nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #93

An administrator has configured the following settings: What are the two results of this configuration? (Choose two.)

The correct answer is B. A session for denied traffic is created. D. The number of logs generated by denied traffic is reduced. The configuration shown typically includes 'set ses-denied-traffic enable' and 'set block-session-timer <seconds>'. Enabling ses-denied-traffic causes FortiGate to create a session entry even for traffic that is explicitly denied by policy (answer B). Once the session is…

Submitted by kevin_r· Apr 18, 2026Firewall policies and authentication

Question

An administrator has configured the following settings:

What are the two results of this configuration? (Choose two.)

Exhibit

FCP_FGT_AD-7.6 question #93 exhibit

Options

  • ADenied users are blocked for 30 minutes.
  • BA session for denied traffic is created.
  • CSession helpers are disabled for denied traffic.
  • DThe number of logs generated by denied traffic is reduced.

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    83% (20)
  • C
    4% (1)

Explanation

The configuration shown typically includes 'set ses-denied-traffic enable' and 'set block-session-timer <seconds>'. Enabling ses-denied-traffic causes FortiGate to create a session entry even for traffic that is explicitly denied by policy (answer B). Once the session is created and cached, subsequent packets matching the same denied flow are handled by the session table rather than re-evaluated by the policy engine-this means only the first packet generates a deny log entry, significantly reducing the volume of logs for repeated denied flows (answer D). Denied users are not blocked for 30 minutes by this setting, and session helpers are not disabled.

Topics

#Firewall policies#Traffic handling#Logging#Denied traffic

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice