2025 FCP_FGT_AD-7.4 dumps review - Professional Quiz Study Materials
FCP_FGT_AD-7.4 Test Prep Training Practice Exam Questions Practice Tests
NEW QUESTION # 30
Which three methods are used by the collector agent for AD polling? (Choose three.)
- A. WMI
- B. WinSecLog
- C. NetAPI
- D. FSSO REST API
- E. FortiGate polling
Answer: A,B,C
Explanation:
The Fortinet Single Sign-On (FSSO) Collector Agent supports three primary methods for Active Directory (AD) polling to collect user information:
WinSecLog: Monitors Windows Security Event Logs for login events.
WMI: Uses Windows Management Instrumentation to poll user login sessions.
NetAPI: Utilizes the Netlogon API to query domain controllers for user session data.
These methods allow the FortiGate to gather user logon information and enforce user-based policies effectively.
Reference:
FortiOS 7.4.1 Administration Guide: FSSO Configuration
NEW QUESTION # 31
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements are true about the requirements of connected physical interfaces on FortiGate? (Choose two.)
- A. Both interfaces must have the interface role assigned
- B. Both interfaces must have DHCP enabled
- C. Both interfaces must have IP addresses assigned
- D. Both interfaces must have directly connected routes on the routing table
Answer: C,D
Explanation:
Both interfaces must have directly connected routes on the routing table In NAT mode, each interface must have a corresponding entry in the routing table, typically as a directly connected route, to route traffic between them effectively.
Both interfaces must have IP addresses assigned
In NAT mode, each interface must have an IP address to participate in routing and NAT operations. The IP addresses allow the FortiGate to forward traffic between different network segments.
NEW QUESTION # 32
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
- A. The server name indication (SNI) extension in the client hello message.
- B. The subject field in the server certificate.
- C. The serial number in the server certificate.
- D. The host field in the HTTP header.
- E. The subject alternative name (SAN) field in the server certificate.
Answer: A,B,E
Explanation:
When SSL certificate inspection is enabled on a FortiGate device, the system uses the following three pieces of information to identify the hostname of the SSL server:
Server Name Indication (SNI) extension in the client hello message (B): The SNI is an extension in the client hello message of the SSL/TLS protocol. It indicates the hostname the client is attempting to connect to. This allows FortiGate to identify the server's hostname during the SSL handshake.
Subject Alternative Name (SAN) field in the server certificate (C): The SAN field in the server certificate lists additional hostnames or IP addresses that the certificate is valid for. FortiGate inspects this field to confirm the identity of the server.
Subject field in the server certificate (D): The Subject field contains the primary hostname or domain name for which the certificate was issued. FortiGate uses this information to match and validate the server's identity during SSL certificate inspection.
The other options are not used in SSL certificate inspection for hostname identification:
Host field in the HTTP header (A): This is part of the HTTP request, not the SSL handshake, and is not used for SSL certificate inspection.
Serial number in the server certificate (E): The serial number is used for certificate management and revocation, not for hostname identification.
Reference
FortiOS 7.4.1 Administration Guide - SSL/SSH Inspection, page 1802.
FortiOS 7.4.1 Administration Guide - Configuring SSL/SSH Inspection Profile, page 1799.
NEW QUESTION # 33
An administrator needs to increase network bandwidth and provide redundancy.
What interface type must the administrator select to bind multiple FortiGate interfaces?
- A. Redundant interface
- B. Aggregate interface
- C. VLAN interface
- D. Software Switch interface
Answer: B
Explanation:
Link aggregation (IEEE 802.3ad) enables you to bind two or more physical interfaces together to form an aggregated (combined) link. This new link has the bandwidth of all the links combined. If a link in the group fails, traffic is transferred automatically to the remaining interfaces with the only noticeable effect being a reduced bandwidth.
To increase network bandwidth and provide redundancy, an administrator can use an Aggregate Interface (also known as Link Aggregation or Port Channel). This interface type allows multiple physical interfaces to be combined into a single logical interface, providing increased bandwidth and fault tolerance. This logical interface appears as a single interface to the rest of the network, and it distributes traffic across the member interfaces.
NEW QUESTION # 34
Refer to the exhibit.
FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles.
Which action must the administrator perform to consolidate the two policies into one?
- A. Create an Interface Group that includes port1 and port2 to create a single firewall policy
- B. Replace port1 and port2 with the any interface in a single firewall policy.
- C. Select port1 and port2 subnets in a single firewall policy.
- D. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy
Answer: A
Explanation:
To consolidate the two separate firewall policies for Sales and Engineering departments accessing the same web server, you can create an Interface Group that includes both port1 (Sales) and port2 (Engineering). Once the Interface Group is created, you can use this group as a single incoming interface in a single firewall policy. This approach reduces the number of policies, making management more efficient.
Reference:
FortiOS 7.4.1 Administration Guide: Firewall Policy Configuration
NEW QUESTION # 35
Refer to the exhibits, which show the system performance output and the default configuration of high memory usage thresholds in a FortiGate.

Based on the system performance output, what can be the two possible outcomes? (Choose two.)
- A. Administrators can access FortiGate onlythrough the console port.
- B. FortiGate will start sending all files to FortiSandbox for inspection.
- C. Administrators cannot change the configuration.
- D. FortiGate has entered conserve mode.
Answer: A,D
Explanation:
Based on the system performance output provided, the memory usage on the FortiGate device is at 90%, which is above the green threshold (82%) but below the red threshold (88%). Given this high memory usage, the FortiGate device will enter "conserve mode" to prevent further resource exhaustion. In conserve mode:
* B. FortiGate has entered conserve mode: When the memory usage reaches or exceeds certain thresholds (in this case, the green and red thresholds), the FortiGate enters conserve mode to protect itself from running out of memory entirely. This mode limits some functionalities to reduce memory usage and avoid a potential system crash.
* D. Administrators can access FortiGate only through the console port: During conserve mode, administrative access might be restricted, and administrators may only be able to connect to the device via the console port. This restriction is in place to ensure that the FortiGate can be managed directly, even under low resource conditions.
The other options are not correct:
* A. FortiGate will start sending all files to FortiSandbox for inspection: This is unrelated to memory usage and conserve mode.
* C. Administrators cannot change the configuration: While access may be limited, configuration changes can still be made via the console port.
References
* FortiOS 7.4.1 Administration Guide - Monitoring System Resources and Performance, page 325.
* FortiOS 7.4.1 Administration Guide - Conserve Mode, page 330.
NEW QUESTION # 36
Which two configuration settings are synchronized when FortiGate devices are in an active-active HA cluster? (Choose two.)
- A. FortiGate hostname
- B. NTP
- C. FortiGuard web filter cache
- D. DNS
Answer: B,D
Explanation:
C: NTP
D: DNS
Not all the configuration settings are synchronized.
There are a few that are not, such as:
* System interface settings of the HA reserved management interface and the HA default route for the reserved management interface
* In-band HA management interface
* HA override
* HA device priority
* Virtual cluster priority
* FortiGate hostname
* HA priority setting for a ping server (or dead gateway detection) configuration
* All licenses except FortiToken licenses (serial numbers)
* Cache
Fortigate Hostname is not synchronized between cluster member.
NEW QUESTION # 37
Which two actions can you perform only from the root FortiGate in a Security Fabric? (Choose two.)
- A. Log in to a downstream FortiSwitch device.
- B. Shut down/reboot a downstream FortiGate device.
- C. Disable FortiAnalyzer logging for a downstream FortiGate device.
- D. Ban or unban compromised hosts.
Answer: B,D
Explanation:
A. Shut down/reboot a downstream FortiGate device.
This is correct. The root FortiGate has the ability to control the power state of downstream FortiGate devices.
D. Ban or unban compromised hosts.
This is also correct. The root FortiGate can take actions to ban or unban compromised hosts, helping to manage and control security incidents.
Therefore, the correct answers are A and D.
NEW QUESTION # 38
Refer to the exhibit.
Which route will be selected when trying to reach 10.20.30.254?
- A. 10.20.30.0/24 [10/0] via 172.20.167.254, port3, [1/0]
- B. 10.20.30.0/26 [10/0] via 172.20.168.254, port2, [1/0]
- C. 0.0.0.0/0 [10/0] via 172.20.121.2, port1, [1/0]
- D. 10.30.20.0/24 [10/0] via 172.20.121.2, port1, [1/0]
Answer: A
Explanation:
The correct route to reach 10.20.30.254 would be:
A. 10.20.30.0/24 [10/0] via 172.20.167.254, port3, [1/0]
This route is more specific (10.20.30.0/24) compared to the other routes (10.20.30.0/26 and
10.30.20.0/24) and would therefore be selected as the best match.
NEW QUESTION # 39
Refer to the exhibit.
The exhibit shows theFortiGuard Category Based Filtersection of a corporate web filter profile.
An administrator must block access todownload.com, which belongs to theFreeware and Software Downloadscategory. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)
- A. Configure a web override rating for download, com and select Malicious Websites as the subcategory.
- B. Configure a static URL filter entry for download, com with Type and Action set to Wildcard and Block, respectively.
- C. Set the Freeware and Software Downloads category Action to Warning
- D. Configure a separate firewall policy with action Deny and an FQDN address object for *. download, com as destination address.
Answer: A,B
NEW QUESTION # 40
Refer to the exhibit.
The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name.
FortiGate allows the traffic according to policy ID 1. This is the policy that allows SD-WAN traffic.
Despite these settings the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows.
What can be the reason?
- A. Destination in the SD-WAN rules are configured per application but the feature visibility is not enabled.
- B. SD-WAN rule names do not appear immediately. The administrator needs to refresh the page.
- C. There is no application control profile applied to the firewall policy.
- D. FortiGate load balanced the traffic according to the implicit SD-WAN rule.
Answer: D
Explanation:
If the SD-WAN traffic logs do not show the specific SD-WAN rule name, it likely means that FortiGate is using the default or implicit SD-WAN rule to balance traffic. The implicit rule comes into effect when no explicit SD-WAN rule is matched, and as a result, the SD-WAN rule name is not displayed in the logs. The default behavior is to load balance the traffic across available interfaces based on SD-WAN strategy.
NEW QUESTION # 41
Which two statements are true about the FGCP protocol? (Choose two.)
- A. FGCP is not used when FortiGate is in transparent mode.
- B. FGCP runs only over the heartbeat links.
- C. FGCP is used to discover FortiGate devices in different HA groups.
- D. FGCP elects the primary FortiGate device.
Answer: B,D
Explanation:
A: FGCP elects the primary FortiGate device.
C: FGCP runs only over the heartbeat links.
The FGCP (FortiGate Clustering Protocol) is a protocol that is used to manage high availability (HA) clusters of FortiGate devices.
It performs several functions, including the following:
FGCP elects the primary FortiGate device: In an HA cluster, FGCP is used to determine which FortiGate device will be the primary device, responsible for handling traffic and making decisions about what to allow or block. FGCP uses a variety of factors, such as the device's priority, to determine which device should be the primary.
FGCP runs only over the heartbeat links: FGCP communicates between FortiGate devices in the HA cluster using the heartbeat links. These are dedicated links that are used to exchange status and control information between the devices. FGCP does not run over other types of links, such as data links.
FortiGate HA uses the Fortinet-proprietary FortiGate Clustering Protocol (FGCP) to discover members, elect the primary FortiGate, synchronize data among members, and monitor the health of members.
To discover and monitor members, the members broadcast heartbeat packets over all configured heartbeat interfaces.
NEW QUESTION # 42
Refer to exhibit.
An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page.
Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?
- A. On the Static URL Filter configuration, set Type to Simple.
- B. On the FortiGuard Category Based Filter configuration, set Action to Warning for Social Networking.
- C. On the Static URL Filter configuration, set Action to Exempt.
- D. On the Static URL Filter configuration, set Action to Monitor.
Answer: C
Explanation:
C: On the Static URL Filter configuration, set Action to Exempt.
Based on the exhibit, the administrator has configured the FortiGuard Category Based Filter to block access to all social networking sites, and has also configured a Static URL Filter to block access to twitter.com. As a result, users are being redirected to a block page when they try to access twitter.com.
To allow users to access twitter.com while blocking all other social networking sites, the administrator can make the following configuration change:
On the Static URL Filter configuration, set Action to Exempt: By setting the Action to Exempt, the administrator can override the block on twitter.com that was specified in the FortiGuard Category Based Filter. This will allow users to access twitter.com, while all other social networking sites will still be blocked.
Note:
Tested this in a lab environment and to make this work as stated in the question the Exempt action is the only way to go, and also *.twimg.com will has to be added to the URL Filter with an Exempt action for this situation to really work!
Allow: Access is permitted. Traffic is passed to remaining operations, including FortiGuard web filter, web content filter, web script filters, and antivirus scanning.
Exempt: Allows traffic from trusted sources to bypass all security inspections.
NEW QUESTION # 43
Refer to the exhibit.
FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles.
Which action must the administrator perform to consolidate the two policies into one?
- A. Create an Interface Group that includes port1 and port2 to create a single firewall policy
- B. Replace port1 and port2 with the any interface in a single firewall policy.
- C. Select port1 and port2 subnets in a single firewall policy.
- D. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy
Answer: A
Explanation:
To consolidate the two separate firewall policies for Sales and Engineering departments accessing the same web server, you can create an Interface Group that includes both port1 (Sales) and port2 (Engineering). Once the Interface Group is created, you can use this group as a single incoming interface in a single firewall policy. This approach reduces the number of policies, making management more efficient.
References:
* FortiOS 7.4.1 Administration Guide: Firewall Policy Configuration
NEW QUESTION # 44
Refer to the exhibit.
The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem.
With this configuration, which statement is true?
- A. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
- B. A default static route is not required on the To_Internet VDOM to allow LAN users to access the internet.
- C. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
- D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.
Answer: C
Explanation:
A. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
Incorrect:
B. A default static route is not required on the To_Internet VDOM to allow LAN users to access the internet.
C. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs. (transparent- transparent)
D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.
Each VDOM has independent security policies and routing tables. Also, and by default, traffic from one VDOM cannot go to a different VDOM.
You cannot create an inter-VDOM link between Layer 2 transparent mode VDOMs. At least one of the VDOMs must be operating in NAT mode.
Similar to FortiGate without VDOMs enabled, the management VDOM should have outgoing internet access. Otherwise, features such as scheduled FortiGuard updates, fail.
NEW QUESTION # 45
An administrator manages a FortiGate model that supports NTurbo.
How does NTurbo enhance performance for flow-based inspection?
- A. NTurbo offloads traffic to the content processor.
- B. NTurbo creates a special data path to redirect traffic between the IPS engine its ingress and egress interfaces.
- C. NTurbo buffers the whole file and then sends it to the antivirus engine.
- D. NTurbo creates two inspection sessions on the FortiGate device.
Answer: A
Explanation:
NTurbo enhances performance for flow-based inspection by offloading traffic to the content processor.
NEW QUESTION # 46
Which two statements are true about the RPF check? (Choose two.)
- A. The RPF check is run on the first reply packet of any new session.
- B. RPF is a mechanism that protects FortiGuard and your network from IP spoofing attacks.
- C. The RPF check is run on the first sent and reply packet of any new session.
- D. The RPF check is run on the first sent packet of any new session.
Answer: B,D
Explanation:
RPF protect against IP spoofin attacks. The source IP address is checked against the routing table for a return path. RPF is only carried out on: The first packet in the session, not on reply.
NEW QUESTION # 47
Which two statements describe how the RPF check is used? (Choose two.)
- A. The RPF check is a mechanism that protects FortiGateand the network from IP spoofingattacks.
- B. The RPF check is run on the first reply packet of any new session.
- C. The RPF check is run on the first sent and reply packet of any new session.
- D. The RPF check is run on the first sent packet of any new session.
Answer: A,D
NEW QUESTION # 48
FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.
In this scenario, what are two requirements for the VLAN ID? (Choose two.)
- A. The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.
- B. The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
- C. The two VLAN subinterfaces must have different VLAN IDs.
- D. The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
Answer: A,C
Explanation:
B: The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.
C: The two VLAN subinterfaces must have different VLAN IDs.
https://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-use-emac-vlan-to-share-the-same-VL AN/ta-p/192843?externalID=FD43883 Each interface (physical or VLAN) can belong to only one VDOM.
Meaning that sub-interfaces (VLANs) from the same physical interface can have the same VLAN ID as long as they are not assign to the same VDOM.
VLAN
https://community.fortinet.com/t5/FortiGate/Technical-Tip-rules-about-VLAN-configuration-and-VDOM- interface/ta-p/197640
* VLANs can be created on any physical or aggregate (802.3ad) interfaces
- The same VLAN number cannot be configured twice on the same physical interface
- The same VLAN number can be used on different physical interfaces
- The usable VLAN ID range is from 1 to 4094
* VDOM interface assignment
- Two VDOMs cannot share the same interface or VLAN
- A VLAN sub-interface can belong to a different VDOM than the physical interface it is attached to.
NEW QUESTION # 49
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
- A. Denied users are blocked for 30 minutes
- B. The number of logs generated by denied traffic is reduced
- C. Device detection on all interfaces is enforced for 30 minutes
- D. A session for denied traffic is created
Answer: B,D
Explanation:
C: A session for denied traffic is created.
D: The number of logs generated by denied traffic is reduced.
During the session, if a security profile detects a violation, FortiGate records the attack log immediately.
To reduce the number of log messages generated and improve performance, you can enable a session table entry of dropped traffic. This creates the denied session in the session table and, if the session is denied, all packets of that session are also denied. This ensures that FortiGate does not have to do a policy lookup for each new packet matching the denied session, which reduces CPU usage and log generation.
This option is in the CLI, and is called ses-denied-traffic. You can also set the duration for block sessions.
This determines how long a session will be kept in the session table by setting block-sessiontimer in the CLI. By default, it is set to 30 seconds.
NEW QUESTION # 50
An administrator must enable a DHCP server on one of the directly connected networks on FortiGate.
However, the administrator is unable to complete the process on the GUI to enable the service on the interface.
In this scenario, what prevents the administrator from enabling DHCP service?
- A. The FortiGate model does not support the DHCP server.
- B. The DHCP server setting is available only on the CLI.
- C. The role of the interface prevents setting a DHCP server.
- D. Another interface is configured as the only DHCP server on FortiGate.
Answer: C
Explanation:
FortiGate interfaces can be configured in different roles, such as WAN or LAN. If an interface is set as a
"WAN" role, you cannot configure it to act as a DHCP server through the GUI. The interface role must be set to "LAN" or "Undefined" to allow DHCP server configuration.
References:
* FortiOS 7.4.1 Administration Guide: DHCP Server Configuration
NEW QUESTION # 51
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network and the firewall policy and IP pool configuration on the FortiGate device.
Which two actions does FortiGate take on internet traffic sourced from the subscribers? (Choose two.)
- A. FortiGate allocates port blocks on a first-come, first-served basis.
- B. FortiGate allocates 128 port blocks per user.
- C. FortiGate allocates port blocks per user, based on the configured range of internal IP addresses.
- D. FortiGate generates a system event log for every port block allocation made per user.
Answer: A,D
Explanation:
B: FortiGate allocates port blocks on a first-come, first-served basis
C: For logging purposes, when FortiGate allocates a port block to a host, it generates a system event log to inform the administrator Not A: FortiGate allocates a block size and number per host for a range of external addresses Not D: It allows 8 blocks of 128 ports per host FortiGate allocates port blocks on a first-come, first-served basis.
For logging purposes, when FortiGate allocates a port block to a host, it generates a system event log to inform the administrator.
NEW QUESTION # 52
Refer to the exhibit showing a FortiGuard connection debug output.
Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
- A. There is at least one server that lost packets consecutively.
- B. FortiGate is usingdefaultFortiGuard communication settings.
- C. A local FortiManaqer is one of the servers FortiGate communicates with.
- D. One server was contacted to retrieve the contract information.
Answer: B,D
NEW QUESTION # 53
Refer to the exhibit.
Which statement about this firewall policy list is true?
- A. The firewall policies are listed by ID sequence view.
- B. LAN to WAN. WAN to LAN. and Implicit are sequence grouping view lists.
- C. The Implicit group can include more than one deny firewall policy.
- D. The firewall policies are listed by ingress and egress interfaces pairing view.
Answer: D
NEW QUESTION # 54
......
Fortinet FCP_FGT_AD-7.4 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
Exam Questions Answers Braindumps FCP_FGT_AD-7.4 Exam Dumps PDF Questions: https://www.prepawaypdf.com/Fortinet/FCP_FGT_AD-7.4-practice-exam-dumps.html
FCP_FGT_AD-7.4 Exam Dumps, FCP_FGT_AD-7.4 Practice Test Questions: https://drive.google.com/open?id=11QisDPfxmKZ5Ly_gW1QqNBEQiG63zCYA