{"id":20884,"date":"2026-09-24T08:12:35","date_gmt":"2026-09-24T08:12:35","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20884"},"modified":"2026-09-24T08:12:35","modified_gmt":"2026-09-24T08:12:35","slug":"fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fct-ad-7-4-exam-dumps\"><b>Fortinet FCP_FCT_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 301. In a FortiClient EMS Vulnerability Scan profile, what does selecting Patch Level = High mean?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Patch only low-severity vulnerabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically patch high-severity and critical vulnerabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Patch only informational findings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable automatic patching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Automatically patch high-severity and critical vulnerabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Automatic Patching section of the Vulnerability Scan profile lets an administrator choose the minimum severity level that FortiClient should patch automatically. Selecting <\/span><b>High<\/b><span style=\"font-weight: 400;\"> causes FortiClient to patch vulnerabilities rated High as well as more severe Critical vulnerabilities. Other choices include Critical, Medium, Low, and All. Choosing a broader patch level increases automatic remediation coverage but can also create more endpoint changes. Administrators should select the level that matches organizational risk tolerance, testing requirements, and software-change procedures.<\/span><\/p>\n<p><b>Question 302. What operational effect can FortiClient automatic vulnerability patching have on an endpoint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It disables EMS Telemetry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It always logs the user off but never reboots<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It automatically changes the endpoint&#8217;s IP address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It may require the endpoint to reboot**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It may require the endpoint to reboot<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet warns that automatic vulnerability patching can require an endpoint reboot. This is important when administrators enable remediation of Critical, High, Medium, Low, or all detected vulnerabilities through EMS. Although automatic patching improves security by reducing exposure time, it can affect user productivity if applications or operating-system components require restart. Organizations should therefore combine patching settings with appropriate user communication, maintenance planning, and testing. A reboot requirement is a possible consequence of patch installation rather than evidence that the patching process malfunctioned.<\/span><\/p>\n<p><b>Question 303. What happens when \u201cExempt Application Vulnerabilities Requiring Manual Update from Vulnerability Compliance Check\u201d is enabled?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Applications requiring manual updates are excluded from compliance evaluation but are still scanned for vulnerabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Those applications are deleted automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Vulnerability scanning is disabled completely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS removes the applications from Software Inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Applications requiring manual updates are excluded from compliance evaluation but are still scanned for vulnerabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">This exclusion setting affects <\/span><b>compliance<\/b><span style=\"font-weight: 400;\">, not vulnerability detection. Applications that require the endpoint user to patch them manually can be exempted from the vulnerability compliance check so they do not cause the endpoint to become noncompliant simply because automatic remediation is unavailable. Fortinet explicitly states that the applications remain subject to vulnerability scanning. This distinction is important: excluding something from the compliance decision does not mean EMS stops detecting or reporting its vulnerabilities. Administrators can therefore preserve visibility while avoiding inappropriate compliance penalties.<\/span><\/p>\n<p><b>Question 304. What is true when an administrator places an application in \u201cExclude Selected Applications from Vulnerability Compliance Check\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient stops detecting the application<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS uninstalls the application<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The application remains subject to vulnerability scanning but is exempt from the configured compliance requirement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The application is removed from all FortiGate policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The application remains subject to vulnerability scanning but is exempt from the configured compliance requirement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The selected-application exclusion controls whether a vulnerable application affects endpoint compliance. Fortinet documents that applications placed on this list remain visible to vulnerability scanning; they are simply exempted from needing to install software patches within the compliance timeframe defined by FortiGate rules. This can be useful for business-critical software that cannot be upgraded immediately. Administrators should avoid treating the exclusion as a vulnerability-scanning bypass because the vulnerability continues to exist and should still be assessed and remediated when operationally feasible.<\/span><\/p>\n<p><b>Question 305. What does \u201cDisable Automatic Patching for These Applications\u201d do when used with vulnerability-compliance exclusions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables all FortiClient scanning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Makes the endpoint permanently compliant<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes vulnerability signatures for those applications<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevents FortiClient from automatically patching the excluded applications**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Prevents FortiClient from automatically patching the excluded applications<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After selected applications have been excluded from the vulnerability compliance check, EMS also provides an option to <\/span><b>Disable Automatic Patching for These Applications<\/b><span style=\"font-weight: 400;\">. This lets administrators separate compliance and remediation behavior. For example, an application can remain visible as vulnerable, be excluded from causing a compliance failure, and also be prevented from receiving an automatic update that could disrupt a critical workflow. Such exclusions should be carefully documented because they intentionally leave identified vulnerabilities unresolved until another remediation process addresses them.<\/span><\/p>\n<p><b>Question 306. When does the \u201cScan On\u201d day selection apply in a scheduled Vulnerability Scan profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> When the schedule type is Weekly or Monthly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when Scan on Registration is enabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only for manually started scans<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when Automatic Patching is disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. When the schedule type is Weekly or Monthly<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Scan On<\/b><span style=\"font-weight: 400;\"> field is relevant when Vulnerability Scan scheduling uses a Weekly or Monthly schedule. An administrator can select the appropriate day of the week or day of the month and define the scan&#8217;s start time. This provides predictable recurring vulnerability assessment without relying entirely on manual scans. It is separate from other scan triggers such as Scan on Registration or Scan on Vulnerability Signature Update. Administrators should understand which trigger caused a scan when analyzing endpoint activity or scheduling resource-intensive vulnerability checks.<\/span><\/p>\n<p><b>Question 307. Which type of information appears as an AV event in the FortiClient Notifications tab?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only VPN tunnel establishment messages<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only software-inventory changes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Scheduled antivirus scans and detected malware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only EMS licensing alerts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Scheduled antivirus scans and detected malware<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FortiClient <\/span><b>Notifications<\/b><span style=\"font-weight: 400;\"> tab provides user-visible information about endpoint events. Fortinet lists antivirus events such as scheduled AV scans and malware detections among the supported notification types. Other categories include Sandbox Detection, Telemetry, Web Filter, and system events. The Notifications tab therefore serves as a useful local endpoint view when troubleshooting whether a security action occurred. It is different from the EMS server&#8217;s centralized event and alert interfaces, which aggregate management information across many endpoints.<\/span><\/p>\n<p><b>Question 308. What can a FortiClient user view by selecting \u201cThreat Detected\u201d in the Notifications area?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS database backups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Quarantined files, site violations, and Real-Time Protection events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGate routing entries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active Directory password changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Quarantined files, site violations, and Real-Time Protection events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that selecting <\/span><b>Threat Detected<\/b><span style=\"font-weight: 400;\"> in FortiClient allows the user to view information including quarantined files, site violations, and Real-Time Protection events. This gives the endpoint user or support technician a local view of security incidents affecting that device. It can be useful when investigating why a file disappeared, why access to a site was denied, or whether RTP detected malicious content. These endpoint notifications complement, rather than replace, centralized EMS or FortiAnalyzer logging used by administrators.<\/span><\/p>\n<p><b>Question 309. Which event is categorized as a Telemetry notification in FortiClient?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configuration updates received from EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGate hardware failure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PostgreSQL replication events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active Directory schema modifications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Configuration updates received from EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient Telemetry notifications include events such as configuration updates received from EMS. This gives the endpoint a visible indication that centralized management has supplied new settings. Because endpoint policies and profiles are delivered through the EMS management relationship, these notifications can help confirm that FortiClient received updated configuration. If EMS shows a policy change but FortiClient never indicates a configuration update, administrators should check endpoint status, Telemetry connectivity, policy applicability, and the timing of the endpoint&#8217;s latest communication with EMS.<\/span><\/p>\n<p><b>Question 310. Which events are examples of FortiClient System notifications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only blocked YouTube videos<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only LDAP authentication failures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only endpoint quarantine actions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Signature and engine updates and software upgrades**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Signature and engine updates and software upgrades<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FortiClient Notifications tab categorizes signature updates, engine updates, and software upgrades as <\/span><b>System events<\/b><span style=\"font-weight: 400;\">. These are distinct from antivirus detections, Web Filter blocks, or Telemetry configuration updates. System notifications can help administrators and users determine whether endpoint security engines and definitions were updated successfully or whether a FortiClient software upgrade occurred. Understanding the notification category can speed troubleshooting because it indicates which FortiClient subsystem generated the event and where administrators should investigate next.<\/span><\/p>\n<p><b>Question 311. What must a custom XML configuration file used for an EMS endpoint profile contain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only settings changed from default<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All configuration settings required by the endpoint at deployment time<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only VPN-related settings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only FortiGuard connection settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. All configuration settings required by the endpoint at deployment time<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet allows administrators to configure an endpoint profile through XML, but a custom XML file must contain <\/span><b>all settings required by the endpoint at the time of deployment<\/b><span style=\"font-weight: 400;\">. Administrators should not assume EMS will automatically reconstruct missing required settings from an incomplete custom file. XML configuration offers flexibility for advanced settings not easily exposed through standard GUI controls, but it also requires careful configuration management. The FortiClient XML Reference should be used to ensure valid elements and supported values are supplied.<\/span><\/p>\n<p><b>Question 312. How does an EMS administrator expose the XML Configuration tab while editing an endpoint profile?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> By enabling Advanced mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> By disabling the endpoint policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> By opening FortiAnalyzer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> By turning off Feature Select<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. By enabling Advanced mode<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When creating or editing an EMS endpoint profile, the administrator can select <\/span><b>Advanced<\/b><span style=\"font-weight: 400;\"> to display the XML Configuration tab. The profile&#8217;s configuration can then be viewed and edited as XML. This provides access to configuration elements that may not be available through normal GUI controls. Because XML errors can affect endpoint configuration, administrators should use the FortiClient XML Reference and validation features rather than making unsupported changes blindly. Advanced XML editing is a supplement to standard EMS profiles, not a replacement for careful profile design.<\/span><\/p>\n<p><b>Question 313. Which action should an administrator perform after manually editing XML in an EMS endpoint profile and before relying on it in production?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete all other profiles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reboot FortiGate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable EMS licensing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use Test XML to validate the edited configuration**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use Test XML to validate the edited configuration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet includes a <\/span><b>Test XML<\/b><span style=\"font-weight: 400;\"> function in the endpoint-profile XML editing workflow. After editing XML, the administrator should validate the configuration before saving and deploying it. This helps identify syntax or structure problems that could otherwise prevent FortiClient from applying the intended configuration correctly. XML profiles can contain advanced settings and therefore offer considerable flexibility, but that flexibility also increases the risk of manual errors. Validation should be treated as a standard part of any XML-based profile change process.<\/span><\/p>\n<p><b>Question 314. When an EMS administrator exports an endpoint profile, what is included in the export?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the profile name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All configured profile components represented in XML<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only Remote Access settings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only licensing information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. All configured profile components represented in XML<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet allows endpoint profiles to be exported from EMS. The export contains <\/span><b>all configured components<\/b><span style=\"font-weight: 400;\"> of the profile in XML form. This is useful for configuration review, troubleshooting, documentation, or transferring profile configuration through supported workflows. Because the exported representation includes the complete profile configuration, administrators should protect these files appropriately, particularly if they contain sensitive connection information. Exporting a profile is different from exporting logs or backing up the EMS database; it is specifically a configuration-level representation of the profile.<\/span><\/p>\n<p><b>Question 315. What default filename does the browser use when downloading an exported EMS profile XML configuration?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">profile.conf<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">forticlient.msi<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">ems.xml.zip<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">policy.db<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. <\/b><b>profile.conf<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that when an administrator exports an endpoint profile, the browser downloads the configuration as a file named <\/span><b>profile.conf<\/b><span style=\"font-weight: 400;\">. Fortinet recommends renaming the file to reflect the actual profile name, which makes stored exports easier to identify and manage. The file contains the profile&#8217;s XML configuration and should not be confused with a FortiClient deployment installer or an EMS database backup. Clear naming is especially valuable in environments where administrators maintain exports of multiple production, test, on-fabric, and off-fabric profiles.<\/span><\/p>\n<p><b>Question 316. What does the \u201cDownload Profile XML\u201d function in an endpoint policy provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One XML file containing the configuration of the selected endpoint profiles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A FortiClient installer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A FortiGate configuration backup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A list of EMS administrator accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. One XML file containing the configuration of the selected endpoint profiles<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">While editing an endpoint policy, EMS provides a <\/span><b>Download Profile XML<\/b><span style=\"font-weight: 400;\"> function. Fortinet states that this produces one XML file containing the configuration for the endpoint profiles selected in that policy. This is useful when administrators need to review the effective configuration components associated with the policy rather than exporting each profile separately. It can also support troubleshooting by showing which profile settings are intended for endpoints governed by that policy. The downloaded XML is configuration data, not an installer or a database backup.<\/span><\/p>\n<p><b>Question 317. If an endpoint policy includes a separate Off-Fabric profile configuration, what additional XML export option is available?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Off-Fabric Profile XML<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGuard Database XML<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer Report XML<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ZTNA Certificate XML<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Off-Fabric Profile XML<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When <\/span><b>Profile (Off-Fabric)<\/b><span style=\"font-weight: 400;\"> is enabled in an endpoint policy, EMS provides a separate <\/span><b>Off-Fabric Profile XML<\/b><span style=\"font-weight: 400;\"> download option. The resulting file contains the configuration of the profiles selected specifically for endpoints classified as off-fabric. This is useful when comparing normal on-fabric and remote endpoint configurations or troubleshooting why security behavior changes when a laptop leaves the corporate network. Because on-fabric and off-fabric profile sets can differ substantially, separate XML exports make it easier to verify exactly what EMS intends to apply in each network context.<\/span><\/p>\n<p><b>Question 318. What is the primary source of FortiGuard Outbreak Alert rules in FortiClient EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGuard provides predefined outbreak rules to EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint users create them locally<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer generates every outbreak rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active Directory creates them from group policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FortiGuard provides predefined outbreak rules to EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGuard Outbreak Alerts provide predefined rules designed to help organizations respond quickly to emerging threats. For example, if FortiGuard Labs identifies a new zero-day vulnerability in a widely installed application, Fortinet can create an outbreak alert rule that identifies endpoints with the vulnerable application. EMS receives the rule and can tag affected endpoints dynamically. This gives administrators rapid visibility without requiring them to manually design a posture rule for every newly disclosed threat. The resulting tags can also participate in FortiOS dynamic policy enforcement.<\/span><\/p>\n<p><b>Question 319. What administrative control does EMS provide over FortiGuard Outbreak Alert rules?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrators can rewrite every FortiGuard rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrators can delete FortiGuard rules permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrators can only enable or disable the predefined rules; they cannot modify or delete them<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrators can convert them into Installer IDs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Administrators can only enable or disable the predefined rules; they cannot modify or delete them<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGuard Outbreak Alert rules are controlled by FortiGuard rather than created locally by the EMS administrator. Fortinet explicitly states that administrators <\/span><b>cannot modify or delete<\/b><span style=\"font-weight: 400;\"> these predefined rules. They can, however, enable or disable individual outbreak rules in the relevant EMS interface. This preserves the integrity of Fortinet-provided threat logic while still allowing organizations to control whether a particular outbreak rule is active in their environment. Administrators needing custom endpoint criteria should create their own security posture tagging rules instead.<\/span><\/p>\n<p><b>Question 320. A newly disclosed zero-day affects a popular application. The organization wants to identify vulnerable endpoints automatically and restrict their network access without manually creating a new endpoint group. Which approach BEST meets the requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create one static IP object for every endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Wait for users to report the vulnerable application<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only Software Inventory and make all access changes manually<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enable the relevant FortiGuard Outbreak Alert rule so EMS dynamically tags affected endpoints and use those dynamic tags in FortiOS policy**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Enable the relevant FortiGuard Outbreak Alert rule so EMS dynamically tags affected endpoints and use those dynamic tags in FortiOS policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiGuard Outbreak Alert rules are designed specifically for rapidly emerging threats. FortiGuard can provide a predefined rule identifying endpoints affected by a newly discovered vulnerability. EMS receives the rule, dynamically tags matching endpoints, and makes those tags visible in the Tag Monitor. Like security posture tags, outbreak tags can be shared with FortiOS, where dynamic policy rules can restrict access for the affected endpoint population. This approach avoids manually creating or maintaining static device groups whenever a new outbreak appears and enables much faster containment of vulnerable systems.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps. Question 301. In a FortiClient EMS Vulnerability Scan profile, what does selecting Patch Level = High mean? Patch only low-severity vulnerabilities Automatically patch high-severity and critical vulnerabilities Patch only informational findings Disable automatic patching Correct Answer: 2. Automatically patch high-severity and critical vulnerabilities Explanation: The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20884"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20884"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20884\/revisions"}],"predecessor-version":[{"id":20885,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20884\/revisions\/20885"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}