nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #127

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to…

The correct answer is A. Set the Destination address as Webserver in the Deny policy. D. Enable match-vip in the Deny policy. The scenario involves a VIP (Virtual IP) object representing the Webserver. By default, FortiGate firewall policies do not match VIP destination addresses in deny policies-VIP matching in deny policies requires 'match-vip' to be enabled (D). Without it, the deny policy is…

Submitted by khalil_dz· Apr 18, 2026Firewall policies and authentication

Question

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which two configuration changes can the administrator make to the policy to deny Webserver access for Remote-User2? (Choose two.)

Options

  • ASet the Destination address as Webserver in the Deny policy.
  • BDisable in the Deny policy.
  • CSet the Destination address as Deny_IP in the Allow_access policy.
  • DEnable match-vip in the Deny policy.

How the community answered

(26 responses)
  • A
    77% (20)
  • B
    8% (2)
  • C
    15% (4)

Explanation

The scenario involves a VIP (Virtual IP) object representing the Webserver. By default, FortiGate firewall policies do not match VIP destination addresses in deny policies-VIP matching in deny policies requires 'match-vip' to be enabled (D). Without it, the deny policy is bypassed for VIP-destined traffic. Additionally, setting the Destination address as Webserver (the VIP object) in the Deny policy (A) ensures the policy targets the correct destination. Option B (disabling something) is incomplete and not the fix. Option C targets the allow policy's destination, which would affect Remote-User1 and break the requirement for User1 to retain access.

Topics

#Firewall Policies#Policy Matching#Virtual IP (VIP)#Access Control

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice