{"id":20862,"date":"2026-09-24T08:08:47","date_gmt":"2026-09-24T08:08:47","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20862"},"modified":"2026-09-24T08:08:47","modified_gmt":"2026-09-24T08:08:47","slug":"fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fct-ad-7-4-exam-dumps\"><b>Fortinet FCP_FCT_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 81. Which file formats can an administrator upload for an EMS server certificate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TXT, CSV, and XML only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PEM, DER, or PKCS12<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ISO and IMG only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CAB and MSI only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. PEM, DER, or PKCS12<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS supports administrator-uploaded server certificates in PEM, DER, and PKCS12 formats. Server certificates protect HTTPS communications and help administrators present a certificate that endpoints and browsers can trust instead of relying on the built-in default certificate. EMS also supports other certificate sources, including ACME-managed certificates and FortiCare-generated certificates in supported configurations. Selecting the appropriate certificate format and ensuring the complete certificate chain is trusted are important when troubleshooting browser warnings, remote administrator access, or endpoint communication issues involving certificate validation.<\/span><\/p>\n<p><b>Question 82. Which statement about the default FortiClient EMS server certificate is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It must be renewed through Active Directory every 30 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can be deleted after uploading another certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can only be used for FortiAnalyzer connections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS uses it when no other certificate is available, and the administrator cannot delete it**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. EMS uses it when no other certificate is available, and the administrator cannot delete it<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS includes a default server certificate that is available when another suitable certificate has not been configured. Fortinet documents that the default certificate cannot be deleted. Uploaded, ACME, or other supported certificates are generally preferable for production environments because they can provide a certificate chain that clients already trust. When another supported certificate is available, the default certificate is not intended to be selected in the same way as the preferred alternatives. Administrators troubleshooting HTTPS trust problems should review the active EMS server certificate and certificate chain rather than attempting to remove the built-in default certificate.<\/span><\/p>\n<p><b>Question 83. What is the PRIMARY benefit of configuring an ACME certificate on FortiClient EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It allows EMS to use certificates managed automatically through an ACME-compatible certificate authority such as Let&#8217;s Encrypt<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It replaces EMS licensing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It converts endpoint certificates into VPN passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need for DNS resolution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It allows EMS to use certificates managed automatically through an ACME-compatible certificate authority such as Let&#8217;s Encrypt<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS supports certificates obtained and managed through the Automated Certificate Management Environment, or ACME, protocol. Let&#8217;s Encrypt is a well-known public certificate authority using ACME, though other ACME-compatible services can also be used. ACME simplifies certificate lifecycle management by supporting automated issuance and renewal processes. This can reduce the administrative burden associated with manually uploading replacement server certificates when certificates approach expiration. ACME does not replace DNS, licensing, or endpoint authentication requirements; the EMS hostname still needs to resolve correctly and clients still need a valid trust path to the certificate being presented.<\/span><\/p>\n<p><b>Question 84. What is the purpose of an admin role in FortiClient EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign FortiClient licenses to individual endpoints<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine the operating system installed on endpoints<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define which EMS administrative permissions an administrator account receives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To configure FortiGate routing policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To define which EMS administrative permissions an administrator account receives<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS admin roles implement role-based administrative access. A role contains permissions across categories such as endpoints, policies, and settings, and the role is then assigned to administrator accounts. EMS includes several built-in roles and also allows administrators with appropriate privileges to create custom roles. If a role does not permit a particular function, EMS hides or disables the relevant menu items or controls. This allows organizations to separate responsibilities\u2014for example, giving a support technician endpoint-management permissions without granting full authority over server settings or administrator accounts.<\/span><\/p>\n<p><b>Question 85. Which built-in EMS admin role is the only built-in role with access to the Administration section of the GUI?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Read-only administrator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint administrator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Standard administrator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Super administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Super administrator<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Super administrator is the most privileged built-in EMS role. Fortinet documents that it has complete access to EMS permissions and is the only built-in role with access to the Administration section of the GUI. It can work with configured Windows and LDAP users and manage user privileges and permissions. The default <\/span><span style=\"font-weight: 400;\">admin<\/span><span style=\"font-weight: 400;\"> account is a Super administrator and cannot be assigned a different admin role. Because of the role&#8217;s broad authority, organizations should restrict Super administrator access to personnel who genuinely require full EMS administrative control.<\/span><\/p>\n<p><b>Question 86. What permissions does the built-in Standard administrator role normally have?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> All endpoint and policy permissions, with read-only access to settings permissions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No permissions unless individually enabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Read-only endpoint permissions only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full access to the Administration section and user-role configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. All endpoint and policy permissions, with read-only access to settings permissions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Standard administrator built-in role provides broad endpoint and policy administration capabilities but limits settings permissions to read-only access. This makes it suitable for administrators who need to manage FortiClient endpoints and policies without receiving the highest level of control over EMS system configuration and administrator management. The role differs from the Super administrator, which has complete permissions and Administration access, and from the Endpoint administrator, which has full endpoint permissions but more restricted policy and settings access. Understanding the default role differences is important when implementing least-privilege EMS administration.<\/span><\/p>\n<p><b>Question 87. What permissions characterize the built-in Endpoint administrator role?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full access to all EMS settings and admin accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All endpoint permissions, with read-only permissions for policy and settings areas<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No endpoint permissions but full policy permissions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only permission to view EMS licenses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. All endpoint permissions, with read-only permissions for policy and settings areas<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Endpoint administrator role is intended for administrators whose responsibilities center on managed endpoints. It includes all endpoint permissions while providing read-only access to policy and settings permissions. This enables operational tasks on endpoints while limiting broader configuration changes. EMS&#8217;s permission reference further divides permissions into specific capabilities, such as running endpoint commands, managing groups, viewing or managing profiles, and quarantining endpoints. A custom admin role can provide even finer separation when the built-in role grants more capability than a particular support team should have.<\/span><\/p>\n<p><b>Question 88. What is true of the built-in Restricted administrator role?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It has full endpoint permissions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can edit profiles but not policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It has no permissions enabled by default<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It automatically becomes a Super administrator after login<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It has no permissions enabled by default<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The built-in Restricted administrator role has no permissions enabled. It can serve as a highly constrained starting point where the organization does not want an account to receive operational access through one of the broader predefined roles. EMS hides or disables functions that an administrator&#8217;s role does not permit. Organizations that require a very specific permission combination can also create custom roles rather than relying solely on the predefined ones. Role selection should follow the principle of least privilege so administrator accounts receive only the endpoint, policy, and settings capabilities needed for their assigned duties.<\/span><\/p>\n<p><b>Question 89. An administrator wants to create an EMS admin account based on an existing Active Directory user. What must be true first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user must already exist in an AD domain configured in EMS as an LDAP authentication source<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer must create the account first<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user must have a FortiGate local account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS must create the Active Directory account automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The user must already exist in an AD domain configured in EMS as an LDAP authentication source<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS can create administrator access based on LDAP users, but those users must already exist in the Active Directory domain configured as an authentication server. EMS derives the available LDAP-user list from imported or configured directory information; it does not create new Active Directory accounts itself. Administrators go to <\/span><b>Administration &gt; Admin Users<\/b><span style=\"font-weight: 400;\">, choose LDAP as the user source, select the configured authentication server, and assign appropriate EMS permissions or roles. This allows organizations to integrate EMS administrative access with existing enterprise identity management while still controlling authorization through EMS roles.<\/span><\/p>\n<p><b>Question 90. Why does Fortinet recommend using an FQDN rather than only an IP address for FortiClient-to-EMS connectivity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An FQDN disables certificate validation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An FQDN makes EMS licensing unnecessary<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An FQDN prevents endpoints from leaving the corporate network<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It simplifies EMS IP changes, migration to another EMS instance, and internal\/external DNS resolution**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It simplifies EMS IP changes, migration to another EMS instance, and internal\/external DNS resolution<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet recommends an EMS FQDN because it provides flexibility unavailable when endpoints are tied directly to a single IP address. DNS can resolve the same EMS hostname to an internal address for devices inside the corporate network and to an external address for remote endpoints. The FQDN also makes future EMS migration or IP-address changes easier because DNS can be updated without reconfiguring every endpoint. This is especially valuable for mobile users who move between internal and external networks while maintaining their FortiClient Telemetry connection to EMS.<\/span><\/p>\n<p><b>Question 91. When external FortiClient endpoints use the EMS FQDN from outside the corporate network, what port does Fortinet documentation specifically describe forwarding to the internal EMS address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 22<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 443 only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 8013<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> UDP 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. TCP 8013<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet&#8217;s post-installation guidance describes an internal\/external DNS design in which the same EMS FQDN can resolve differently depending on endpoint location. For external clients, the organization&#8217;s externally reachable address should forward traffic received on port 8013 to the internal EMS address so FortiClient can maintain the required management connection. The exact deployment should still follow the complete EMS ports and services documentation and organizational firewall design. For exam purposes, port 8013 is important because it is commonly associated with FortiClient Telemetry communication to EMS.<\/span><\/p>\n<p><b>Question 92. Which EMS migration path is correct for moving directly to FortiClient EMS 7.4.0 from the earlier Windows-based EMS generation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any EMS 6.x version can migrate directly to 7.4.0<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Migrate from EMS 7.2.4; earlier releases must first be upgraded to 7.2.4<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only EMS 7.2.5 can migrate to 7.4.0<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No migration path from Windows EMS exists<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Migrate from EMS 7.2.4; earlier releases must first be upgraded to 7.2.4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For the original EMS 7.4.0 migration, Fortinet specifies EMS 7.2.4 as the supported source release. Environments on an earlier EMS version must first follow the supported upgrade path to 7.2.4 and then migrate from the Windows Server architecture to the Linux-based EMS 7.4.0 architecture. This is not a conventional in-place upgrade from arbitrary older releases. The migration architecture changed significantly with EMS 7.4, making the supported source version and migration procedure important operational details. Administrators should always consult the FortiClient upgrade path before production migration.<\/span><\/p>\n<p><b>Question 93. Why can EMS 7.2.5 not be migrated directly to EMS 7.4.0?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS 7.2.5 uses a MySQL database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS 7.2.5 supports only macOS endpoints<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS 7.2.5 cannot store endpoint policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS 7.2.5 was released after EMS 7.4.0 and is not a supported 7.4.0 migration source**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. EMS 7.2.5 was released after EMS 7.4.0 and is not a supported 7.4.0 migration source<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet explicitly notes that EMS 7.2.5 cannot migrate to EMS 7.4.0 because 7.2.5 was released after 7.4.0. For the EMS 7.4.0 migration workflow, 7.2.4 is the supported source release. This example illustrates why administrators should not assume that a numerically newer patch in an older branch is automatically a valid migration source for every newer major branch release. Supported upgrade and migration paths are release specific. Before maintenance, administrators should verify the Fortinet upgrade path and release-specific migration documentation rather than relying only on version-number comparisons.<\/span><\/p>\n<p><b>Question 94. What should an administrator do before any EMS version upgrade or other major maintenance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all endpoint policies permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Back up the EMS database and consider a full server backup or VM snapshot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete old FortiClient installers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke every server certificate<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Back up the EMS database and consider a full server backup or VM snapshot<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet strongly recommends backing up the EMS database before upgrades or other maintenance. The documentation also suggests considering a full server backup or VM snapshot where possible. This provides a recovery path if the maintenance operation fails or produces unexpected results. An EMS database contains critical management configuration and state, so performing disruptive maintenance without a backup creates avoidable operational risk. Backup planning should be part of the maintenance procedure itself rather than an afterthought triggered only after a failed upgrade. Administrators should also verify backup integrity and know the applicable restoration procedure.<\/span><\/p>\n<p><b>Question 95. What HA operating mode does FortiClient EMS support for the EMS application nodes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active-passive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active-active only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Round-robin active-active only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anycast only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Active-passive<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS application high availability uses an active-passive architecture. Two or more EMS nodes connect to a common database or supported PostgreSQL database cluster. The first EMS node installed acts as the primary, while additional nodes join as secondary nodes ready to assume the active role during failover. This provides redundancy at the EMS application layer. Database HA can also be designed separately through a PostgreSQL cluster. Administrators should distinguish application-node redundancy from database redundancy because a highly available EMS design may need to address both layers to eliminate single points of failure.<\/span><\/p>\n<p><b>Question 96. What database relationship is required among EMS application nodes in an HA cluster?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every EMS node must use a completely separate unrelated database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Secondary nodes store configuration only in local files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Two or more EMS nodes connect to the same database or supported PostgreSQL database cluster<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS HA requires Microsoft SQL Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Two or more EMS nodes connect to the same database or supported PostgreSQL database cluster<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In FortiClient EMS application HA, the EMS nodes share the database layer. Two or more EMS nodes connect to the same standalone PostgreSQL server or to a supported list of PostgreSQL nodes forming a database cluster. Each EMS node registers itself in the shared database and retrieves its configuration from that common data source. This shared configuration allows a secondary EMS node to take over the active application role during failover. For full resilience, organizations may also deploy PostgreSQL database HA rather than leaving one standalone database as a remaining point of failure.<\/span><\/p>\n<p><b>Question 97. In a documented EMS HA georedundancy test, how can an administrator simulate failure of the primary EMS application node?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the EMS database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke the FortiClient license<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stop DNS service on every endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stop the FortiClient Endpoint Management Server Monitor Service on the primary node and verify secondary takeover**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Stop the FortiClient Endpoint Management Server Monitor Service on the primary node and verify secondary takeover<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet&#8217;s HA georedundancy validation procedure recommends simulating application-node failure by stopping the FortiClient Endpoint Management Server Monitor Service on the primary node. Administrators should then verify that a secondary node becomes the EMS primary and confirm that FortiClient can still register successfully through the shared FQDN. This controlled failover test validates not only EMS node state but also DNS, network access, database availability, and endpoint connectivity. Fortinet recommends performing georedundancy and failover testing with a test endpoint before placing the design into full production service.<\/span><\/p>\n<p><b>Question 98. What is the purpose of the EMS High Availability Keep Alive Interval setting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It controls the interval used by the HA mechanism to monitor node availability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It controls FortiClient antivirus signature age<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It defines the user&#8217;s EMS login timeout<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It sets the Web Filter schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It controls the interval used by the HA mechanism to monitor node availability<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The High Availability Keep Alive Interval is part of EMS HA configuration and controls timing associated with node-health monitoring in the HA environment. HA systems must detect when the active EMS node is no longer available so that a secondary can assume the primary role. Administrators can configure the interval from the EMS settings in supported HA deployments. The parameter is unrelated to endpoint antivirus signatures, user login sessions, or Web Filter schedules. HA timing should be selected with care because failover responsiveness and infrastructure stability both depend on appropriate health-monitoring behavior.<\/span><\/p>\n<p><b>Question 99. Which certificate can EMS revoke and update when administrators suspect that the certificate used for ZTNA trust has been compromised?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the endpoint&#8217;s Windows logon certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only an Active Directory domain-controller certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The EMS CA certificate used for ZTNA, which EMS can replace and propagate to FortiOS and FortiClient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the FortiAnalyzer server certificate<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The EMS CA certificate used for ZTNA, which EMS can replace and propagate to FortiOS and FortiClient<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS maintains a CA certificate used in supported ZTNA workflows. The EMS settings display its expiration information and provide a <\/span><b>Revoke and Update<\/b><span style=\"font-weight: 400;\"> action. Fortinet notes that administrators may use this option when the certificate is compromised and can no longer be trusted. EMS then works with FortiOS and FortiClient to establish updated certificate information. Replacing a trust certificate can affect existing connections, so administrators should treat revocation as a controlled security operation rather than routine maintenance. The feature requires the appropriate FortiClient ZTNA or EPP licensing.<\/span><\/p>\n<p><b>Question 100. A company is moving from EMS 7.2.4 on Windows Server to EMS 7.4.0, wants resilient remote endpoint connectivity, and requires administrative separation of duties. Which approach BEST meets these requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perform an unsupported in-place Windows upgrade and give every administrator the default admin account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep endpoints permanently configured with the old EMS IP and use one shared Super administrator account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Migrate using the supported 7.2.4-to-7.4.0 Linux workflow, use an EMS FQDN for endpoint connectivity, back up before maintenance, and assign administrators least-privilege EMS roles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable certificates and HA so migration is simpler<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Migrate using the supported 7.2.4-to-7.4.0 Linux workflow, use an EMS FQDN for endpoint connectivity, back up before maintenance, and assign administrators least-privilege EMS roles<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A reliable EMS migration combines several Fortinet best practices. EMS 7.4.0 uses a Linux architecture and supports migration from EMS 7.2.4 through the documented workflow rather than an arbitrary in-place Windows upgrade. Fortinet recommends backing up before maintenance. Using an FQDN makes endpoint connectivity more resilient to IP changes and server migration, particularly for devices that move between internal and external networks. Finally, EMS role-based administration allows organizations to avoid sharing the highly privileged default administrator account and instead assign endpoint, policy, or settings permissions according to job responsibilities.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps. Question 81. Which file formats can an administrator upload for an EMS server certificate? TXT, CSV, and XML only PEM, DER, or PKCS12 ISO and IMG only CAB and MSI only Correct Answer: 2. PEM, DER, or PKCS12 Explanation: FortiClient EMS supports administrator-uploaded server certificates [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20862"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20862"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20862\/revisions"}],"predecessor-version":[{"id":20863,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20862\/revisions\/20863"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}