Free Sales Ending Soon - 100% Valid FCP_FGT_AD-7.6 Exam Dumps with 45 Questions
Verified FCP_FGT_AD-7.6 dumps Q&As on your Network Security Exam Questions Certain Success!
NEW QUESTION # 11
Which two statements describe characteristics of automation stitches? (Choose two.)
- A. An automation stitch can have multiple triggers.
- B. Multiple actions can run in parallel.
- C. Triggers can involve external connectors.
- D. Actions involve only devices included in the Security Fabric.
Answer: B,C
Explanation:
Automation stitches can execute multiple actions concurrently (in parallel).
Triggers for automation stitches can come from external connectors beyond just Fortinet devices.
NEW QUESTION # 12
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)
- A. Both interfaces must have the interface role assigned.
- B. Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.
- C. Both interfaces must have IP addresses assigned.
- D. Both interfaces must have directly connected routes on the routing table.
Answer: C,D
Explanation:
Interfaces must have directly connected routes in the routing table to forward traffic correctly.
Interfaces must have IP addresses assigned to communicate within their respective networks.
NEW QUESTION # 13
Refer to the exhibit.
The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.
What must the administrator configure to answer this specific request from the NOC team?
- A. Move NOC_Access to the top of the list to ensure all profile settings take effect.
- B. Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.
- C. Increase the admintimeout value under config system accprofile NOC_Access.
- D. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access
Answer: C
Explanation:
The admintimeout setting in the admin access profile controls the inactivity timeout for GUI sessions. Increasing this value will extend the session duration before automatic disconnection.
NEW QUESTION # 14
An administrator notices that some users are unable to establish SSL VPN connections, while others can connect without any issues.
What should the administrator check first?
- A. Ensure that forced tunneling is enabled to reroute all traffic through the SSL VPN
- B. Ensure that the affected users are using the correct port number.
- C. Ensure that the HTTPS service is enabled on SSL VPN tunnel interface
- D. Ensure that user traffic is hitting the firewall policy.
Answer: D
Explanation:
If user traffic is not matching the appropriate firewall policy that permits SSL VPN, users will be unable to establish connections, making this the first aspect to verify.
NEW QUESTION # 15
You have created a web filter profile named restrict_media-profile with a daily category usage quota.
When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.
What could be the reason?
- A. The web filter profile is already referenced in another firewall policy.
- B. The firewall policy is in no-inspection mode instead of deep-inspection.
- C. The inspection mode in the firewall policy is not matching with web filter profile feature set.
- D. The naming convention used in the web filter profile is restricting it in the firewall policy.
Answer: C
Explanation:
Web filter profiles with category usage quotas require the firewall policy to be in proxy-based (deep) inspection mode; if the inspection mode does not match this requirement, the profile will not appear in the drop-down list.
NEW QUESTION # 16
You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked.
What FortiGate settings should you check to resolve this issue?
- A. Network Protocol Enforcement
- B. Application and Filter Overrides
- C. FortiGuard category ratings
- D. Replacement Messages for UDP-based Applications
Answer: A
Explanation:
Network Protocol Enforcement settings control how FortiGate inspects and enforces protocols on traffic, including peer-to-peer applications on known ports. If not properly enabled, peer-to-peer traffic may bypass blocking despite the application control profile.
NEW QUESTION # 17
Refer to the exhibits.
The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device.
Based on the system performance output, what are the two possible outcomes? (Choose two.)
- A. FortiGate drops new sessions.
- B. Administrators can change the configuration.
- C. FortiGate has entered conserve mode.
- D. Administrators can access FortiGate only through the console port.
Answer: A,B
Explanation:
Since memory usage is at 90%, exceeding the red threshold (88%), FortiGate enters a state where configuration changes are still allowed.
In this state, FortiGate drops new sessions to preserve resources and maintain stability.
NEW QUESTION # 18
Which two statements are correct when FortiGate enters conserve mode? (Choose two.)
- A. FortiGate continues to run critical security actions, such as quarantine.
- B. FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.
- C. FortiGate halts complete system operation and requires a reboot to regain available resources.
- D. FortiGate refuses to accept configuration changes.
Answer: B,D
Explanation:
In conserve mode, FortiGate restricts configuration changes to preserve system stability.
When IPS fail-open is enabled, FortiGate continues forwarding traffic without IPS inspection during resource constraints (conserve mode).
NEW QUESTION # 19
An administrator suspects that the Collector Agent is not forwarding login events to FortiGate.
What is the most effective troubleshooting step?
- A. Restart the domain controller to refresh authentication services.
- B. Check if TCP port 8000 is open between the collector agent and FortiGate.
- C. Verify if FortiGate is set to use LDAP authentication instead of FSSO.
- D. Verify if DC agent is enabled on the FortiGate.
Answer: B
Explanation:
The Collector Agent communicates with FortiGate over TCP port 8000. Ensuring this port is open and reachable is essential for forwarding login events.
NEW QUESTION # 20
Refer to the exhibits.
Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibit.
What would be the expected outcome in the HA cluster?
- A. HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.
- B. HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority.
- C. The HA cluster will become out of sync because the override setting must match on all HA members.
- D. HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.
Answer: A
Explanation:
With override enabled on HQ-NGFW-2 and its higher priority (110 vs. 90), HQ-NGFW-2 will become the primary device, preempting HQ-NGFW-1 despite the current primary status.
NEW QUESTION # 21
Refer to the exhibit.
What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?
- A. FortiGate will close the connection if the SNI does not match the CN or SAN fields.
- B. FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.
- C. FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.
- D. FortiGate will close the connection if the SNI does not match the CN and SAN fields
Answer: D
Explanation:
With the Server certificate SNI check set to Strict, FortiGate enforces that the SNI must match either the Common Name (CN) or Subject Alternative Name (SAN) in the server certificate; otherwise, it closes the connection.
NEW QUESTION # 22
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
- A. On HQ-NGFW, enable Diffie-Hellman Group 2.
- B. On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0
- C. On BR1-FGT, set Seconds to 43200.
- D. On HQ-NGFW. set Encryption to AES256
Answer: B,C
Explanation:
The key lifetime (Seconds) must match on both sides; BR1-FGT is set to 14400, so setting it to 43200 matches HQ-NGFW.
The remote address on BR1-FGT should match the HQ-NGFW's local subnet (10.0.11.0/24), but it is currently set incorrectly as 172.20.1.0/24. Changing it to 10.0.11.0/255.255.255.0 will align the Phase 2 selectors.
NEW QUESTION # 23
Refer to the exhibits.
The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects.
The WAN (port2) interface has the IP address 100.65.0.101/24.
The LAN (port4) interface has the IP address 10.0.11.254/24.
Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)
- A. 100.65.0.99
- B. 100.65.0.49
- C. 100.65.0.101
- D. 100.65.0.149
Answer: A
Explanation:
The ping traffic policy uses the IP pool named SNAT-Remote1, which has the external IP range 100.65.0.99. Therefore, traffic matching this policy (ping from HQ-PC-1 to BR1-FGT) will use 100.65.0.99 for source NAT.
NEW QUESTION # 24
You are analyzing connectivity problems caused by intermediate devices blocking traffic in SSL VPN environment.
In which two ways can you effectively resolve the problem? (Choose two.)
- A. You can turn off IKE fragmentation to fix large certificate negotiation problems.
- B. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP ports.
- C. You should use IPsec to solve issues with fragment drops and large certificate exchanges.
- D. You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 or 4500).
Answer: A,D
Explanation:
Disabling IKE fragmentation helps resolve issues caused by intermediate devices blocking large fragmented packets during certificate negotiation.
Using SSL VPN tunnel mode encapsulates traffic over HTTPS, bypassing blocks on ESP and UDP ports commonly used by IPsec.
NEW QUESTION # 25
An administrator wants to analyze and manage digital certificates to prevent browser warnings when users connect to the SSL VPN portal.
Which two statements describe how to correctly do this? (Choose two.)
- A. The administrator must disable HTTPS administrative access entirely to avoid certificate warnings.
- B. The administrator can rely on the default FortiGate self-signed certificate to prevent all security warnings in the browser.
- C. The administrator can use a publicly trusted certificate from a known certificate authority (CA) to stop browser warnings.
- D. The administrator can import the FortiGate self-signed certificate into each user's browser as a trusted certificate.
Answer: C,D
Explanation:
Using a publicly trusted certificate from a known CA prevents browser warnings without additional user action.
Importing the FortiGate self-signed certificate into users' browsers as trusted eliminates warnings caused by untrusted certificates.
NEW QUESTION # 26
Refer to the exhibit.
FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles.
Which action must the administrator perform to consolidate the two policies into one?
- A. Replace port1 and port2 with the any interface in a single firewall policy.
- B. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy.
- C. Create an Aggregate interface that includes port1 and port2 to create a single firewall policy.
- D. Select port1 and port2 subnets in a single firewall policy.
Answer: B
Explanation:
Enabling Multiple Interface Policies allows you to select multiple interfaces (like port1 and port2) in a single firewall policy, consolidating access rules for both Sales and Engineering to the web server.
NEW QUESTION # 27
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?
- A. Disabled
- B. On Idle
- C. On Demand
- D. Enabled
Answer: D
Explanation:
The "On Idle" DPD mode configures FortiGate to send DPD probes only when no inbound traffic is detected, meeting the requirement to send probes only when the tunnel is idle.
NEW QUESTION # 28
Refer to the exhibit.
Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
- A. Administrators cannot change the configuration.
- B. Administrators must restart FortiGate to allow new session.
- C. FortiGate drops new sessions requiring inspection.
- D. FortiGate skips quarantine actions.
Answer: C,D
Explanation:
In fail-open mode, FortiGate skips quarantine actions to maintain traffic flow despite IPS or antivirus failures.
FortiGate drops new sessions that require inspection when in conserve mode and fail-open is enabled, to protect the network from potentially harmful traffic.
NEW QUESTION # 29
......
FCP_FGT_AD-7.6 Exam Dumps - 100% Marks In FCP_FGT_AD-7.6 Exam: https://www.examslabs.com/Fortinet/Network-Security/best-FCP_FGT_AD-7.6-exam-dumps.html
Exam Dumps Use Real Network Security Dumps With 45 Questions: https://drive.google.com/open?id=1E57-A1swVyrFxoVolUsjTZ0_lJGX2VHq