{"id":20890,"date":"2026-09-24T08:13:17","date_gmt":"2026-09-24T08:13:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20890"},"modified":"2026-09-24T08:13:17","modified_gmt":"2026-09-24T08:13:17","slug":"fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fct-ad-7-4-exam-dumps\"><b>Fortinet FCP_FCT_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 361. What is the default number of unsuccessful administrator login attempts before FortiClient EMS locks the administrator account temporarily?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One attempt<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Five attempts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Three attempts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ten attempts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Three attempts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS includes an administrator lockout mechanism designed to reduce the risk of repeated password-guessing attempts against the management interface. The <\/span><b>Admin Lockout Attempt<\/b><span style=\"font-weight: 400;\"> setting specifies how many unsuccessful login attempts are allowed before EMS temporarily locks the administrator. Fortinet documents the default value as three attempts, while the setting can be increased up to the supported maximum. Administrators should combine account lockout with strong credentials, role-based permissions, secure HTTPS access, and appropriate session controls. A lockout is temporary and is governed separately by the configured Admin Lockout Period.<\/span><\/p>\n<p><b>Question 362. What is the maximum value that can be configured for Admin Lockout Attempt in EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 10 attempts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 20 attempts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 50 attempts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unlimited attempts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. 10 attempts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS allows administrators to customize how many failed sign-in attempts trigger temporary account lockout. Fortinet documents a maximum value of <\/span><b>10 unsuccessful attempts<\/b><span style=\"font-weight: 400;\">. Increasing the threshold can reduce accidental lockouts caused by mistyped passwords, while a lower value provides stronger resistance to repeated guessing attempts. The setting should be selected according to organizational security policy. Administrators should also understand that the lockout threshold operates together with the Admin Lockout Period, which determines how long the administrator remains unable to sign in after reaching the configured failure threshold.<\/span><\/p>\n<p><b>Question 363. What happens if an administrator attempts to log in during an active EMS Admin Lockout Period using the correct password?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The login succeeds because the password is correct<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS immediately disables the account permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS changes the administrator password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The login still fails, and the lockout period restarts**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The login still fails, and the lockout period restarts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">During the configured EMS administrator lockout period, login attempts do not succeed even when the administrator provides the correct credentials. Fortinet further documents that each login attempt made during the lockout period causes that period to reset and begin again. Administrators should therefore avoid repeatedly retrying credentials while an account is known to be locked because doing so can prolong the lockout. Once the configured lockout time passes without further login attempts, EMS resets the temporary lockout and permits the administrator to attempt authentication again.<\/span><\/p>\n<p><b>Question 364. What happens after the configured EMS Admin Lockout Period expires?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The administrator must reinstall EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The temporary lockout resets and the administrator can attempt to log in again<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The account is permanently deleted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS automatically grants Super administrator privileges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The temporary lockout resets and the administrator can attempt to log in again<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS administrator lockout is intended to be temporary. After the configured <\/span><b>Admin Lockout Period<\/b><span style=\"font-weight: 400;\"> expires, the lockout resets and the administrator can attempt to sign in again. If the administrator subsequently reaches the configured failed-attempt threshold again, another lockout period begins. This behavior allows EMS to slow repeated guessing attacks without permanently removing the account. Administrators should distinguish this temporary failed-login lockout from other account controls, such as automatically disabling administrator accounts after a configured number of inactive days.<\/span><\/p>\n<p><b>Question 365. What does \u201cExpire login session after x minutes\u201d control in EMS Admin User Settings?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> How long an inactive EMS administrator session can remain logged in before automatic logout<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> How long FortiClient VPN sessions stay connected<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> How long antivirus signatures remain valid<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> How long an endpoint remains quarantined<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. How long an inactive EMS administrator session can remain logged in before automatic logout<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Expire login session after x minutes<\/b><span style=\"font-weight: 400;\"> setting controls administrator web-session inactivity. If an EMS administrator remains inactive for longer than the configured number of minutes, EMS automatically logs that user out. This helps reduce the risk of an unattended management session remaining accessible indefinitely. Fortinet also permits a value of zero, which keeps inactive users logged in indefinitely. In security-sensitive environments, administrators generally use a finite timeout appropriate to their operational requirements. This setting affects the EMS administrator interface, not FortiClient VPN sessions, endpoint Telemetry, or antivirus functionality.<\/span><\/p>\n<p><b>Question 366. What does configuring the EMS administrator session inactivity timeout to 0 do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Immediately logs out all administrators<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables all administrator accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keeps inactive administrator sessions logged in indefinitely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Forces password changes at every login<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Keeps inactive administrator sessions logged in indefinitely<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that entering <\/span><b>0<\/b><span style=\"font-weight: 400;\"> for the administrator login-session inactivity timeout disables automatic inactivity logout. As a result, inactive EMS administrator sessions remain logged in indefinitely unless the user explicitly signs out or the session ends for another reason. While this can be convenient in certain controlled environments, it creates additional security risk if an administrator leaves a browser session unattended. Organizations should select a timeout that balances usability with protection of the EMS management interface and should consider workstation locking and privileged-access policies as complementary controls.<\/span><\/p>\n<p><b>Question 367. What does the \u201cDisable administrators&#8217; accounts when inactive for x days\u201d setting do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes inactive administrator accounts permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables an administrator account after the configured period without login activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changes inactive administrators to endpoint users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revokes the EMS server certificate<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Disables an administrator account after the configured period without login activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS can automatically disable administrator accounts that have not been used for a specified number of days. For example, if the setting is configured for 10 days and an administrator does not log in during that period, EMS disables the account so it cannot authenticate. This helps reduce the risk created by dormant privileged accounts that remain enabled indefinitely. Fortinet documents that a Super administrator can reactivate such a disabled account. This control is different from temporary failed-login lockout because it is based on prolonged inactivity rather than repeated incorrect password attempts.<\/span><\/p>\n<p><b>Question 368. Who can reactivate an EMS administrator account that EMS disabled because of prolonged inactivity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any endpoint user<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiAnalyzer only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The disabled administrator without assistance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A Super administrator**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A Super administrator<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When EMS automatically disables an administrator account because it has been inactive for longer than the configured threshold, Fortinet specifies that a <\/span><b>Super administrator<\/b><span style=\"font-weight: 400;\"> can reactivate the account. This reflects EMS&#8217;s role-based administrative model: high-impact account-management operations are reserved for highly privileged administrators. Automatic inactivity disabling protects the environment from dormant privileged accounts, while Super administrator reactivation provides a controlled recovery mechanism for legitimate users returning after a long absence. Organizations should therefore maintain appropriately protected Super administrator access so account recovery remains possible when required.<\/span><\/p>\n<p><b>Question 369. What does the EMS \u201cChange password after x days\u201d setting apply to?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Built-in EMS users such as the admin account and local administrators created in EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All Active Directory passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGate administrator passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every endpoint user&#8217;s operating-system password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Built-in EMS users such as the admin account and local administrators created in EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Change password after x days<\/b><span style=\"font-weight: 400;\"> control applies specifically to built-in EMS accounts, including the built-in admin user and local administrators created within EMS. It does not control password expiration in Active Directory, SAML identity providers, FortiGate, or endpoint operating systems. Those external identity sources maintain their own credential policies. Fortinet also allows the administrator to enter zero to disable this EMS password-expiration setting. Understanding the scope of this control helps avoid confusion when an LDAP-based administrator&#8217;s password does not follow the expiration schedule configured for EMS local accounts.<\/span><\/p>\n<p><b>Question 370. What does entering 0 for \u201cChange password after x days\u201d do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Forces immediate password reset<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes all local administrator passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enables daily password changes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables the EMS local-account password-expiration setting**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Disables the EMS local-account password-expiration setting<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet allows an administrator to enter <\/span><b>0<\/b><span style=\"font-weight: 400;\"> for the local-account password-change interval. This disables the EMS-enforced password-expiration requirement for built-in EMS users. It does not remove passwords or disable authentication; it simply stops EMS from forcing local administrators to change their passwords after a specified number of days. Organizations may instead rely on another internal password-management policy, but they should ensure that local privileged accounts remain adequately protected. This setting does not control credentials managed by LDAP, SAML, Microsoft Entra ID, or another external identity source.<\/span><\/p>\n<p><b>Question 371. What happens the first time an administrator logs in to a newly installed FortiClient EMS 7.4 system using the default admin account?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS permanently keeps the password blank<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS automatically creates an LDAP account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS requires creation of a new username and password for increased security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGate must approve the login<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. EMS requires creation of a new username and password for increased security<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">On a newly installed EMS system, Fortinet documents that the default <\/span><span style=\"font-weight: 400;\">admin<\/span><span style=\"font-weight: 400;\"> account initially has no password. After the administrator signs in for the first time, EMS requires the administrator to create a new set of credentials that follows the displayed password rules. This prevents the system from continuing to operate with the initial blank-password state. The initial-login process is therefore part of hardening the EMS management interface. Production administrators should also configure trusted certificates, appropriate administrator roles, lockout behavior, and inactivity controls after completing initial access.<\/span><\/p>\n<p><b>Question 372. Under what condition can EMS display a certificate-related popup after an administrator logs in?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> If no secure SSL certificate has been imported or the certificate has not been correctly configured for Endpoint Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever an endpoint has a vulnerability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever FortiAnalyzer is disconnected<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever an administrator changes a password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. If no secure SSL certificate has been imported or the certificate has not been correctly configured for Endpoint Control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that EMS can display a popup after login when a secure SSL certificate has not been imported or when an imported certificate has not been configured correctly for the Endpoint Control service. The warning helps administrators identify an incomplete certificate configuration that could cause trust problems for browsers, endpoints, or FortiGate integrations. Importing a certificate alone is not always sufficient; it must also be assigned to the appropriate EMS service. Certificate deployment should therefore include both upload and service-assignment verification.<\/span><\/p>\n<p><b>Question 373. Why should the certificate assigned to the EMS Endpoint Control service be trusted by FortiClient endpoints?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The certificate is used to license FortiClient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Control communication must be protected by a certificate the connecting endpoints can trust<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It determines FortiClient antivirus severity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It stores user SAML passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Endpoint Control communication must be protected by a certificate the connecting endpoints can trust<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EMS uses certificates to secure communication with FortiClient endpoints and other connected Fortinet components. The certificate presented for Endpoint Control should be trusted by the connecting endpoints so that the TLS-protected management connection can be validated reliably. Fortinet&#8217;s ZTNA deployment guidance recommends installing a server certificate from a trusted public or private certificate authority and assigning it as the Endpoint Control certificate. This reduces trust warnings and provides stronger identity assurance than relying on an untrusted default certificate.<\/span><\/p>\n<p><b>Question 374. Which EMS service and port pair is correctly matched?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Chromebook daemon \u2014 TCP 8013<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Control daemon \u2014 TCP 10443<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Installer service \u2014 TCP 8443<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Control daemon \u2014 TCP 8013**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Endpoint Control daemon \u2014 TCP 8013<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The EMS <\/span><b>Endpoint Control<\/b><span style=\"font-weight: 400;\"> service uses TCP <\/span><b>8013<\/b><span style=\"font-weight: 400;\"> by default and is the primary management and Telemetry communication channel between FortiClient and EMS. Fortinet separately documents TCP 10443 for installer downloads, TCP 8443 for the Chromebook daemon, and TCP 443 for the EMS administrative GUI. The websocket notification daemon uses TCP 8015. Because different EMS functions can use different server certificates and ports, administrators troubleshooting TLS or connectivity issues should identify the specific service that is failing before making network or certificate changes.<\/span><\/p>\n<p><b>Question 375. Which EMS service uses the same web-server certificate category as the GUI and listens on TCP 10443?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient installer download service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Chromebook profile service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Control Telemetry service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PostgreSQL database service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. FortiClient installer download service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The EMS web-server certificate covers the Apache web services, including the administrative GUI on TCP 443 and FortiClient installer downloads on <\/span><b>TCP 10443<\/b><span style=\"font-weight: 400;\">. The same web-server certificate category is also associated with the notification\/websocket service on TCP 8015. Endpoint Control on TCP 8013 is configured separately, as is the Chromebook service on TCP 8443. Understanding these certificate assignments helps administrators diagnose cases where the EMS GUI is trusted but FortiClient Telemetry is not, or where installer downloads show certificate problems even though endpoint management is otherwise functioning.<\/span><\/p>\n<p><b>Question 376. Which EMS service normally uses TCP 8443 and can have a separate certificate assignment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient installer download<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiOS websocket notifications<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Chromebook daemon<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Control Telemetry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Chromebook daemon<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents TCP <\/span><b>8443<\/b><span style=\"font-weight: 400;\"> for the EMS Chromebook daemon. EMS Server Certificates allows administrators to see which certificate is assigned to the Chromebook service separately from certificates used by the web server or Endpoint Control. This distinction matters in mixed-platform environments because a certificate issue affecting Chromebook connectivity may not affect Windows or macOS FortiClient Telemetry. Administrators should map the failing feature to its exact EMS service, port, and certificate assignment before troubleshooting network access or trust-chain issues.<\/span><\/p>\n<p><b>Question 377. If EMS has only the FortiCare-issued certificates and its built-in default certificate available, which certificate does EMS prefer first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The default certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The <\/span><span style=\"font-weight: 400;\">.2.cert<\/span><span style=\"font-weight: 400;\"> FortiCare certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A randomly selected certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The <\/span><span style=\"font-weight: 400;\">.1.cert<\/span><span style=\"font-weight: 400;\"> FortiCare certificate**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The <\/b><b>.1.cert<\/b><b> FortiCare certificate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Licensed EMS systems can receive FortiCare-issued certificates named with <\/span><span style=\"font-weight: 400;\">.1.cert<\/span><span style=\"font-weight: 400;\"> and <\/span><span style=\"font-weight: 400;\">.2.cert<\/span><span style=\"font-weight: 400;\"> suffixes. Fortinet documents that when only these certificates and the EMS default certificate are available, EMS prefers the FortiCare-issued certificates over the default certificate, with <\/span><b>.1.cert<\/b><b> preferred over <\/b><b>.2.cert<\/b><span style=\"font-weight: 400;\">. However, these certificates may not be trusted automatically by standard browsers or endpoints because they are not necessarily issued by a public CA. For production deployments, administrators often configure a certificate issued by a trusted public or organizational certificate authority.<\/span><\/p>\n<p><b>Question 378. What can an administrator configure with \u201cReset Stalled Deployment Interval\u201d?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of hours after which EMS resets a deployment considered stalled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of minutes before an administrator password expires<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The amount of time FortiGate caches routing information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The interval for Web Filter category updates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The number of hours after which EMS resets a deployment considered stalled<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Reset Stalled Deployment Interval<\/b><span style=\"font-weight: 400;\"> setting specifies how many hours EMS waits before resetting a deployment that has become stalled. This provides an automated recovery mechanism for deployment tasks that are no longer progressing normally. A stalled deployment is different from an endpoint simply being offline or a user intentionally scheduling installation for later. Administrators should review endpoint connectivity, installer availability, operating-system compatibility, and deployment configuration when repeated stalls occur instead of relying solely on automatic reset. The interval is configured as an EMS management setting and can also be site-specific in multisite deployments.<\/span><\/p>\n<p><b>Question 379. In a multisite EMS deployment, which statement about the login banner is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One banner is automatically shared globally across every site and cannot differ<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Login banners are supported only on FortiClient endpoints<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The login banner is configured at the site level and appears when signing in to that specific site<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Login banners require FortiAnalyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The login banner is configured at the site level and appears when signing in to that specific site<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet lists <\/span><b>Enable login banner<\/b><span style=\"font-weight: 400;\"> among settings configured separately for individual EMS sites. The banner displayed applies when an administrator signs in to the specified site, allowing organizations to present site-specific legal notices, operational messages, or administrative warnings. This reflects the broader multisite design in which many EMS settings and objects\u2014including endpoint policies, profiles, deployment packages, Feature Select, Software Inventory, and site-level permissions\u2014are managed independently per site. Administrators should therefore avoid assuming that every EMS setting automatically propagates across all sites.<\/span><\/p>\n<p><b>Question 380. An EMS administrator reports repeated account lockouts, certificate warnings on endpoints, and deployment jobs that remain stuck. Which troubleshooting approach BEST addresses all three issues?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review Admin Lockout Attempt and Lockout Period settings, verify a trusted certificate is assigned to the Endpoint Control service, and examine the Reset Stalled Deployment Interval together with deployment connectivity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all administrator security settings and use the default certificate permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reinstall every FortiClient endpoint immediately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace FortiGate because all three symptoms must originate from the firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Review Admin Lockout Attempt and Lockout Period settings, verify a trusted certificate is assigned to the Endpoint Control service, and examine the Reset Stalled Deployment Interval together with deployment connectivity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The three symptoms involve different EMS subsystems. Administrator lockouts should be investigated through the configured failed-attempt threshold and lockout period. Endpoint certificate warnings point to server-certificate trust and whether the correct certificate is assigned to Endpoint Control on TCP 8013. Stalled deployments require review of deployment state, endpoint reachability, installer access, and the configured stalled-deployment reset interval. Treating each issue according to its subsystem avoids destructive troubleshooting such as reinstalling endpoints or disabling security controls without evidence. A systematic EMS troubleshooting approach maps each symptom to the relevant configuration and communication path.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps. Question 361. What is the default number of unsuccessful administrator login attempts before FortiClient EMS locks the administrator account temporarily? One attempt Five attempts Three attempts Ten attempts Correct Answer: 3. Three attempts Explanation: FortiClient EMS includes an administrator lockout mechanism designed to reduce the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20890"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20890"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20890\/revisions"}],"predecessor-version":[{"id":20891,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20890\/revisions\/20891"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20890"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20890"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}