{"id":20860,"date":"2026-09-24T08:08:31","date_gmt":"2026-09-24T08:08:31","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20860"},"modified":"2026-09-24T08:08:31","modified_gmt":"2026-09-24T08:08:31","slug":"fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fct-ad-7-4-exam-dumps\"><b>Fortinet FCP_FCT_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 61. What must be enabled in a FortiClient EMS System Settings profile for Web Filter options to function on Windows, macOS, and Linux endpoints?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSL VPN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Vulnerability Scan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sandbox Detection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiProxy (Disable Only When Troubleshooting)<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. FortiProxy (Disable Only When Troubleshooting)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient Web Filter depends on FortiProxy functionality on supported Windows, macOS, and Linux endpoints. Fortinet specifically states that the <\/span><b>FortiProxy (Disable Only When Troubleshooting)<\/b><span style=\"font-weight: 400;\"> option must be enabled in the System Settings profile before Web Filter options can operate. Because FortiProxy participates in the traffic-inspection path used by several FortiClient security functions, disabling it as a normal configuration choice can prevent expected filtering behavior. If Web Filter has been enabled in its endpoint profile but does not operate correctly, confirming that FortiProxy remains enabled should be an early troubleshooting step.<\/span><\/p>\n<p><b>Question 62. A Web Filter profile is scheduled from 8:00 AM to 6:00 PM. An endpoint user manually changes the endpoint system clock. What determines whether the Web Filter schedule is active?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint&#8217;s newly configured clock<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system time on EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiGate system time only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiAnalyzer system time<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The system time on EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Filter scheduling in FortiClient EMS is based on the system time maintained by EMS, not the endpoint&#8217;s local clock. Fortinet specifically documents that changing time on an endpoint does not affect the configured Web Filter schedule. This prevents an endpoint user from bypassing scheduled filtering merely by modifying the workstation&#8217;s clock. Administrators configuring time-based web policies should therefore verify the EMS server&#8217;s system time and time-zone configuration when scheduled filtering starts or ends unexpectedly. Troubleshooting should focus on EMS time rather than assuming the endpoint&#8217;s local time controls enforcement.<\/span><\/p>\n<p><b>Question 63. What can a custom URL filter exclusion do in FortiClient Web Filter?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Override the action that would otherwise be determined by the FortiGuard URL category<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace the FortiGuard categorization database globally<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable FortiClient Telemetry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create an EMS administrator account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Override the action that would otherwise be determined by the FortiGuard URL category<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient Web Filter normally submits detected domains to FortiGuard for categorization and then applies the administrator-configured action associated with the returned category. A custom URL filter exclusion can override that normal category-based handling for specifically defined URLs. This gives administrators a way to create exceptions without changing the action for an entire FortiGuard category. For example, an organization could allow a particular site while continuing to block the broader category to which FortiGuard assigns it. Custom URL handling is therefore useful for controlled exceptions to centrally managed category-based filtering.<\/span><\/p>\n<p><b>Question 64. Why can a user receive a browser certificate warning when FortiClient blocks an HTTPS website?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient automatically replaces every website certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS revokes the site&#8217;s public certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient uses certificate inspection rather than SSL deep inspection, so it cannot always present a trusted HTTPS block page<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer encrypts the web-filter response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. FortiClient uses certificate inspection rather than SSL deep inspection, so it cannot always present a trusted HTTPS block page<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient does not perform SSL deep inspection in the same manner as a FortiGate configured for deep inspection. Instead, it uses certificate inspection for HTTPS web filtering. Because of this, when FortiClient blocks an HTTPS site, it may be unable to display a traditional block page over a connection the browser considers trusted, which can result in a certificate warning. Fortinet documents alternatives such as using the browser plug-in for HTTPS filtering or configuring the applicable HTTPS blocking behavior. This is expected behavior rather than necessarily evidence of a broken website certificate.<\/span><\/p>\n<p><b>Question 65. What actions can the FortiClient Application Firewall apply to supported application categories or application signatures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt, Decrypt, or Archive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow, Block, or Monitor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route, NAT, or Proxy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authenticate, Quarantine, or Delete<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Allow, Block, or Monitor<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FortiClient Application Firewall can classify applications using Fortinet application-control signatures and apply one of three principal actions: <\/span><b>Allow<\/b><span style=\"font-weight: 400;\">, <\/span><b>Block<\/b><span style=\"font-weight: 400;\">, or <\/span><b>Monitor<\/b><span style=\"font-weight: 400;\">. Administrators can configure actions at the application-category level or create application overrides for particular signatures. Categories include areas such as P2P, Proxy, Remote Access, Social Media, Cloud Applications, VoIP, and Video\/Audio. Application overrides allow exceptions to the broader category policy. This gives EMS administrators centralized control over endpoint application traffic without requiring a separate rule for every application unless more granular handling is needed.<\/span><\/p>\n<p><b>Question 66. What does \u201cBlock Known Communication Channels Used by Attackers\u201d enable in a FortiClient Firewall profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL category filtering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full SSL inspection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active Directory password blocking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Command-and-control detection using known malicious IP address and port combinations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Command-and-control detection using known malicious IP address and port combinations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Block Known Communication Channels Used by Attackers<\/b><span style=\"font-weight: 400;\"> option enables command-and-control detection using IP reputation information. FortiClient compares endpoint network traffic against known C&amp;C IP address and port combinations and can block communication associated with attacker infrastructure. This capability helps stop compromised applications or malware from communicating with known command-and-control systems. It is part of the endpoint Application Firewall profile and should not be confused with Web Filter URL categorization or SSL inspection. Fortinet treats C&amp;C detection as a network-based endpoint protection mechanism using known malicious communication indicators.<\/span><\/p>\n<p><b>Question 67. What is the purpose of the \u201cDetect &amp; Block Exploits\u201d setting in a FortiClient Firewall profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inspect network traffic for intrusion attempts that exploit known vulnerabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically patch every detected software vulnerability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block all executable files from running<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable VPN access when a vulnerability exists<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Inspect network traffic for intrusion attempts that exploit known vulnerabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><b>Detect &amp; Block Exploits<\/b><span style=\"font-weight: 400;\"> enables inspection of network traffic for intrusion attempts designed to exploit known vulnerabilities. It complements other FortiClient security capabilities by focusing on malicious exploitation attempts observed in traffic rather than simply identifying missing software patches. Vulnerability Scan, by comparison, identifies vulnerable software and operating-system conditions, while the firewall exploit protection inspects traffic for active attacks. Understanding this difference is important for exam scenarios because FortiClient combines several security layers, and each feature addresses a different part of the endpoint attack chain.<\/span><\/p>\n<p><b>Question 68. Why should an administrator avoid using application signatures marked \u201cDeep Inspection\u201d in a FortiClient Firewall profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They can be used only with FortiAnalyzer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They permanently disable FortiClient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient does not provide SSL deep inspection and therefore cannot apply those signatures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deep Inspection signatures are supported only on Linux EMS servers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. FortiClient does not provide SSL deep inspection and therefore cannot apply those signatures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet explicitly warns administrators not to use application-control signatures marked <\/span><b>Deep Inspection<\/b><span style=\"font-weight: 400;\"> in a FortiClient Firewall profile. FortiClient does not include SSL deep inspection, so it cannot apply signatures that require decrypted application payload inspection. When administrators browse application signatures for overrides, EMS indicates whether a signature requires deep inspection. Those signatures should be excluded from FortiClient profiles. This is an important architectural distinction between endpoint application control and FortiGate security profiles, where SSL deep inspection can be available and can support signatures that depend on inspecting encrypted application content.<\/span><\/p>\n<p><b>Question 69. What can happen if an administrator configures more than 1,000 Application Firewall application overrides in EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient automatically converts them into Web Filter rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS ignores every override above 1,000 without impact<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer takes over application-control processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS instability can occur, so Fortinet does not recommend exceeding 1,000 overrides<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. EMS instability can occur, so Fortinet does not recommend exceeding 1,000 overrides<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet warns that configuring more than 1,000 application overrides is not recommended because it can cause EMS instability. Overrides are intended to provide exceptions or special handling for selected application signatures while category-level policies handle broader application classes. If an administrator attempts to reproduce an entire application-control database through thousands of individual overrides, the configuration becomes inefficient and can affect EMS stability. A better design is generally to configure appropriate category actions and then use a manageable number of overrides for specific applications that require treatment different from their parent category.<\/span><\/p>\n<p><b>Question 70. In a FortiClient EMS Firewall profile, what is true of \u201cCustom Application Overrides\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient does not support this feature, so administrators should not configure it<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is required before normal application overrides can work<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is supported only when FortiClient is off-fabric<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It automatically creates FortiGuard signatures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FortiClient does not support this feature, so administrators should not configure it<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet&#8217;s current FortiClient 7.4 documentation explicitly states that <\/span><b>Custom Application Overrides<\/b><span style=\"font-weight: 400;\"> are not supported by FortiClient and should not be configured. This differs from ordinary application overrides, where administrators select supported Fortinet application signatures and apply Allow, Block, or Monitor actions. The distinction can be easy to overlook when similar terminology exists across Fortinet products. Exam questions may test whether administrators understand which FortiGate-style application-control capabilities are actually implemented on FortiClient. Unsupported features should not be included in endpoint firewall profiles.<\/span><\/p>\n<p><b>Question 71. What happens when the \u201cRequire Password to Disconnect From EMS\u201d option is enabled in a System Settings profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint user cannot log in to Windows<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user must enter the configured password before disconnecting FortiClient from EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS requires the FortiGate administrator password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient automatically disconnects when the password expires<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The user must enter the configured password before disconnecting FortiClient from EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The System Settings profile includes a control allowing administrators to require a password before users can disconnect FortiClient from EMS. This helps prevent local users from intentionally removing their endpoint from centralized management. Depending on the profile configuration, administrators can also control whether an endpoint administrator is allowed to uninstall FortiClient using the command line without the disconnection password. These controls are useful when organizations need to prevent managed endpoints from bypassing corporate security policies, Telemetry, posture evaluation, or centralized configuration simply by disconnecting the client from EMS.<\/span><\/p>\n<p><b>Question 72. What is the purpose of the \u201cDo Not Allow User to Back Up Configuration\u201d option in the FortiClient System Settings profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent EMS from backing up its database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable FortiAnalyzer log retention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent endpoint users from creating backups of the local FortiClient configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent FortiGate from exporting firewall policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Prevent endpoint users from creating backups of the local FortiClient configuration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Do Not Allow User to Back Up Configuration<\/b><span style=\"font-weight: 400;\"> setting prevents users from using FortiClient to create local backups of the endpoint configuration. This can help organizations maintain control over managed security settings and reduce the risk that users export centrally managed configuration for reuse or manipulation outside the intended management framework. The option applies to endpoint FortiClient configuration rather than EMS database backup or FortiGate configuration export. System Settings profiles contain several controls of this type that regulate how much local administrative freedom endpoint users retain while the device is centrally managed by EMS.<\/span><\/p>\n<p><b>Question 73. In FortiClient EMS logging, what happens if the EMS log level is configured as Info?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Messages from Info through Emergency are included in the EMS logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only Info messages are recorded<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Debug messages are recorded but critical messages are discarded<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS stops generating system-event logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Messages from Info through Emergency are included in the EMS logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS logging uses severity levels. When the administrator selects a particular log level, EMS includes messages from that severity through the more severe levels. Fortinet gives the example that selecting <\/span><b>Info<\/b><span style=\"font-weight: 400;\"> records messages from Info through Emergency. Lower-level debugging messages are not included unless Debug is selected. This model allows administrators to balance visibility against log volume. During ordinary operations, a moderate severity threshold may be appropriate, while temporary Debug logging can provide more detailed information when troubleshooting. Administrators should also configure retention so accumulated logs do not grow indefinitely.<\/span><\/p>\n<p><b>Question 74. What does the \u201cAutomatically clear logs older than\u201d setting control in FortiClient EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The maximum age of endpoint operating systems<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of days EMS retains logs before automatically deleting older log entries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The expiration date of EMS licenses<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The age of vulnerability signatures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The number of days EMS retains logs before automatically deleting older log entries<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Under <\/span><b>System Settings &gt; Logs<\/b><span style=\"font-weight: 400;\">, EMS allows administrators to define how many days logs should be retained before older entries are automatically cleared. Log retention should be planned according to troubleshooting needs, operational policies, available storage, and any relevant compliance requirements. This setting applies to EMS logs and alerts, not endpoint operating-system age, EMS license expiration, or FortiGuard signature updates. Administrators should balance retaining enough history for diagnostics against unnecessarily storing a continuously growing volume of operational logs. A sensible retention policy is part of maintaining a healthy EMS server.<\/span><\/p>\n<p><b>Question 75. Which FortiClient logging severity generates detailed debug logs for selected endpoint features such as Telemetry, IPsec VPN, SSL VPN, Web Filter, and Sandbox?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Notice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Warning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Debug<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Emergency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Debug<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Debug<\/b><span style=\"font-weight: 400;\"> logging severity enables detailed endpoint logs for selected FortiClient features. Fortinet lists features such as AntiVirus, Application Firewall, Telemetry, FSSOMA, Proxy, IPsec VPN, AntiExploit, SSL VPN, Update, Vulnerability, Web Filter, and Sandbox. These detailed logs can then be included when diagnostic-tool output is requested for deeper troubleshooting. Debug logging can generate significantly more information than normal operating levels, so it is generally best enabled when investigating a specific issue rather than used permanently without need. Selecting the appropriate feature reduces unnecessary log volume while preserving relevant technical detail.<\/span><\/p>\n<p><b>Question 76. Which FortiClient event categories are included when \u201cUpload Security Event\u201d is enabled for FortiAnalyzer or FortiManager logging?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only license-renewal messages<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only endpoint logon and logoff events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Malware Protection, Web Filter, Vulnerability Scan, and Application Firewall events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only EMS database backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Malware Protection, Web Filter, Vulnerability Scan, and Application Firewall events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The System Settings profile can instruct FortiClient to upload several types of security events to FortiAnalyzer or FortiManager. <\/span><b>Upload Security Event<\/b><span style=\"font-weight: 400;\"> specifically includes events from Malware Protection, Web Filter, Vulnerability Scan, and Application Firewall. A separate <\/span><b>Upload System Event<\/b><span style=\"font-weight: 400;\"> option covers system-oriented information such as endpoint control, updates, and FortiClient events. This separation allows administrators to choose what operational and security telemetry should be forwarded for centralized analysis. Correct logging configuration is important when FortiAnalyzer is used for endpoint visibility, event investigation, threat hunting, or Security Fabric workflows.<\/span><\/p>\n<p><b>Question 77. Which FortiClient EMS license is required for the \u201cSend Software Inventory\u201d feature to FortiAnalyzer or FortiManager?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Free Trial only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ZTNA license only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No EMS license is required<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EPP license<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. EPP license<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that <\/span><b>Send Software Inventory<\/b><span style=\"font-weight: 400;\"> requires an Endpoint Protection Platform (EPP) license. When enabled, EMS sends FortiClient software-inventory information to FortiAnalyzer or FortiManager, giving administrators centralized visibility into software installed on managed endpoints. This requirement aligns with the broader EPP feature set, which includes advanced endpoint-protection and inventory capabilities beyond the core ZTNA license. If the software-inventory option is unavailable or does not behave as expected, administrators should confirm the EMS license entitlement before troubleshooting FortiAnalyzer connectivity or endpoint configuration.<\/span><\/p>\n<p><b>Question 78. On which endpoint platforms does EMS support sending operating-system events to FortiAnalyzer or FortiManager through the documented \u201cSend OS Events\u201d feature?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Windows and macOS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Linux only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Android only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Chromebook only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Windows and macOS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS supports the <\/span><b>Send OS Events<\/b><span style=\"font-weight: 400;\"> feature for Windows and macOS endpoints. On Windows, FortiClient can send events from the Windows Event Viewer System, Security, and Applications categories, including user login and logout events. On macOS, relevant OS events are sourced from the system log. These events can be forwarded to FortiAnalyzer or FortiManager for additional visibility and analysis. The feature is not documented as a generic all-platform capability for Linux, Android, or Chromebook endpoints. Platform support should therefore be verified when designing centralized host-event collection.<\/span><\/p>\n<p><b>Question 79. What does the \u201cClient-Based Logging When On-Fabric\u201d setting control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether FortiClient includes local log messages while the endpoint is on-fabric<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether EMS creates Active Directory users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether FortiClient obtains a DHCP lease<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether FortiAnalyzer stores only VPN logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Whether FortiClient includes local log messages while the endpoint is on-fabric<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Client-Based Logging When On-Fabric<\/b><span style=\"font-weight: 400;\"> option controls whether FortiClient includes local log messages while the endpoint is considered on-fabric. Fortinet also notes that when the endpoint is off-fabric, FortiClient hides local <\/span><b>Export log<\/b><span style=\"font-weight: 400;\"> and <\/span><b>Clear log<\/b><span style=\"font-weight: 400;\"> options from the GUI, although FortiClient can still send logs to FortiAnalyzer when such forwarding is configured. This feature concerns endpoint-local logging behavior and should not be confused with EMS server logging or the separate upload options controlling which categories of events are forwarded to FortiAnalyzer or FortiManager.<\/span><\/p>\n<p><b>Question 80. An administrator must create a centrally managed endpoint configuration that blocks risky applications, filters websites on a business-hours schedule, prevents users from disconnecting from EMS, and forwards security events to FortiAnalyzer. Which design is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure all settings manually on each endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only an EMS deployment package with no profiles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Build appropriate Firewall, Web Filter, and System Settings profiles, combine them through an endpoint policy, and configure FortiAnalyzer logging<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only FortiAnalyzer because it can directly configure all FortiClient endpoint features<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Build appropriate Firewall, Web Filter, and System Settings profiles, combine them through an endpoint policy, and configure FortiAnalyzer logging<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS uses modular endpoint profiles to centrally configure endpoint security features. The Firewall profile can control application categories and signatures, the Web Filter profile can enforce scheduled category and URL filtering, and the System Settings profile can restrict local client actions such as EMS disconnection and configure logging to FortiAnalyzer or FortiManager. Administrators combine the required profiles in an endpoint policy and assign that policy to applicable endpoints. This preserves centralized control and consistent enforcement. FortiAnalyzer provides analysis and reporting but does not replace EMS as the central FortiClient configuration authority.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps. Question 61. What must be enabled in a FortiClient EMS System Settings profile for Web Filter options to function on Windows, macOS, and Linux endpoints? SSL VPN Vulnerability Scan Sandbox Detection FortiProxy (Disable Only When Troubleshooting) Correct Answer: 4. FortiProxy (Disable Only When Troubleshooting) Explanation: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20860"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20860"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20860\/revisions"}],"predecessor-version":[{"id":20861,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20860\/revisions\/20861"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}