorization appears incorrect or unavailable, administrators should review the filtering configuration, inspection method, and FortiGuard service status.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which IPsec setting controls the encryption and authentication proposals negotiated for protected traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP options<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phase 2 proposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Filter category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrator profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The IPsec Phase 2 proposal defines the cryptographic parameters used to protect data traffic within the VPN security association. Depending on the configuration, it can specify supported encryption and authentication algorithms. The VPN peers must have compatible proposals for successful Phase 2 negotiation. If Phase 1 is established but the tunnel does not successfully negotiate protected traffic, administrators should compare Phase 2 proposals along with traffic selectors and other settings. Strong and compatible cryptographic settings should be selected according to the organization&#8217;s security requirements and supported FortiOS configuration.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which FortiGate feature can provide a public-to-private port mapping for a specific service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VIP with port forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VIP with port forwarding can map a public destination address and port to a specific private server address and port. This is commonly used to publish selected internal services such as web applications to external clients. Administrators should create a corresponding firewall policy that permits only the required traffic and should avoid exposing unnecessary services. Security profiles can provide additional inspection where appropriate. When troubleshooting port-forwarding problems, administrators should verify the VIP mapping, external and internal ports, firewall policy, routing, and whether the internal server is actually listening on the expected service.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which FortiGate function can display information about traffic currently passing through the firewall?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiView<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiView provides interactive visibility into traffic and security activity on FortiGate. It can display information about sources, destinations, applications, sessions, bandwidth, and other traffic characteristics depending on the available data and view. This helps administrators quickly identify traffic patterns and investigate unusual activity. FortiView is primarily a monitoring and visualization capability rather than a replacement for detailed packet diagnostics. When deeper analysis is required, administrators can combine FortiView information with session monitoring, traffic logs, policy lookup, packet capture, or debug flow.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which FortiGate feature can limit bandwidth consumed by a particular class of traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiToken<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic shaping controls how bandwidth is allocated to selected network traffic. Administrators can use shaping policies or profiles to limit bandwidth consumption or prioritize important traffic according to business requirements. This can prevent bandwidth-intensive applications from consuming resources needed by critical services. Traffic shaping should be configured according to the actual capacity of the WAN or network link. Administrators should monitor traffic before and after applying shaping rules to verify that the configured limits produce the expected result without unnecessarily degrading legitimate business applications.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which FortiGate feature can provide centralized authentication services and identity integration for network users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAuthenticator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiWeb<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAuthenticator provides centralized identity and authentication services for Fortinet environments. It can integrate with supported identity sources and authentication mechanisms, allowing organizations to centralize user authentication rather than maintaining separate authentication systems on individual network devices. It can also support token-based authentication and related identity functions depending on the deployment. When integrated with FortiGate, administrators need appropriate connectivity and authentication configuration. Centralized identity services can simplify access management while supporting more consistent authentication and authorization policies across the network.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which FortiGate diagnostic command can help administrators inspect the routing table from the CLI?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get router info routing-table all<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">diagnose debug application ssl<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">execute backup config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">get system status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">get router info routing-table all<\/span><span style=\"font-weight: 400;\"> command displays routing-table information from the FortiGate CLI. Administrators can use it to examine routes, their associated interfaces, gateways, and other routing information when troubleshooting connectivity. It is particularly useful when determining whether FortiGate has a valid path toward a destination. If routing appears correct but traffic still fails, administrators can continue with policy lookup, debug flow, packet capture, and security-profile logs. Understanding the routing table is an important part of systematic FortiGate connectivity troubleshooting.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 Which FortiGate feature can control traffic based on the destination application or service while also applying security inspection? Application Control NTP VLAN RADIUS Correct Answer: 1 Explanation Application Control identifies applications from network traffic and allows FortiGate to apply configured actions to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15795"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15795"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15795\/revisions"}],"predecessor-version":[{"id":15840,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15795\/revisions\/15840"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}