nerdexam
Fortinet

FCSS_EFW_AD-7.6 · Question #75

An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode. Which two actions must the administrator take? (Choose two.)

The correct answer is B. Configure central source network address translation (SNAT), if NAT is required. D. Specify an SSLISSH inspection profile on a consolidated policy. In FortiGate's NGFW policy-based mode, NAT is not configured inline within individual firewall policies - instead, it is handled separately via central SNAT policies (B). Additionally, policy-based mode uses consolidated policies (combining IPv4/IPv6), and an SSL/SSH inspection…

Advanced Threat Protection

Question

An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode. Which two actions must the administrator take? (Choose two.)

Options

  • AConfigure the action as quarantine, if an application requires feedback to prevent instability.
  • BConfigure central source network address translation (SNAT), if NAT is required.
  • CCreate an application control profile and apply the profile to a firewall policy.
  • DSpecify an SSLISSH inspection profile on a consolidated policy.

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    74% (25)
  • C
    18% (6)

Explanation

In FortiGate's NGFW policy-based mode, NAT is not configured inline within individual firewall policies - instead, it is handled separately via central SNAT policies (B). Additionally, policy-based mode uses consolidated policies (combining IPv4/IPv6), and an SSL/SSH inspection profile is mandatory on these policies for application identification to function correctly on encrypted traffic (D).

Why the distractors are wrong:

  • A is incorrect - quarantine is not the recommended action for applications requiring feedback; this describes an unrelated use case and is not a required configuration step in this mode.
  • C is incorrect - creating an application control profile and attaching it to a policy is the workflow for profile-based mode, not policy-based mode. In policy-based mode, application visibility is built directly into the consolidated policy without a separate profile.

Memory tip: Think of policy-based mode as "centralized and consolidated" - NAT goes to a central SNAT table, and traffic policies are consolidated (hence needing the SSL/SSH profile there). If you remember those two "C" words, B and D follow naturally.

Topics

#application control#NGFW policy-based mode#SSL inspection#consolidated policy

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.6 Practice