Enhance your career with FCP_FGT_AD-7.6 PDF Dumps - True Fortinet Exam Questions
New (2025) Download free FCP_FGT_AD-7.6 PDF for Fortinet Practice Tests
Fortinet FCP_FGT_AD-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 24
Refer to the exhibit.
The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.
What must the administrator configure to answer this specific request from the NOC team?
- A. Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.
- B. Increase the admintimeout value under config system accprofile NOC_Access.
- C. Move NOC_Access to the top of the list to ensure all profile settings take effect.
- D. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access
Answer: B
Explanation:
The admintimeout setting in the admin access profile controls the inactivity timeout for GUI sessions. Increasing this value will extend the session duration before automatic disconnection.
NEW QUESTION # 25
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
- A. On HQ-NGFW. set Encryption to AES256
- B. On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0
- C. On BR1-FGT, set Seconds to 43200.
- D. On HQ-NGFW, enable Diffie-Hellman Group 2.
Answer: B,C
Explanation:
The key lifetime (Seconds) must match on both sides; BR1-FGT is set to 14400, so setting it to 43200 matches HQ-NGFW.
The remote address on BR1-FGT should match the HQ-NGFW's local subnet (10.0.11.0/24), but it is currently set incorrectly as 172.20.1.0/24. Changing it to 10.0.11.0/255.255.255.0 will align the Phase 2 selectors.
NEW QUESTION # 26
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)
- A. Both interfaces must have the interface role assigned.
- B. Both interfaces must have IP addresses assigned.
- C. Both interfaces must have directly connected routes on the routing table.
- D. Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.
Answer: B,C
Explanation:
Interfaces must have directly connected routes in the routing table to forward traffic correctly.
Interfaces must have IP addresses assigned to communicate within their respective networks.
NEW QUESTION # 27
Refer to the exhibit.
As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?
- A. Administrator entered the command diagnose test application ipsmonitor 99.
- B. Administrator entered the command diagnose test application ipsmonitor 5.
- C. FortiGate entered into IPS fail open state.
- D. There is a no firewall policy configured with an IPS security profile.
Answer: D
Explanation:
The output shows the IPS engine count as 0, indicating no active IPS engines are running. This typically means no firewall policy is referencing the IPS security profile, so the IPS profile is not being applied or triggered.
NEW QUESTION # 28
An administrator wanted to configure an IPS sensor to block traffic that triggers a signature set number of times during a specific time period.
How can the administrator achieve the objective?
- A. Use IPS filter, rate-mode periodical option.
- B. Use IPS group signatures, set rate-mode 60.
- C. Use IPS filter, rate-mode periodical option.
- D. Use IPS packet logging option with periodical filter option.
Answer: C
Explanation:
The IPS filter with the rate-mode set to "periodical" allows the administrator to block traffic that triggers a signature a specified number of times within a defined time period, meeting the requirement.
NEW QUESTION # 29
Refer to the exhibits.
An administrator wants to add HQ-ISFW-2 in the Security Fabric. HQ-ISFW-2 is in the same subnet as HQ-ISFW. After configuring the Security Fabric settings on HQ-ISFW-2, the status stays Pending.
What can be the two possible reasons? (Choose two.)
- A. SAML Single Sign-On must be set to Manual.
- B. Upstream FortiGate IP must be set to 10.0.11.254.
- C. HQ-ISFW-2 must be authorized on HQ-ISFW.
- D. Management IP must be set to 10.0.13.254.
Answer: B,C
Explanation:
The Upstream FortiGate IP should match the IP address of the Fabric Root interface, which is 10.0.11.254, not 10.0.13.254.
The new device (HQ-ISFW-2) must be authorized on the Fabric Root (HQ-ISFW) before it can join the Security Fabric, otherwise the status remains pending.
NEW QUESTION # 30
You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked.
What FortiGate settings should you check to resolve this issue?
- A. FortiGuard category ratings
- B. Network Protocol Enforcement
- C. Application and Filter Overrides
- D. Replacement Messages for UDP-based Applications
Answer: B
Explanation:
Network Protocol Enforcement settings control how FortiGate inspects and enforces protocols on traffic, including peer-to-peer applications on known ports. If not properly enabled, peer-to-peer traffic may bypass blocking despite the application control profile.
NEW QUESTION # 31
What is the primary FortiGate election process when the HA override setting is enabled?
- A. Connected monitored ports > HA uptime > Priority > FortiGate serial number
- B. Connected monitored ports > Priority > System uptime > FortiGate serial number
- C. Connected monitored ports > System uptime > Priority > FortiGate serial number
- D. Connected monitored ports > Priority > HA uptime > FortiGate serial number
Answer: D
Explanation:
When HA override is enabled, FortiGate uses the following election order: number of connected monitored ports, then device priority, followed by HA uptime, and finally FortiGate serial number as a tiebreaker.
NEW QUESTION # 32
An administrator notices that some users are unable to establish SSL VPN connections, while others can connect without any issues.
What should the administrator check first?
- A. Ensure that the HTTPS service is enabled on SSL VPN tunnel interface
- B. Ensure that the affected users are using the correct port number.
- C. Ensure that forced tunneling is enabled to reroute all traffic through the SSL VPN
- D. Ensure that user traffic is hitting the firewall policy.
Answer: D
Explanation:
If user traffic is not matching the appropriate firewall policy that permits SSL VPN, users will be unable to establish connections, making this the first aspect to verify.
NEW QUESTION # 33
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI.
Based on the exhibit, which statement is true?
- A. port2 and port3 are not assigned to a zone.
- B. The Underlay zone is the zone by default.
- C. The Underlay zone contains no member.
- D. The virtual-wan-link and overlay zones can be deleted.
Answer: B
Explanation:
The Underlay zone is the default SD-WAN zone, typically representing the physical interfaces in the SD-WAN configuration before overlay or virtual links are added.
NEW QUESTION # 34
Which three statements explain a flow-based antivirus profile? (Choose three.)
- A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
- B. FortiGate buffers the whole file but transmits to the client at the same time.
- C. Flow-based inspection optimizes performance compared to proxy-based inspection.
- D. If a virus is detected, the last packet is delivered to the client.
- E. The IPS engine handles the process as a standalone.
Answer: A,B,C
Explanation:
Flow-based antivirus buffers the entire file while simultaneously transmitting data to the client to minimize latency.
Flow-based inspection combines multiple scanning techniques from proxy-based modes for efficient detection.
Flow-based inspection provides better performance by processing traffic on the fly without full proxy overhead.
NEW QUESTION # 35
Refer to the exhibit.
The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.
An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)
- A. Configure a separate firewall policy with action Deny and an FQDN address object for*.download.com as destination address.
- B. Set the Freeware and Software Downloads category Action to Warning.
- C. Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
- D. Configure a web override rating for download.com and select Malicious Websites as the subcategory.
Answer: A,C
Explanation:
Creating a static URL filter to block download.com specifically allows blocking that site without affecting the entire category.
Using a separate firewall policy with a Deny action for an FQDN address object matching download.com can also block the site while allowing others in the same category.
NEW QUESTION # 36
Refer to the exhibit.
An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow. This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times.
Why are there no logs generated under security logs for ABC.Com?
- A. The ABC.Com Type is set as Application instead of Filter.
- B. The ABC.Com is hitting the category Excessive-Bandwidth.
- C. The ABC.Com Action is set to Allow.
- D. The ABC.Com is configured under application profile, which must be configured as a web filter profile.
Answer: C
Explanation:
When the action is set to Allow in an application override, traffic matching this override is allowed without generating security logs because it bypasses deeper inspection and blocking.
NEW QUESTION # 37
Refer to the exhibits.
Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibit.
What would be the expected outcome in the HA cluster?
- A. HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.
- B. The HA cluster will become out of sync because the override setting must match on all HA members.
- C. HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority.
- D. HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.
Answer: A
Explanation:
With override enabled on HQ-NGFW-2 and its higher priority (110 vs. 90), HQ-NGFW-2 will become the primary device, preempting HQ-NGFW-1 despite the current primary status.
NEW QUESTION # 38
A network administrator is reviewing firewall policies in both Interface Pair View and By Sequence View. The policies appear in a different order in each view.
Why is the policy order different in these two views?
- A. Policies in Interface Pair View are prioritized by security levels, while By Sequence View strictly follows the administrator's manual ordering.
- B. The firewall dynamically reorders policies in Interface Pair View based on recent traffic patterns, but By Sequence View remains static.
- C. Interface Pair View sorts policies based on matching interfaces, while By Sequence View shows the actual processing order of rules.
- D. By Sequence View groups policies based on rule priority, while Interface Pair View always follows the order of traffic logs.
Answer: C
Explanation:
Interface Pair View organizes policies grouped by source and destination interfaces, whereas By Sequence View displays policies in the exact order they are processed by the firewall.
NEW QUESTION # 39
Refer to the exhibit.
Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
- A. Administrators must restart FortiGate to allow new session.
- B. FortiGate drops new sessions requiring inspection.
- C. FortiGate skips quarantine actions.
- D. Administrators cannot change the configuration.
Answer: B,C
Explanation:
In fail-open mode, FortiGate skips quarantine actions to maintain traffic flow despite IPS or antivirus failures.
FortiGate drops new sessions that require inspection when in conserve mode and fail-open is enabled, to protect the network from potentially harmful traffic.
NEW QUESTION # 40
A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy.
When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded.
The administrator confirms that the traffic matches the configured firewall policy.
What are two reasons for the failed virus detection by FortiGate? (Choose two.)
- A. The browser does not trust the FortiGate self-signed CA certificate.
- B. The El CAR test file exceeds the protocol options oversize limit.
- C. The website is exempted from SSL inspection.
- D. The selected SSL inspection profile has certificate inspection enabled.
Answer: A,C
NEW QUESTION # 41
What are three key routing principles in SD-WAN? (Choose three.)
- A. By default. SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination.
- B. By default. SD-WAN rules are skipped if only one route to the destination is available.
- C. By default. SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
- D. SD-WAN rules have precedence over any other type of routes.
- E. Regular policy routes have precedence over SD-WAN rules.
Answer: A,C,D
Explanation:
SD-WAN rules are skipped if none of the SD-WAN members have a valid route to the destination.
SD-WAN rules take precedence over other route types.
SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member by default.
NEW QUESTION # 42
......
100% Free FCP_FGT_AD-7.6 Files For passing the exam Quickly: https://www.vcetorrent.com/FCP_FGT_AD-7.6-valid-vce-torrent.html
FCP_FGT_AD-7.6 Dumps Questions Study Exam Guide : https://drive.google.com/open?id=1DaMQDyupp4M7p3wPJWl4oH_-SDfCQtoN