FCP_FGT_AD-7.4 Exam Questions
92 real FCP_FGT_AD-7.4 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Features and concepts
Which inspection mode does FortiGate use for application profiles if it is configured as a profile- based next-generation firewall (NGFW)?
NGFWinspection modeflow-based inspectionapplication profiles - Question #2Logging and Monitoring
Refer to the exhibit showing a FortiGuard connection debug output. Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.)
FortiGuarddebug outputserver communicationconnection analysis - Question #3Logging and Monitoring
Refer to the exhibit. Why did FortiGate drop the packet?
packet dropimplicit denyfirewall policytraffic analysis - Question #4Features and concepts
An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable...
DHCP serverinterface roleFortiGate configurationnetwork services - Question #5Alerting and Incident Response
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What do you conclude when adding the FTP.Login.Failed signature...
IPSsignature settingstraffic actionintrusion prevention - Question #6Features and concepts
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. Which order must FortiGate use when the web filt...
web filteringHTTP inspection orderURL filterFortiGuard category - Question #7Logging and Monitoring
FortiGate is integrated with FortiAnalyzer and FortiManager. When a firewall policy is created, which attribute is added to the policy to improve functionality and to support recor...
firewall policyUUIDFortiAnalyzer loggingpolicy attributes - Question #8Features and concepts
An administrator configured a FortiGate to act as a collector for agentless polling mode. What must the administrator add to the FortiGate device to retrieve AD user group informat...
agentless pollingAD user groupsLDAPcollector mode - Question #9Features and concepts
An administrator manages a FortiGate model that supports NTurbo. How does NTurbo enhance performance for flow-based inspection?
NTurboflow-based inspectionperformance optimizationIPS engine - Question #10
Refer to the exhibit. FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles. Which action must the ad...
- Question #11Authentication
Refer to the exhibit, which shows a partial configuration from the remote authentication server. Why does the FortiGate administrator need this configuration?
RADIUSuser group filteringremote authenticationOU matching - Question #12Firewall Policies
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port1)...
SNATIP poolNATfirewall policy - Question #13VPN
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The...
IPsecphase 1IKE modeinterface configuration - Question #14Content inspection
A network administrator has configured an SSL/SSH inspection profile defined for full SSL inspection and set with a private CA certificate. The firewall policy that allows the traf...
SSL inspectionCA certificatecertificate trustHTTPS - Question #15Authentication
Refer to the exhibit. FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt. What is the...
firewall authenticationDNS servicecaptive portallogin prompt - Question #16Authentication
Which three methods are used by the collector agent for AD polling? (Choose three.)
FSSOcollector agentAD pollingWinSecLog - Question #17Routing
Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)
ECMPSD-WANload balancing algorithmv4-ecmp-mode - Question #18Authentication
What are two features of collector agent advanced mode? (Choose two.)
FSSOcollector agentadvanced modenested groups - Question #19FortiGuard
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
FortiGuardDNS over TLSDNS serversdefault settings - Question #20Content inspection
Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infe...
antivirusflow-based inspectionblock replacement messagepacket reset - Question #21High Availability
Refer to the exhibits. FGT-1 and FGT-2 are updated with HA configuration commands shown in the exhibit. What would be the expected outcome in the HA cluster?
HA clusteroverrideprimary electionpriority - Question #22Firewall Policies
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with defau...
firewall policyVIPmatch-vipdeny policy - Question #23Routing
Refer to the exhibit. Which two statements are true about the routing entries in this database table? (Choose two.)
routing tableadministrative distancestandby routeinactive interface - Question #24Content inspection
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
SSL certificate inspectionSNISANserver certificate - Question #25Routing
Refer to the exhibit. Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
SD-WANdefault ruletraffic distributionsource-destination IP - Question #26VPN
A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad. Which IPsec Wizard template must the administrator apply?
IPsec VPNwizard templateremote accessdial-up user - Question #27System and Session Management
Refer to the exhibits, which show the system performance output and the default configuration of high memory usage thresholds in a FortiGate. Based on the system performance output...
conserve modememory thresholdssystem performanceconfiguration restrictions - Question #28Firewall Policies
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device....
IP pooloverload NATone-to-one NATconnectivity troubleshooting - Question #29Deployment and system configuration
Which method allows management access to the FortiGate CLI without network connectivity?
serial consoleCLI accessout-of-band managementnetwork-independent access - Question #30System and Session Management
Refer to the exhibit. In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the...
packet snifferdebug flowtroubleshootingHTTP connectivity - Question #31Content inspection
Refer to the exhibit. The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which be...
web filteringURL filtercategory overrideFQDN address object - Question #32VPN
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tu...
IPsec VPNDead Peer Detectionstatic route distancetunnel failover - Question #33Firewall Policies
Refer to the exhibit. Which statement about this firewall policy list is true?
firewall policypolicy list viewsequence groupingingress egress interface - Question #34Routing
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?
SD-WANSD-WAN zonesinterface membersvirtual-wan-link - Question #35Routing
Which two statements describe how the RPF check is used? (Choose two.)
RPF checkreverse path forwardingIP spoofingsession packets - Question #36Routing
Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)
SD-WANrule strategymember selectionload balancing - Question #37VPN
Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)
IPsec IKEv1XAuthpre-shared keycertificate signature - Question #38High Availability
Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.)
HAconfiguration synchronizationchecksumincremental sync - Question #39Firewall policies and authentication
What are two features of the NGFW profile-based mode? (Choose two.)
NGFWprofile-based modeflow inspectionproxy inspection - Question #40
Refer to the exhibit to view the firewall policy. Why would the firewall policy not block a well-known virus, for example eicar?
- Question #41Content inspection
Refer to the exhibits. The exhibits show the application sensor configuration and the Excessive- Bandwidth and Apple filter details. Based on the configuration, what will happen to...
application controlapplication sensorfilter overridebandwidth filter - Question #42VPN
An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
SSL VPNlogin-timeouthigh latencyVPN negotiation - Question #43Content inspection
When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate. Which three actions are valid actions that FortiGate can...
SSL inspectionfull inspectioninvalid certificatecertificate action - Question #44Content inspection
Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)
IPS sensorsignature actionintrusion preventionWindows signatures - Question #45Security Fabric
Which statement is a characteristic of automation stitches?
automation stitchesSecurity Fabrictriggersautomated actions - Question #46High Availability
What is the primary FortiGate election process when the HA override setting is disabled?
HA electionprimary selectionoverride disabledserial number - Question #47VPN
Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)
SSL VPNFortiGate-to-FortiGate VPNCA certificatetunnel interface - Question #48
Which FortiGate feature sends real-time queries to the FortiGuard Distribution Network (FDN)?
- Question #49
Which FortiGate interface does source device type enable device detection on?
- Question #50
What criteria does FortiGate use to match traffic to a firewall policy? (Choose two.)