Pass Fortinet FCP_FGT_AD-7.6 exam questions - convert Test Engine to PDF [Q29-Q46]

Share

Pass Fortinet FCP_FGT_AD-7.6 exam questions - convert Test Engine to PDF

Pass Your FCP_FGT_AD-7.6 Exam Easily - Real FCP_FGT_AD-7.6 Practice Dump Updated Dec 27, 2025

NEW QUESTION # 29
When configuring firewall policies which of the following is true regarding the policy ID?

  • A. It is mandatory to provide a policy ID while creating a firewall policy regardless of GUI or CLI.
  • B. A firewall policy ID identifies the order of policy execution in firewall policies.
  • C. You can create a policy in CLI with policy ID 0.
  • D. A policy ID cannot be edited once a policy is created.

Answer: D

Explanation:
Once a firewall policy is created, its policy ID is fixed and cannot be changed; this ID uniquely identifies the policy within the FortiGate configuration.


NEW QUESTION # 30
An administrator wants to form an HA cluster using the FGCP protocol.
Which two requirements must the administrator ensure both members fulfill? (Choose two.)

  • A. They must have the same number of configured VDOMs.
  • B. They must have the heartbeat interfaces in the same subnet.
  • C. They must have the same hard drive configuration.
  • D. They must have the same HA group ID.

Answer: C,D


NEW QUESTION # 31
An administrator needs to analyze and resolve port conflicts between SSL VPN and HTTPS administrative access on the same interface.
In which two ways can this be done? (Choose two.)

  • A. Disable SSL VPN if HTTPS administrative access is using port 443 on any interface.
  • B. Keep port 443 for both SSL VPN and HTTPS administrative access on the same interface without any problems.
  • C. Change the port number for either the SSL VPN service or the HTTPS administrative service if both are on the same interface.
  • D. Run SSL VPN on one interface using port 443 and enable HTTPS administrative access on a different interface, also using port 443.

Answer: C,D

Explanation:
You can keep port 443 for SSL VPN on one interface and also use port 443 for HTTPS admin access on a different interface. Since the services are bound to different interfaces, no conflict occurs.
If both SSL VPN and HTTPS admin access are required on the same interface, you must change the port number for one of the services to avoid a port conflict.


NEW QUESTION # 32
An administrator manages a FortiGate model that supports NTurbo.
How does NTurbo acceleration enhance antivirus performance?

  • A. For flow-based inspection, NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces.
  • B. For flow-based inspection, NTurbo creates two inspection sessions on the FortiGate device.
  • C. For proxy-based inspection, NTurbo buffers the whole file and then sends it to the antivirus engine.
  • D. For proxy-based inspection, NTurbo offloads traffic to the content processor.

Answer: A

Explanation:
With flow-based inspection, NTurbo improves antivirus performance by establishing a dedicated fast data path that redirects traffic between the IPS engine and the FortiGate ingress/egress interfaces. This reduces CPU overhead, allowing antivirus scanning to happen at higher throughput without requiring full proxy-based buffering.


NEW QUESTION # 33
Refer to the exhibits. An administrator configured both members of an HA cluster at the same time. After one week of monitoring, the administrator wants to verify the HA failover performance.
How can the administrator force a failover?

  • A. The administrator must set the parameter override to enable on HQ-NGFW-2.
  • B. The administrator must increase the HA priority on HQ-NGFW-2.
  • C. The administrator must set the monitored port to down on HQ-NGFW-1.
  • D. The administrator must reset the HA uptime on HQ-NGFW-1.

Answer: C

Explanation:
Both FortiGates are in an active-passive (a-p) HA cluster with override disabled. This means failover is triggered only if the primary (HQ-NGFW-1) becomes unavailable or monitored interfaces fail. To test failover performance, the administrator can set the monitored interface (port1) down on HQ-NGFW-1, which will force a failover to HQ-NGFW-2.


NEW QUESTION # 34
What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device?
(Choose two.)

  • A. The heartbeat interface of the primary device in the cluster is always assigned IP address
    169.254.0.1.
  • B. Heartbeat IP addresses are used to distinguish between cluster members.
  • C. Heartbeat interfaces have virtual IP addresses that are manually assigned.
  • D. A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster.

Answer: B,D

Explanation:
Heartbeat IP addresses are used to distinguish between cluster members → Each FortiGate in the HA cluster uses unique heartbeat IPs so members can identify one another.
A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster → Heartbeat IPs are dynamically reassigned when the cluster membership changes to maintain proper communication.


NEW QUESTION # 35
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode.
Which step is NOT part of the expected process?

  • A. The collector agent forwards login event data to FortiGate.
  • B. The user logs into the windows domain.
  • C. The DC agent sends login event data directly to FortiGate.
  • D. FortiGate determines user identity based on the IP address in the FSSO list.

Answer: C

Explanation:
In DC Agent mode, the DC agent installed on the Domain Controller captures the logon events (e.g., Event ID 4624) in real-time. It then pushes this information to the Collector Agent. The Collector Agent, which runs as a service on a dedicated machine, is responsible for consolidating this information and then forwarding it to the FortiGate firewall. The FortiGate receives this data and uses the user's IP address to apply appropriate security policies.


NEW QUESTION # 36
Refer to the exhibit.

What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?

  • A. FortiGate will close the connection if the SNI does not match the CN or SAN fields.
  • B. FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields.
  • C. FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields.
  • D. FortiGate will close the connection if the SNI does not match the CN and SAN fields

Answer: D

Explanation:
With the Server certificate SNI check set to Strict, FortiGate enforces that the SNI must match either the Common Name (CN) or Subject Alternative Name (SAN) in the server certificate; otherwise, it closes the connection.


NEW QUESTION # 37
You want to ensure that an SSL VPN user's authenticated session does not remain active after they disconnect from the VPN.
Which configuration will ensure this?

  • A. Manually clear active firewall authentication sessions after a user disconnects.
  • B. Configure the firewall authentication session timeout to be lower than the SSL VPN session timeout.
  • C. Enable settings to force the firewall authentication session to end when the SSL VPN session ends
  • D. Increase the SSL VPN idle timeout to reduce the chance of early disconnections.

Answer: C

Explanation:
Firewall policy authentication session is associated with SSL VPN tunnel session.
Firewall policy authentication session is forced to end when SSL VPN tunnel session ends.
Prevents reuse of authenticated SSL VPN firewall sessions (not yet expired) by a different user, after the initial user terminates the SSL VPN tunnel session.


NEW QUESTION # 38
Which inspection mode does FortiGate use for application profiles if it is configured as a profile- based next-generation firewall (NGFW)?

  • A. Flow-based inspection
  • B. Proxy-based inspection
  • C. Full content inspection
  • D. Certificate inspection

Answer: B

Explanation:
When FortiGate operates in profile-based NGFW mode, it supports both flow-based and proxy- based inspection for security profiles. However, application profiles (such as Application Control, Web Filter, and Antivirus) are inspected using proxy-based inspection by default in profile-based mode, as this mode allows FortiGate to fully analyze and enforce policies on the application content layer.


NEW QUESTION # 39
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?

  • A. NetAPI polling can increase bandwidth usage in large networks.
  • B. The NetSessionEnum function is used to track user logouts.
  • C. The collector agent must search Windows application event logs.
  • D. The collector agent uses a Windows API to query DCs for user logins.

Answer: B


NEW QUESTION # 40
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.
What is the reason for the certificate warning errors?

  • A. The matching firewall policy is set to proxy inspection mode.
  • B. The option invalid SSL certificates is set to allow on the SSL/SSH inspection profile
  • C. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
  • D. The browser does not trust the certificate used by FortiGate for SSL inspection.

Answer: D

Explanation:
When full SSL inspection is enabled, FortiGate decrypts and re-signs HTTPS traffic using its own SSL inspection certificate. If the FortiGate CA certificate is not imported and trusted by the client's browser or OS, the browser sees it as untrusted and displays certificate warning errors. HTTP traffic is unaffected since it does not use certificates.


NEW QUESTION # 41
An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled.
However, the static route is not showing in the routing table.
Which two statements about this scenario are correct? (Choose two.)

  • A. The administrator must define the remote network correctly in the phase 2 selectors.
  • B. The administrator must enable a dynamic routing protocol on the dialup interface.
  • C. The administrator must use a policy route instead of a static route for add-route to work properly.
  • D. The administrator must ensure phase 2 is successfully established.

Answer: A,D

Explanation:
The administrator must ensure phase 2 is successfully established → The static route for the dialup VPN is only added after Phase 2 negotiation completes successfully.
The administrator must define the remote network correctly in the phase 2 selectors → The add- route feature installs a route based on the Phase 2 selectors; if they are incorrect, no route will appear in the routing table.


NEW QUESTION # 42
Refer to the exhibit.

The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.
What must the administrator configure to answer this specific request from the NOC team?

  • A. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access
  • B. Increase the admintimeout value under config system accprofile NOC_Access.
  • C. Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.
  • D. Move NOC_Access to the top of the list to ensure all profile settings take effect.

Answer: B

Explanation:
The admintimeout setting in the admin access profile controls the inactivity timeout for GUI sessions.
Increasing this value will extend the session duration before automatic disconnection.


NEW QUESTION # 43
Refer to the exhibit, which shows a routing table.

An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only.
What are the two criteria that the administrator can use to achieve this objective? (Choose two.)

  • A. The new static route must have the metric set to 1.
  • B. The new static route must have the distance set to 9.
  • C. The new static route must have the priority set to 3.
  • D. The existing static route through port3 must have the distance set to 11.

Answer: B,D


NEW QUESTION # 44
Refer to the exhibits.

An administrator wants to add HQ-ISFW-2 in the Security Fabric. HQ-ISFW-2 is in the same subnet as HQ-ISFW. After configuring the Security Fabric settings on HQ-ISFW-2, the status stays Pending.
What can be the two possible reasons? (Choose two.)

  • A. HQ-ISFW-2 must be authorized on HQ-ISFW.
  • B. Management IP must be set to 10.0.13.254.
  • C. Upstream FortiGate IP must be set to 10.0.11.254.
  • D. SAML Single Sign-On must be set to Manual.

Answer: A,C

Explanation:
The Upstream FortiGate IP should match the IP address of the Fabric Root interface, which is 10.0.11.254, not 10.0.13.254.
The new device (HQ-ISFW-2) must be authorized on the Fabric Root (HQ-ISFW) before it can join the Security Fabric, otherwise the status remains pending.


NEW QUESTION # 45
Refer to the exhibit.

Which two statements are true about the routing entries in this database table? (Choose two.)

  • A. All of the entries in the routing database table are installed in the FortiGate routing table.
  • B. The port2 interface is marked as inactive.
  • C. The default route on port2 is marked as the standby route.
  • D. Both default routes have different administrative distances.

Answer: C,D

Explanation:
The routing table in the exhibit shows two default routes (0.0.0.0/0) with different administrative distances:
* The default route through port2 has an administrative distance of 20.
* The default route through port1 has an administrative distance of 10.
Administrative distance determines the priority of the route; a lower value is preferred. Here, the route through port1 with an administrative distance of 10 is the preferred route. The route through port2 with an administrative distance of 20 acts as a standby or backup route. If the primary route (port1) fails or is unavailable, traffic will then be routed through port2.
Regarding the statement that the port2 interface is marked as inactive, there is no indication in the routing table that port2 is inactive. Similarly, all the routes displayed are not necessarily installed in the FortiGate routing table, as the table could include both active and backup routes.
References:
FortiOS 7.4.1 Administration Guide: Default route configuration
FortiOS 7.4.1 Administration Guide: Routing table explanation


NEW QUESTION # 46
......

FCP_FGT_AD-7.6 Real Exam Questions and Answers FREE: https://www.dumpsactual.com/FCP_FGT_AD-7.6-actualtests-dumps.html

2025 Realistic Verified Free Fortinet FCP_FGT_AD-7.6 Exam Questions: https://drive.google.com/open?id=1BHBHwyXxcjXzEAUvA0s1kh2nidpTswqy