nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #98

Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. Which two actions would you take to resolve the issue? (Choose two.)

The correct answer is A. Move up Google in the Application and Filter Overrides section to set its priority to 1. E. Set SSL inspection to deep-content inspection. Move up Google in the Application and Filter Overrides section to set its priority to 1. The “Excessive-Bandwidth” filter has a higher priority (1) and is configured to Block. Because Google applications generate significant bandwidth, they match this rule first and get…

Submitted by brentm· Apr 18, 2026Content inspection

Question

Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. Which two actions would you take to resolve the issue? (Choose two.)

Exhibits

FCP_FGT_AD-7.6 question #98 exhibit 1
FCP_FGT_AD-7.6 question #98 exhibit 2

Options

  • AMove up Google in the Application and Filter Overrides section to set its priority to 1.
  • BSet the action for Google in the Application and Filter Overrides section to Allow.
  • CAdd Google.com to the URL category in the security profile.
  • DChange the Inspection mode to Flow-based.
  • ESet SSL inspection to deep-content inspection.

How the community answered

(58 responses)
  • A
    84% (49)
  • B
    9% (5)
  • C
    3% (2)
  • D
    3% (2)

Explanation

Move up Google in the Application and Filter Overrides section to set its priority to 1. The “Excessive-Bandwidth” filter has a higher priority (1) and is configured to Block. Because Google applications generate significant bandwidth, they match this rule first and get blocked. Moving the “Google” filter to priority 1 ensures that the monitor action for Google is applied before Set SSL inspection to deep-content inspection. Google applications use HTTPS encryption, so the FortiGate cannot identify or control them unless SSL traffic is decrypted. Changing from certificate-inspection (which only inspects certificates) to deep-inspection allows FortiGate to fully analyze encrypted application traffic and properly apply the Application Control rules.

Topics

#Application Control#SSL Inspection#Policy Priority#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice