{"id":20868,"date":"2026-09-24T08:10:35","date_gmt":"2026-09-24T08:10:35","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20868"},"modified":"2026-09-24T08:10:35","modified_gmt":"2026-09-24T08:10:35","slug":"fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fct-ad-7-4-exam-dumps\"><b>Fortinet FCP_FCT_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 141. Which requirement must be met for FortiClient Anti-Exploit to function?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter must be enabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiSandbox must be reachable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Real-Time Protection must be enabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint must be connected to SSL VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Real-Time Protection must be enabled<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient Anti-Exploit detects suspicious payloads or processes launched from legitimate applications and is intended to defend against exploit techniques, including attacks targeting unpatched or zero-day vulnerabilities. Fortinet specifically states that <\/span><b>Real-Time Protection must be enabled<\/b><span style=\"font-weight: 400;\"> for the Anti-Exploit feature to function. Anti-Exploit complements normal antivirus scanning because it focuses on suspicious application behavior rather than only matching malicious files to known signatures. Administrators who enable Anti-Exploit in an EMS Malware Protection profile but leave Real-Time Protection disabled should therefore expect the exploit-protection function not to operate as intended.<\/span><\/p>\n<p><b>Question 142. What is a key characteristic of FortiClient Anti-Exploit detection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can detect suspicious exploit behavior without relying exclusively on traditional malware signatures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It scans only removable media devices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It works only when a FortiGate performs SSL deep inspection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is designed only to identify missing Windows patches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It can detect suspicious exploit behavior without relying exclusively on traditional malware signatures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient Anti-Exploit is designed to identify exploit behavior targeting legitimate applications such as web browsers and Microsoft Office programs. Fortinet describes it as a signature-less protection mechanism capable of detecting both known and unknown exploit techniques, including memory-based attacks and drive-by downloads. When suspicious exploitation is detected, FortiClient can terminate the compromised application process. This is different from Vulnerability Scan, which identifies software or operating-system vulnerabilities, and from standard antivirus, which primarily evaluates files for malicious content. Anti-Exploit focuses on exploitation behavior occurring through legitimate applications.<\/span><\/p>\n<p><b>Question 143. Which platform limitation applies to FortiClient Anti-Ransomware in the 7.4 documentation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is supported only on Android<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It requires a FortiGate hardware appliance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is available only when Web Filter is disabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is not supported on FortiClient macOS**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It is not supported on FortiClient macOS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents an important platform limitation for the Anti-Ransomware feature: it is not supported on FortiClient macOS. Anti-Ransomware protects selected folders or file types from suspicious modifications and can terminate malicious ransomware behavior, quarantine modified files, and optionally restore files from FortiClient backups. Platform support should always be verified when designing EMS profiles because not every feature available in a Windows-oriented profile is supported identically across macOS, Linux, Android, or other endpoints. Administrators should avoid assuming that centrally configured EMS settings automatically provide identical endpoint functionality on every operating system.<\/span><\/p>\n<p><b>Question 144. What must be enabled for FortiClient Anti-Ransomware to restore files that ransomware encrypted?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSL VPN Auto Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enable File Backup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer Event Upload<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web Filter HTTPS inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Enable File Backup<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient Anti-Ransomware can terminate suspicious ransomware processes and quarantine modified files, but file recovery depends on the <\/span><b>Enable File Backup<\/b><span style=\"font-weight: 400;\"> option. When backup is enabled, FortiClient periodically backs up eligible files in protected locations and can restore those files after ransomware behavior is detected. If backup is disabled, Fortinet states that FortiClient cannot recover the affected files even though it may still detect and stop the ransomware activity. Administrators should therefore distinguish ransomware detection from ransomware recovery. Recovery requires that file backup be enabled and appropriately configured before the attack occurs.<\/span><\/p>\n<p><b>Question 145. What happens when Anti-Ransomware is configured with \u201cMonitor only with Anti-Ransomware detection\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient logs the suspicious activity but does not terminate the process based on that setting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient immediately deletes the endpoint user account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS quarantines the endpoint from the network automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient restores every file regardless of whether backup is enabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FortiClient logs the suspicious activity but does not terminate the process based on that setting<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Anti-Ransomware profile provides several responses to suspicious ransomware behavior. <\/span><b>Monitor only with Anti-Ransomware detection<\/b><span style=\"font-weight: 400;\"> records the detected activity rather than automatically terminating the suspicious process. Other modes can terminate the ransomware behavior immediately or temporarily suspend the process while asking the endpoint user whether the process should be terminated. Monitor-only mode can be useful during evaluation or tuning when administrators want visibility into potential detections before enforcing remediation. However, because suspicious processes are not automatically stopped in monitor-only mode, this setting provides less active protection than termination-based enforcement.<\/span><\/p>\n<p><b>Question 146. What does \u201cBypass Valid Signer\u201d do in an Anti-Ransomware configuration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It blocks every digitally signed application<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It sends all signed applications to FortiSandbox<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can exclude a process from the selected Anti-Ransomware action when it has a valid trusted digital signature<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It disables Anti-Ransomware signature updates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It can exclude a process from the selected Anti-Ransomware action when it has a valid trusted digital signature<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><b>Bypass Valid Signer<\/b><span style=\"font-weight: 400;\"> allows FortiClient to exclude processes from the selected Anti-Ransomware action when the process has a valid digital signature issued by a trusted certificate authority. Fortinet notes that enabling this capability may reduce false positives and speed file analysis. The feature does not mean that all signed software is automatically safe in every security context, but it lets administrators reduce unnecessary Anti-Ransomware intervention for trusted signed applications. As with other exclusions, the setting should be used carefully because overly broad trust decisions can weaken endpoint protection.<\/span><\/p>\n<p><b>Question 147. How does FortiClient Cloud-Based Malware Detection initially check a high-risk file against FortiGuard?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It uploads the complete disk image to FortiGuard<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It generates a SHA1 checksum and queries the FortiGuard checksum library<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It compares only the file name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It sends the endpoint&#8217;s IP address for reputation scoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It generates a SHA1 checksum and queries the FortiGuard checksum library<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a high-risk file is downloaded or executed, FortiClient Cloud-Based Malware Detection calculates a <\/span><b>SHA1 checksum<\/b><span style=\"font-weight: 400;\"> for that file. FortiClient sends the checksum to FortiGuard and checks it against FortiGuard&#8217;s checksum library. If the checksum is identified as malicious, FortiGuard returns that verdict to FortiClient, and the default response is to quarantine the file. This approach reduces the need to transmit every complete file merely to determine whether it matches a known malicious sample. Fortinet limits the feature to high-risk file types such as executable, document, PDF, and DLL files.<\/span><\/p>\n<p><b>Question 148. By default, what does FortiClient do when FortiGuard identifies a file checked by Cloud-Based Malware Detection as malicious?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allows the file permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sends the file to Active Directory<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restarts EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Quarantines the file**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Quarantines the file<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents <\/span><b>Quarantine<\/b><span style=\"font-weight: 400;\"> as the default behavior when Cloud-Based Malware Detection receives a malicious verdict from FortiGuard. The Malware Protection profile can also provide an Alert &amp; Notify option depending on configuration. Cloud-Based Malware Detection is intended to provide additional protection against high-risk files originating from sources such as the internet or network drives. Administrators can configure whether FortiClient should wait for cloud-scan results before allowing access and whether file access should be denied when no cloud verdict is available. These settings let organizations choose between stronger enforcement and greater availability.<\/span><\/p>\n<p><b>Question 149. What is the effect of enabling \u201cDeny Access to File When There is No Cloudscan Result\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient deletes every file not already in the local antivirus database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient disables FortiGuard queries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient denies access to the downloaded file if it cannot obtain a cloud-scan result<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS automatically quarantines the entire endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. FortiClient denies access to the downloaded file if it cannot obtain a cloud-scan result<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Deny Access to File When There is No Cloudscan Result<\/b><span style=\"font-weight: 400;\"> option provides a more restrictive response when FortiClient cannot obtain a verdict from the cloud malware-scanning service. Instead of allowing access simply because no malicious verdict was returned, FortiClient denies access to the file. A missing result may occur when FortiClient cannot reach FortiGuard. This setting can improve security in environments that prefer fail-closed behavior, but administrators should understand that FortiGuard connectivity problems could then affect users&#8217; ability to access legitimate downloaded files.<\/span><\/p>\n<p><b>Question 150. What does \u201cExclude Files from Trusted Sources\u201d do in Cloud-Based Malware Protection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excludes qualifying files signed with a valid certificate issued by a trusted CA from cloud submission<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excludes every file downloaded through HTTPS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excludes all Microsoft Office files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables real-time antivirus protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Excludes qualifying files signed with a valid certificate issued by a trusted CA from cloud submission<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When <\/span><b>Exclude Files from Trusted Sources<\/b><span style=\"font-weight: 400;\"> is enabled, FortiClient can exclude files from Cloud-Based Malware Protection submission when the files are digitally signed with valid certificates issued by trusted certificate authorities. Fortinet notes that this feature can reduce false positives and improve analysis speed. Administrators should nevertheless apply trusted-source exclusions carefully. A broad exclusion can reduce the number of files undergoing cloud analysis, so trust should be based on valid signatures and appropriate enterprise policy rather than simply assuming all downloaded software is harmless.<\/span><\/p>\n<p><b>Question 151. What actions can be configured as the default removable-media access behavior in a FortiClient Malware Protection profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow, Block, or Monitor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Encrypt, Archive, or Delete<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Scan, Route, or Proxy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve, Deny, or Quarantine EMS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Allow, Block, or Monitor<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Removable Media Access section of the Malware Protection profile allows administrators to define what FortiClient should do when removable media does not match a more specific rule. The available default actions are <\/span><b>Allow<\/b><span style=\"font-weight: 400;\">, <\/span><b>Block<\/b><span style=\"font-weight: 400;\">, and <\/span><b>Monitor<\/b><span style=\"font-weight: 400;\">. Allow permits device access, Block prevents access, and Monitor records the device connection without blocking it. On supported Windows endpoints, administrators can also create more granular removable-media rules based on device characteristics. Removable-media controls help organizations reduce the risk of malware introduction and unauthorized data transfer through USB and similar devices.<\/span><\/p>\n<p><b>Question 152. What limitation applies to removable-media access rules on FortiClient macOS and Linux?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They support only per-device serial-number rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They support only the configured default removable-media access action, not the other granular EMS rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They always block every USB device<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They require FortiAnalyzer before they function<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. They support only the configured default removable-media access action, not the other granular EMS rules<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that FortiClient macOS and Linux support only the action configured for <\/span><b>Default removable media access<\/b><span style=\"font-weight: 400;\">. They do not support the more detailed removable-media access rules received from EMS that can be applied on supported Windows endpoints. This is another example of platform differences within the same centrally managed EMS profile. Administrators should review operating-system support before relying on device-specific policies, especially in mixed endpoint environments. A profile may contain granular Windows device rules while macOS and Linux endpoints enforce only the broader default Allow, Block, or Monitor behavior.<\/span><\/p>\n<p><b>Question 153. Why does Fortinet recommend keeping the antivirus exclusion list as short as possible?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A longer exclusion list can negatively affect antivirus performance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS supports only one exclusion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclusions automatically disable FortiClient Telemetry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Large exclusion lists consume VPN licenses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A longer exclusion list can negatively affect antivirus performance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet explicitly advises administrators to keep antivirus exclusion lists as short as possible because longer lists can affect antivirus performance. Each exclusion introduces additional path, file, extension, or wildcard logic that FortiClient must evaluate during scanning. Exclusions also reduce the security coverage of antivirus scanning, so unnecessary entries can introduce both performance and security concerns. Administrators should create exclusions only where applications have a documented compatibility requirement and should periodically review whether old exclusions are still necessary. A focused exclusion list is easier to troubleshoot, audit, and maintain than a large collection of broad wildcard rules.<\/span><\/p>\n<p><b>Question 154. Which statement about FortiClient antivirus exclusion lists is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclusions are never case sensitive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclusions can be used only for file extensions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network shares cannot be excluded<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclusion lists are case-sensitive**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Exclusion lists are case-sensitive<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet notes that Malware Protection antivirus exclusion lists are <\/span><b>case-sensitive<\/b><span style=\"font-weight: 400;\">. Administrators should therefore enter paths, filenames, variables, and patterns with attention to the actual case expected by the endpoint environment. EMS supports several exclusion methods, including fully qualified files and folders, file extensions, wildcards, and supported path variables. Network shares may also be excluded using mapped drive letters or UNC paths. Incorrect case or overly broad wildcard logic can result in an exclusion not matching as expected\u2014or matching more than intended\u2014so exclusions should be tested carefully.<\/span><\/p>\n<p><b>Question 155. Which syntax is valid for excluding all files with the <\/b><b>.jrs<\/b><b> extension from antivirus scanning?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">*.jrs<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">jrs\/*<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">%jrs%<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">all:jrs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. <\/b><b>*.jrs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS supports wildcard syntax in antivirus exclusions. Fortinet gives <\/span><span style=\"font-weight: 400;\">*.jrs<\/span><span style=\"font-weight: 400;\"> as an example for excluding all files with the specified extension. Administrators can also combine wildcards with supported path variables such as <\/span><span style=\"font-weight: 400;\">%systemroot%<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">%userprofile%<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">%appdata%<\/span><span style=\"font-weight: 400;\">, or <\/span><span style=\"font-weight: 400;\">%localappdata%<\/span><span style=\"font-weight: 400;\">. Wildcards are powerful because one exclusion can match many files, but they should be used carefully to avoid creating excessively broad antivirus bypasses. Exclusion patterns should be limited to known application requirements and reviewed when software is upgraded or decommissioned.<\/span><\/p>\n<p><b>Question 156. Which Malware Protection exclusion option affects Real-Time Protection but does not necessarily exclude the same extension from on-demand scanning?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Paths to Excluded Folders<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> File Extensions Excluded from Real-Time Protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Paths to Excluded Files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Default Removable Media Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. File Extensions Excluded from Real-Time Protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS provides separate settings for extensions excluded from <\/span><b>Real-Time Protection<\/b><span style=\"font-weight: 400;\"> and extensions excluded from <\/span><b>On Demand Scanning<\/b><span style=\"font-weight: 400;\">. This separation lets administrators exclude a file type from continuous RTP inspection while still allowing scheduled or manually initiated antivirus scans to inspect that file type, or vice versa. Folder and file path exclusions generally apply more broadly to relevant scanning modes. Understanding the distinction prevents administrators from accidentally assuming that an RTP extension exclusion also removes the same files from all future on-demand scans.<\/span><\/p>\n<p><b>Question 157. What is the main difference between a Quick antivirus scan and a Full antivirus scan in an EMS Malware Protection profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Quick scans only removable media, while Full scans only network drives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Quick scan performs no rootkit detection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full scan works only on macOS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Quick scans currently running executables, DLLs, and drivers, while Full scans the broader system file set in addition to rootkit detection**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Quick scans currently running executables, DLLs, and drivers, while Full scans the broader system file set in addition to rootkit detection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet&#8217;s Malware Protection scheduling options distinguish Quick and Full scans by scope. A <\/span><b>Quick<\/b><span style=\"font-weight: 400;\"> scan runs the rootkit detection engine and examines executable files, DLLs, and drivers that are currently running. A <\/span><b>Full<\/b><span style=\"font-weight: 400;\"> scan also performs rootkit detection but then scans the wider system file set, including files, executables, DLLs, and drivers. Full scans therefore provide more comprehensive coverage but require more endpoint resources and time. Administrators can use scan priority and scheduling to balance protection with the performance impact on end users.<\/span><\/p>\n<p><b>Question 158. When are \u201cScan Removable Media\u201d and \u201cScan Network Drives\u201d available in scheduled Malware Protection scanning?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when Scan Type is Full<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when Scan Type is Quick<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when Anti-Ransomware is disabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when FortiSandbox is unavailable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Only when Scan Type is Full<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents <\/span><b>Scan Removable Media<\/b><span style=\"font-weight: 400;\"> and <\/span><b>Scan Network Drives<\/b><span style=\"font-weight: 400;\"> as options available when the scheduled antivirus <\/span><b>Scan Type is Full<\/b><span style=\"font-weight: 400;\">. A Full scan performs a broader system scan, while a Quick scan focuses on currently running executables, DLLs, and drivers. Scanning connected removable media and network drives can increase the scope and duration of a scheduled scan, so administrators should consider endpoint performance, network load, and the business need for those additional locations. The settings are not general toggles for every scheduled scan type.<\/span><\/p>\n<p><b>Question 159. On FortiClient Android, what limitation applies to Malware Protection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Real-time scanning is not supported because of Android platform restrictions, though scheduled scans can be pushed from EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Malware scanning is completely unsupported<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only FortiSandbox scans are allowed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS cannot configure any Android scan schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Real-time scanning is not supported because of Android platform restrictions, though scheduled scans can be pushed from EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that FortiClient Android does not support real-time malware scanning because of platform-level restrictions. EMS can still push scheduled antivirus scans to Android devices, including Quick and Full scans at configured times. The endpoint displays scan status and history, including the last scan, files scanned, and detected threats. Android also has additional platform limitations; for example, exclusions are not supported in the documented Android malware-scanning workflow. Administrators should therefore avoid assuming that an EMS Malware Protection profile provides identical real-time capabilities across Windows, macOS, Linux, and Android.<\/span><\/p>\n<p><b>Question 160. An organization wants to prevent unauthorized USB use, detect ransomware, block exploit behavior, query FortiGuard for high-risk downloaded files, and keep antivirus exclusions narrowly controlled. Which EMS configuration is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only a Remote Access profile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only a Web Filter profile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Build an appropriately licensed Malware Protection profile with removable-media controls, Anti-Ransomware, Real-Time Protection plus Anti-Exploit, cloud malware detection, and carefully scoped exclusions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure the features only in FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Build an appropriately licensed Malware Protection profile with removable-media controls, Anti-Ransomware, Real-Time Protection plus Anti-Exploit, cloud malware detection, and carefully scoped exclusions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">These endpoint-security requirements belong primarily in the EMS <\/span><b>Malware Protection<\/b><span style=\"font-weight: 400;\"> profile. Removable Media Access controls USB and similar devices. Anti-Ransomware can protect selected folders and file types and optionally restore files when backup is enabled. Anti-Exploit requires Real-Time Protection and monitors legitimate applications for exploit behavior. Cloud-Based Malware Detection checks high-risk files against FortiGuard, while antivirus exclusions let administrators handle known application compatibility needs. Because many of these capabilities are license dependent, the organization must also verify that the installed EMS entitlement supports the required features.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps. Question 141. Which requirement must be met for FortiClient Anti-Exploit to function? Web Filter must be enabled FortiSandbox must be reachable Real-Time Protection must be enabled The endpoint must be connected to SSL VPN Correct Answer: 3. Real-Time Protection must be enabled Explanation: FortiClient Anti-Exploit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20868"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20868"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20868\/revisions"}],"predecessor-version":[{"id":20869,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20868\/revisions\/20869"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}