FCSS_EFW_AD-7.4 Exam Questions
78 real FCSS_EFW_AD-7.4 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1FortiGate-VM Configuration in Azure
Refer to the exhibit, which shows an ADVPN network. An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2. What two options must the admi...
ADVPNBGPebgp-enforce-multihopnext-hop-self - Question #2FortiGate-VM Configuration in Azure
Refer to the exhibit, which contains the partial output of an OSPF command. An administrator is checking the OSPF status of a FortiGate device and receives the output shown in the...
OSPFASBRmulti-area routingexternal routes - Question #3FortiGate-VM Configuration in Azure
The IT department discovered during the last network migration that all zero phase selectors in phase 2 IPsec configurations impacted network operations. What are two valid approac...
IPsecphase 2 selectorsVPN migrationrouting protocols - Question #4FortiGate-VM Configuration in Azure
How will configuring set tcp-mss-sender and set tcp-mss-receiver in a firewall policy affect the size and handling of TCP packets in the network?
TCP MSSfirewall policypacket handlingTCP optimization - Question #5FortiGate-VM Configuration in Azure
A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server....
SSL/TLS inspectionSSL inspection profileweak cipherHTTPS security - Question #6FortiGate-VM Configuration in Azure
Refer to the exhibit, which contains the partial output of an OSPF command. An administrator is checking the OSPF status of a FortiGate device and receives the output shown in the...
OSPFASBRexternal routingFortiGate status - Question #7FortiGate-VM Configuration in Azure
An administrator is setting up an ADVPN configuration and wants to ensure that peer IDs are not exposed during VPN establishment. Which protocol can the administrator use to enhanc...
ADVPNIKEv2peer ID encryptionVPN security - Question #8FortiGate-VM Configuration in Azure
An administrator must minimize CPU and RAM use on a FortiGate firewall while also enabling essential security features, such as web filtering and application control for HTTPS traf...
SSL certificate inspectionweb filteringapplication controlperformance optimization - Question #9Centralized Management and Logging
An administrator must standardize the deployment of FortiGate devices across branches with consistent interface roles and policy packages using FortiManager. What is the recommende...
FortiManagermetadata variablespolicy packageinterface assignment - Question #10FortiGate-VM Configuration in Azure
Refer to the exhibit, which shows an enterprise network connected to an internet service provider. An administrator must configure a loopback as a BGP source to connect to the ISP....
BGPloopback interfaceebgp-multihopupdate-source - Question #11FortiGate-VM Configuration in Azure
What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on network transmission patterns and application signatures?
IPSapplication controlprotocol decodersapplication signatures - Question #12FortiGate-VM Configuration in Azure
An administrator is designing an ADVPN network for a large enterprise with spokes that have varying numbers of internet links. They want to avoid a high number of routes and peer c...
ADVPNdynamic routingloopback interfaceshub-and-spoke - Question #13VPN
Refer to the exhibit, which shows the ADVPN IPsec interface representing the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub to Spoke 3 and Spoke 4. An administra...
ADVPNIPsec phase 1IBGP/EBGP crossoverauto-discovery-crossover - Question #14High Availability and Clustering
A FortiGate device with UTM profiles is reaching the resource limits, and the administrator expects the traffic in the enterprise network to increase. The administrator has receive...
FGSPFGCP active-activehigh availabilityload balancing - Question #15Routing
Refer to the exhibit. The routing tables of FortiGate_A and FortiGate_B are shown. FortiGate_A and FortiGate_B are in the same autonomous system. The administrator wants to dynamic...
BGProute-maproute advertisementIBGP - Question #16VPN
Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and site...
IPsec hub-and-spokeECMProute-overlapoverlapping subnets - Question #17Routing
An administrator wants to scale the IBGP sessions and optimize the routing table in an IBGP network. Which parameter should the administrator configure?
IBGProute reflectorBGP scalingroute-reflector-client - Question #18System and Network Configuration
Refer to the exhibits. The configuration of a user's Windows PC, which has a default MTU of 1500 bytes, along with FortiGate interfaces set to an MTU of 1000 bytes, and the results...
MTUDF bitpath MTU discoverypacket fragmentation - Question #19Infrastructure and Integration
Refer to the exhibit, which shows the VDOM section of a FortiGate device. An administrator discovers that webfilter stopped working in Core1 and Core2 after a maintenance window. W...
VDOMweb filterFortiGuard FDNVDOM link - Question #20Routing
Refer to the exhibit. An administrator is deploying a hub and spokes network and using OSPF as dynamic protocol. Which configuration is mandatory for neighbor adjacency?
OSPFhub-and-spokepoint-to-multipointneighbor adjacency - Question #21Infrastructure and Integration
A company that acquired multiple branches across different countries needs to install new FortiGate devices on each of those branches. However, the IT staff lacks sufficient knowle...
FortiManagerZTPprovisioning templatesmetadata variables - Question #22High Availability and Clustering
An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23:ff:fc:00:86. What two conclusions can the administrator draw? (Choose two...
FGCPHA clusterMAC address analysisVDOM - Question #23Security Profiles
A company's guest internet policy, operating in proxy mode, blocks access to Artificial Intelligence Technology sites using FortiGuard. However, a guest user accessed a page in thi...
SSL inspectionnonstandard portsprotocol port mappingweb filter - Question #24Security Profiles
An administrator needs to install an IPS profile without triggering false positives that can impact applications and cause problems with the user's normal traffic flow. Which actio...
IPSfalse positivesIPS profile tuningapplication filtering - Question #25Routing
Refer to the exhibit, which shows a hub and spokes deployment. An administrator is deploying several spokes, including the BGP configuration for the spokes to connect to the hub. W...
BGPneighbor-groupneighbor-rangehub-and-spoke - Question #26Security Profiles
Why does the ISDB block layers 3 and 4 of the OSI model when applying content filtering? (Choose two.)
ISDBInternet Service Databasecontent filteringFortiGuard - Question #27Infrastructure and Integration
Refer to the exhibits. The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown. When prompted to s...
Security FabricSSOadmin privilegesdownstream FortiGate - Question #28Security Profiles
A user reports that their computer was infected with malware after accessing a secured HTTPS website. However, when the administrator checks the FortiGate logs, they do not see tha...
SSL inspectionfull SSL inspectionHTTPSmalware detection - Question #29Routing
Refer to the exhibit, which contains a partial command output. The administrator has configured BGP on FortiGate. The status of this new BGP configuration is shown in the exhibit....
BGPebgp-enforce-multihopBGP neighbor troubleshootingmultihop EBGP - Question #30System and Network Configuration
Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud. What two conclusions can you draw from the exhibit? (...
TLS handshakewildcard certificateFortiManager Cloudpacket capture analysis - Question #31Infrastructure and Integration
Refer to the exhibit, which shows a LAN interface connected from FortiGate to two FortiSwitch devices. What two conclusions can you draw from the corresponding LAN interface? (Choo...
FortiSwitchFortiLinkMCLAG802.3ad aggregation - Question #32High Availability and Clustering
Refer to the exhibit, which shows the HA status of an active-passive cluster. An administrator wants FortiGate_B to handle the Core2 VDOM traffic. Which modification must the admin...
HA active-passiveVDOM trafficcluster priorityoverride - Question #33Hardware Acceleration
During the maintenance window, an administrator must sniff all the traffic going through a specific firewall policy, which is handled by NP6 interfaces. The output of the sniffer t...
NP6 offloadingpacket sniffingauto-asic-offloadfirewall policy - Question #34Advanced Routing
Refer to the exhibit, which shows a network diagram. An administrator would like to modify the MED value advertised from FortiGate_1 to a BGP neighbor in the autonomous system 30....
BGPMED attributeroute-map-outeBGP policy - Question #35Security Profiles
An administrator received a FortiAnalyzer alert that a 1 disk filled up in a day. Upon investigation, they found thousands of unusual DNS log requests, such as JHCMQK.website.com,...
DNS exfiltrationIPS signaturesDNS over TLSdata exfiltration prevention - Question #36Security Fabric
An administrator configured the FortiGate devices in an enterprise network to join the Fortinet Security Fabric. The administrator has a list of IP addresses that must be blocked b...
external threat feedsdynamic address objectsSecurity Fabric automationIP blocklist - Question #37Advanced Routing
Refer to the exhibit, which shows an OSPF network. Which configuration must the administrator apply to optimize the OSPF database?
OSPFstub areaarea border routerOSPF database optimization - Question #38Transparent Mode and VDOMs
What does the command set forward-domain <domain_ID> in a transparent VDOM interface do?
transparent VDOMforward-domainbroadcast domain isolationVLAN segmentation - Question #39Security Fabric
Refer to the exhibit, which shows a physical topology and a traffic log. The administrator is checking on FortiAnalyzer traffic from the device with IP address 10.1.10.1, located b...
Security Fabric loggingFortiAnalyzerUTM propagationISFW - Question #40IPsec VPN
Refer to the exhibit, which contains a partial VPN configuration. What can you conclude from this VPN IPsec phase 1 configuration?
IPsec Phase 1dial-up VPNaggressive modeVPN configuration analysis - Question #41IPsec VPN
A company's users on an IPsec VPN between FortiGate A and B have experienced intermittent issues since implementing VXLAN. The administrator suspects that packets exceeding the 150...
MTUVXLAN overheadIPsec fragmentationjumbo frames - Question #42High Availability
Refer to the exhibit, which shows a command output. FortiGate_A and FortiGate_B are members of an FGSP cluster in an enterprise network. While testing the cluster using the ping co...
FGSPsession-pickup-connectionlesscluster session syncstateless traffic - Question #43Hardware Acceleration
Refer to the exhibit, which shows a partial troubleshooting command output. An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the o...
IPsec SANPU offloadingNP accelerationinbound outbound SA - Question #44IPsec VPN
Refer to the exhibit, which shows a corporate network and a new remote office network. An administrator must integrate the new remote office network with the corporate enterprise n...
OSPF over IPsecremote office integrationdynamic routing over VPNnetwork design - Question #45Advanced Routing
Refer to the exhibit, which shows an enterprise network connected to an internet service provider. The administrator must configure the BGP section of FortiGate A to give internet...
BGPneighbor configurationeBGP peeringISP connectivity - Question #46IPsec VPN
Refer to the exhibit, which shows an ADVPN network. The client behind Spoke-1 generates traffic to the device located behind Spoke-2. What is the first message that the hub sends t...
ADVPNshortcut offerhub-spoke VPNdynamic tunnel establishment - Question #47Hardware Acceleration
What is the initial step performed by FortiGate when handling the first packets of a session?
packet processing pipelineACL checkIP integritysession first packet - Question #48Security Profiles
An administrator applied a block-all IPS profile for client and server targets to secure the server, but the database team reported the application stopped working immediately afte...
IPS profilemonitor modefalse positive managementapplication protection - Question #49Hardware Acceleration
An administrator is extensively using VXLAN on FortiGate. Which specialized acceleration hardware does FortiGate need to improve its performance?
NP7VXLAN accelerationnetwork processorhardware offload - Question #50Advanced Routing
Refer to the exhibit, which shows a partial enterprise network. An administrator would like the area 0.0.0.0 to detect the external network. What must the administrator configure?
OSPF redistributionRIPexternal route injectionarea 0 visibility