FCP_FGT_AD-7.4 Exam Questions
92 real FCP_FGT_AD-7.4 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Content inspection
Which two statements explain antivirus scanning modes? (Choose two.)
antivirusflow-based inspectionproxy-based inspectionfile buffering - Question #52Content inspection
Refer to the exhibits, which show the firewall policy and the security profile for Facebook. Users are given access to the Facebook web application. They can play video content hos...
SSL inspectiondeep inspectionapplication controlFacebook - Question #53Content inspection
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
application controlNGFWIPS enginetraffic inspection - Question #54VPN
A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?
SSL VPNDoS mitigationhttp-request-header-timeoutattack surface - Question #55Firewall policies and authentication
A FortiGate firewall policy is configured with active authentication however, the user cannot authenticate when accessing a website. Which protocol must FortiGate allow even though...
active authenticationDNScaptive portalunauthenticated access - Question #56Content inspection
Refer to exhibit. An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try...
web filteringFortiGuard categoriesstatic URL filterExempt action - Question #57VPN
There are multiple dial-up IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels. Whi...
IPsec VPNdial-up VPNPeer IDaggressive mode - Question #58System and Session Management
Which three CLI commands, can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)
Layer 3 troubleshootingpingtraceroutepacket sniffer - Question #59VPN
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is outboun...
IPsec VPNdead peer detectionDPD On Demandtunnel monitoring - Question #60System and Session Management
Which two statements are correct when FortiGate enters conserve mode? (Choose two.)
conserve modememory managementIPS fail-opensystem resources - Question #61Content inspection
Which statement is correct regarding the use of application control for inspecting web applications?
application controlweb applicationsparent-child applicationsSSL inspection - Question #62Routing
What are three key routing principles in SD-WAN? (Choose three.)
SD-WANrouting principlespolicy routesSD-WAN rules - Question #63Firewall Policies
Refer to the exhibits, which show a diagram of a FortiGate device connected to the network. VIP object configuration, and the firewall policy configuration. The WAN (port1) interfa...
VIPDNATport mappingpacket transformation - Question #64Content inspection
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection? (Choose two.)
SSL inspectionCA certificatekeyUsage extensioncertificate attributes - Question #65System and Session Management
Refer to the exhibit showing a debug flow output. What two conclusions can you make from the debug flow output? (Choose two.)
debug flowICMP trafficsession creationtraffic analysis - Question #66Content inspection
Which three statements explain a flow-based antivirus profile? (Choose three.)
flow-based antivirusproxy-based inspectionIPS engineantivirus scanning - Question #67High Availability
Which two statements are true about the FGCP protocol? (Choose two.)
FGCPHA protocolheartbeat linksprimary election - Question #68Authentication
Refer to the exhibit which contains a RADIUS server configuration. An administrator added a configuration for a new RADIUS server. While configuring, the administrator selected the...
RADIUSuser groupsInclude in every user groupauthentication server - Question #69Security Fabric
Which statement about the deployment of the Security Fabric in a multi-VDOM environment is true?
Security Fabricmulti-VDOMtopology visibilityVDOM configuration - Question #70Routing
Refer to the exhibit. The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD- WAN- specific columns: SD-WAN Quality and SD-WAN Rule Name. Fo...
SD-WANtraffic logsimplicit SD-WAN ruleload balancing - Question #71Content inspection
FortiGuard categories can be overridden and defined in different categories. To create a web rating override for the example.com home page the override must be configured using a s...
web rating overrideFortiGuard categoriesURL syntaxweb filtering - Question #72System and Session Management
An administrator has configured the following settings: config system settings set ses-denied-traffic enable end config system global set block-session-timer 30 end What are the tw...
denied traffic sessionsblock-session-timerlog reductionsession management - Question #73Firewall Policies
Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing...
VIPARP replyconnectivity troubleshootingDNAT - Question #74VPN
An organization requires remote users to send external application data running on their PCs and access FTP resources through an SSUTLS connection. Which FortiGate configuration ca...
SSL VPNtunnel modeFTP accessremote access - Question #75Routing
Which three statements about SD-WAN zones are true? (Choose three.)
SD-WAN zonesinterface membersstatic routeslogical grouping - Question #76Routing
An administrator has configured a strict RPF check on FortiGate. How does strict RPF check work?
RPFreverse path forwardingincoming interfacerouting - Question #77Content inspection
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visit...
SSL inspectioncertificate trustHTTPSweb filtering - Question #78
Refer to the exhibit. The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivi...
- Question #79Content inspection
A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus...
SSL inspectionantiviruscertificate inspectionSSL exemption - Question #80Content inspection
Refer to the exhibit. Examine the intrusion prevention system (IPS) diagnostic command shown in the exhibit. If option 5 is used with the IPS diagnostic command and the outcome is...
IPS diagnosticsCPU usagetraffic inspectionIPS engine - Question #81Routing
How can you disable RPF checking?
RPFsrc-checkinterface settings - Question #82VPN
An administrator is configuring an IPsec VPN between site A and site . The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quic...
IPsec VPNquick mode selectorsite-to-site VPNsubnet configuration - Question #83Deployment and system configuration
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements are true about the requirements of conne...
NAT modephysical interfaceconnected routesIP address assignment - Question #84High Availability
Which two pieces of information are synchronized between FortiGate HA members? (Choose two.)
HA synchronizationIPsec SADHCP leasesFortiGate HA - Question #85Routing
Refer to the exhibit. Based on the routing database shown in the exhibit which two conclusions can you make about the routes? (Choose two.)
routing databaseadministrative distancedefault routesrouting table - Question #86Authentication
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
FSSOagentless pollingSMB protocolworkstation check - Question #87Authentication
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
FSSONetAPI pollingNetSessionEnumcollector agent - Question #88Security Fabric
Refer to the exhibits. An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not avail...
Security Fabricaddress object synchronizationCSF settingsfabric-object-unification - Question #89VPN
Refer to the exhibits. The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to the SSL VPN?
SSL VPNport configurationVPN troubleshooting - Question #90Firewall Policies
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies configuration, VIP configuration, and IP pool configura...
SNATIP poolNATfirewall policy - Question #91
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy, and the sniffer CLI output on the FortiGate d...
- Question #92VPN
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phas...
IPsec VPNphase 2encryption mismatchquick mode selector