[Nov-2024] Download Real Fortinet FCP_FGT_AD-7.4 Exam Dumps Test Engine Exam Questions
New FCP_FGT_AD-7.4 exam dumps Use Updated Fortinet Exam
NEW QUESTION # 28
Which three settings and protocols can be used to provide secure and restrictive administrative access to FortiGate? (Choose three.)
- A. HTTPS
- B. FortiTelemetry
- C. Trusted host
- D. SSH
- E. Trusted authentication
Answer: A,C,D
Explanation:
To provide secure and restrictive administrative access to FortiGate, the following three settings and protocols can be used:
A. SSH (Secure Shell)
SSH is a secure protocol that allows secure remote access to the FortiGate command-line interface (CLI).
C. Trusted host
Configuring trusted hosts allows you to restrict administrative access to specified IP addresses, providing an additional layer of security.
D. HTTPS (Hypertext Transfer Protocol Secure)
HTTPS is a secure protocol that enables secure access to the FortiGate web-based graphical user interface (GUI).
So, the correct choices are A, C, and D.
NEW QUESTION # 29
Refer to the exhibit.
Which two statements are true about the routing entries in this database table? (Choose two.)
- A. All of the entries in the routing database table are installed in the FortiGate routing table.
- B. The default route on porc2 is marked as the standby route.
- C. Both default routes have different administrative distances.
- D. The port2 interface is marked as inactive.
Answer: B,C
Explanation:
The routing table in the exhibit shows two default routes (0.0.0.0/0) with different administrative distances:
* The default route through port2 has an administrative distance of 20.
* The default route through port1 has an administrative distance of 10.
Administrative distance determines the priority of the route; a lower value is preferred. Here, the route through port1 with an administrative distance of 10 is the preferred route. The route through port2 with an administrative distance of 20 acts as a standby or backup route. If the primary route (port1) fails or is unavailable, traffic will then be routed through port2.
Regarding the statement that the port2 interface is marked as inactive, there is no indication in the routing table that port2 is inactive. Similarly, all the routes displayed are not necessarily installed in the FortiGate routing table, as the table could include both active and backup routes.
References:
* FortiOS 7.4.1 Administration Guide: Default route configuration
* FortiOS 7.4.1 Administration Guide: Routing table explanation
NEW QUESTION # 30
If the Issuer and Subject values are the same in a digital certificate, to which type of entity was the certificate issued?
- A. A user
- B. A CRL
- C. A root CA
- D. A subordinate CA
Answer: C
Explanation:
If the Issuer and Subject values are the same in a digital certificate, it typically indicates that the certificate is a self-signed certificate.
Therefore, the correct answer is:
B. A root CA (Certificate Authority)
A self-signed certificate is one where the entity that issued the certificate is also the entity identified by the certificate. In the context of a Certificate Authority (CA), this is often referred to as a root CA certificate. Root CA certificates are at the top of the certificate hierarchy and are used to sign other certificates, creating a chain of trust in a Public Key Infrastructure (PKI).
NEW QUESTION # 31
Refer to exhibit.
An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page.
Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?
- A. On the Static URL Filter configuration, set Action to Monitor.
- B. On the Static URL Filter configuration, set Action to Exempt.
- C. On the FortiGuard Category Based Filter configuration, set Action to Warning for Social Networking.
- D. On the Static URL Filter configuration, set Type to Simple.
Answer: B
Explanation:
C: On the Static URL Filter configuration, set Action to Exempt.
Based on the exhibit, the administrator has configured the FortiGuard Category Based Filter to block access to all social networking sites, and has also configured a Static URL Filter to block access to twitter.com. As a result, users are being redirected to a block page when they try to access twitter.com.
To allow users to access twitter.com while blocking all other social networking sites, the administrator can make the following configuration change:
On the Static URL Filter configuration, set Action to Exempt: By setting the Action to Exempt, the administrator can override the block on twitter.com that was specified in the FortiGuard Category Based Filter. This will allow users to access twitter.com, while all other social networking sites will still be blocked.
Note:
Tested this in a lab environment and to make this work as stated in the question the Exempt action is the only way to go, and also *.twimg.com will has to be added to the URL Filter with an Exempt action for this situation to really work!
Allow: Access is permitted. Traffic is passed to remaining operations, including FortiGuard web filter, web content filter, web script filters, and antivirus scanning.
Exempt: Allows traffic from trusted sources to bypass all security inspections.
NEW QUESTION # 32
When configuring a firewall virtual wire pair policy, which following statement is true?
- A. Only a single virtual wire pair can be included in each policy.
- B. Exactly two virtual wire pairs need to be included in each policy.
- C. Any number of virtual wire pairs can be included, as long as the policy traffic direction is the same.
- D. Any number of virtual wire pairs can be included in each policy, regardless of the policy traffic direction settings.
Answer: D
Explanation:
Any number of virtual wire pairs can be included in each policy, regardless of the policy traffic direction settings.
We tested to create a policy. We can use any number of virtual wire pairs. We can select 3 options in traffic direction: in/out/both.
Firewall virtual wire pair policies can include more than a single virtual wire pair. This capability can streamline the policy management process by eliminating the need to create multiple, similar policies for each virtual wire pair. When creating or modifying a policy, you can select the traffic direction for each VWP included in the policy.
NEW QUESTION # 33
What devices form the core of the security fabric?
- A. One FortiGate device and one FortiManager device
- B. Two FortiGate devices and one FortiManager device
- C. One FortiGate device and one FortiAnalyzer device
- D. Two FortiGate devices and one FortiAnalyzer device
Answer: D
Explanation:
C: Two FortiGate devices and one FortiAnalyzer device.
These devices form the core of the Fortinet Security Fabric, providing firewall functionality, centralized management, logging, and reporting capabilities.
In certain scenarios, especially when emphasizing visibility and analysis, having multiple FortiGate devices and a FortiAnalyzer device can indeed form a core configuration within the Fortinet Security Fabric. FortiAnalyzer is used for centralized logging, reporting, and analysis of data from multiple FortiGate devices, enhancing the overall security posture.
NEW QUESTION # 34
View the exhibit.
A user at 192.168.32.15 is trying to access the web server at 172.16.32.254.
Which two statements best describe how the FortiGate will perform reverse path forwarding (RPF) checks on this traffic? (Choose two.)
- A. Strict RPF check will deny the traffic.
- B. Strict RPF check will allow the traffic.
- C. Loose RPF check will allow the traffic.
- D. Loose RPF check will deny the traffic.
Answer: B,C
Explanation:
B. Loose RPF check will allow the traffic.
C. Strict RPF check will allow the traffic.
NEW QUESTION # 35
Refer to the exhibit.
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)
- A. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
- B. FortiGate SN FGVM010000065036 HA uptime has been reset.
- C. FortiGate devices are not in sync because one device is down.
- D. FortiGate SN FGVM010000064692 has the higher HA priority.
Answer: B,D
Explanation:
1. Override is disable by default - OK
2. "If the HA uptime of a device is AT LEAST FIVE MINUTES (300 seconds) MORE than the HA Uptime of the other FortiGate devices, it becomes the primary" The question here is HA Uptime of FGVM01000006492 > 5 minutes? NO - 198 seconds < 300 seconds (5 minutes) HA age of fortinet SNxxx64682 is only 198seconds, HA by age need more than 300 seconds as estated in the reference "If HA age difference is less than 5 minutes (300 seconds), the device priority and FortiGate serial number selects the cluster unit to become the primary unit.
B. FortiGate devices are not in sync because one device is down. (not in exhibit)
C. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime. (no greater than 300 sec)
NEW QUESTION # 36
Which two statements are correct about a software switch on FortiGate? (Choose two.)
- A. All interfaces in the software switch share the same IP address
- B. It can be configured only when FortiGate is operating in NAT mode
- C. Can act as a Layer 2 switch as well as a Layer 3 router
- D. It can group only physical interfaces
Answer: A,B
Explanation:
A is correct: "Only supported in NAT mode"
C is correct: "The interfaces share the same IP address and belong to the same broadcast domain.
Incorrect options:
B is incorrect: "Acts Like a traditional Layer 2 switch".
D is incorrect: "Can group multiple physical and wireless interfaces into a single virtual switch Interface" Can group physical and wireless.
Only works on NAT mode.
Acts like traditional layer 3 switch.
Interfaces share same IP and broadcast domain.
NEW QUESTION # 37
Which two settings can be separately configured per VDOM on a FortiGate device? (Choose two.)
- A. FortiGuard update servers
- B. NGFW mode
- C. System time
- D. Operating mode
Answer: B,D
Explanation:
C: Operating mode is per-VDOM setting. You can combine transparent mode VDOM's with NAT mode VDOMs on the same physical Fortigate.
D: Inspection-mode selection has moved from VDOM to firewall policy, and the default inspection-mode is flow, so NGFW Mode can be changed from Profile-base (Default) to Policy-base directly in System > Settings from the VDOM.
A and B are incorrect: The firmware on your Fortigate and some settings, such as system time, apply to the entire device-they are not specific to each VDOM.
NGFW mode is a per-VDOM setting.
Operation mode is a per-VDOM setting. You can combine transparent mode VDOMs with NAT mode VDOMs on the same physical FortiGate.
NEW QUESTION # 38
Refer to the exhibit.
Which statement about the configuration settings is true?
- A. When a remote user accesses http://10.200.1.1:443, the SSL-VPN login page opens.
- B. The settings are invalid. The administrator settings and the SSL-VPN settings cannot use the same port.
- C. When a remote user accesses https://10.200.1.1:443, the FortiGate login page opens.
- D. When a remote user accesses https://10.200.1.1:443, the SSL-VPN login page opens.
Answer: D
Explanation:
B. When a remote user accesses https://10.200.1.1:443, the SSL-VPN login page opens.
In this scenario, the remote user is accessing the FortiGate device using HTTPS (port 443), which is typically used for SSL-VPN access. Therefore, when accessing the device at that address and port, the SSL-VPN login page should open for the user to authenticate and establish a VPN connection.
NEW QUESTION # 39
What is the primary FortiGate election process when the HA override setting is disabled?
- A. Connected monitored ports > Priority > HA uptime > FortiGate Serial number
- B. Connected monitored ports > HA uptime > Priority > FortiGate Serial number
- C. Connected monitored ports > System uptime > Priority > FortiGate Serial number
- D. Connected monitored ports > Priority > System uptime > FortiGate Serial number
Answer: B
Explanation:
If Override DISABLED then: ports > HA Uptime > Priority > SN.
If Overrrid ENABLED then: ports > Priority > HA Uptime > SN.
The FortiGate election process when the HA override setting is disabled follows the criteria you provided:
Connected monitored ports: The FortiGate with more connected monitored ports is preferred.
HA uptime: The FortiGate with the longer High Availability (HA) uptime (less recently rebooted in HA) is preferred.
Priority: Priority is used as a tiebreaker. If two FortiGates have the same number of connected monitored ports and the same HA uptime, the one with the higher priority is preferred.
FortiGate Serial number: The FortiGate Serial number is used as a final tiebreaker if all other criteria are the same.
NEW QUESTION # 40
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
- A. The server name indication (SNI) extension in the client hello message.
- B. The serial number in the server certificate.
- C. The subject field in the server certificate.
- D. The host field in the HTTP header.
- E. The subject alternative name (SAN) field in the server certificate.
Answer: A,C,E
Explanation:
When SSL certificate inspection is enabled on a FortiGate device, the system uses the following three pieces of information to identify the hostname of the SSL server:
* Server Name Indication (SNI) extension in the client hello message (B): The SNI is an extension in the client hello message of the SSL/TLS protocol. It indicates the hostname the client is attempting to connect to. This allows FortiGate to identify the server's hostname during the SSL handshake.
* Subject Alternative Name (SAN) field in the server certificate (C): The SAN field in the server certificate lists additional hostnames or IP addresses that the certificate is valid for. FortiGate inspects this field to confirm the identity of the server.
* Subject field in the server certificate (D): The Subject field contains the primary hostname or domain name for which the certificate was issued. FortiGate uses this information to match and validate the server's identity during SSL certificate inspection.
The other options are not used in SSL certificate inspection for hostname identification:
* Host field in the HTTP header (A): This is part of the HTTP request, not the SSL handshake, and is not used for SSL certificate inspection.
* Serial number in the server certificate (E): The serial number is used for certificate management and revocation, not for hostname identification.
References
* FortiOS 7.4.1 Administration Guide - SSL/SSH Inspection, page 1802.
* FortiOS 7.4.1 Administration Guide - Configuring SSL/SSH Inspection Profile, page 1799.
NEW QUESTION # 41
Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)
- A. FortiCache
- B. FortiSIEM
- C. FortiCloud
- D. FortiAnalyzer
- E. FortiSandbox
Answer: B,C,D
Explanation:
The three remote log storage options you can configure on FortiGate are:
A. FortiSIEM
FortiSIEM is a comprehensive security information and event management (SIEM) solution that allows for centralized log storage and analysis.
B. FortiCloud
FortiCloud provides cloud-based services, including log storage, for Fortinet devices, allowing for remote log storage and management.
E. FortiAnalyzer
FortiAnalyzer is a dedicated log and analysis appliance that provides centralized log storage, reporting, and analysis capabilities for Fortinet devices.
So, the correct choices are A, B, and E.
Fortisandbox is not a logging solution.
NEW QUESTION # 42
Refer to the exhibits.
The exhibits show a firewall policy (Exhibit A) and an antivirus profile (Exhibit B).

Why is the user unable to receive a block replacement message when downloading an infected file for the first time?
- A. The intrusion prevention security profile needs to be enabled when using flow-based inspection mode.
- B. The firewall policy performs the full content inspection on the file.
- C. The volume of traffic being inspected is too high for this model of FortiGate.
- D. The flow-based inspection is used, which resets the last packet to the user.
Answer: D
Explanation:
The flow-based inspection is used, which resets the last packet to the user.
Key to right answer is "unable to receive a block replacement message when downloading an infected file for the first time".
* "ONLY" If the virus is detected at the "START" of the connection, the IPS engine sends the block replacement message immediately
* When a virus is detected on a TCP session (FIRST TIME), but where "SOME PACKETS" have been already forwarded to the receiver, FortiGate "resets the connection" and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a "SECOND ATTEMPT" to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
Two possible scenarios can occur when a virus is detected:
- When a virus is detected on a TCP session where some packets have been already forwarded to the receiver, FG resets the connection and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that IF A SECOND ATTEMPT TO TRANSMIT THE FILE IS MADE, THE IPS ENGINE WILL SEND A BLOCK REPLACEMENT MESSAGE to the client instead of scanning the file again.
- If the virus is detected at the start of the connection, the IPS engine sends the block replacement message immediately.
In flow based inspection, when a virus is detected on a TCP session where some packets have been already forwarded to the receiver, FortiGate resets the connection and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that if a second attempt to transmit the file is made, the IPS engine will then send a block replacement message to the client instead of scanning the file again.
NEW QUESTION # 43
What are two functions of ZTNA? (Choose two.)
- A. ZTNA provides role-based access.
- B. ZTNA provides a security posture check.
- C. ZTNA manages access for remote users only.
- D. ZTNA manages access through the client only.
Answer: A,B
Explanation:
C. ZTNA provides a security posture check.
D. ZTNA provides role-based access.
ZTNA (Zero Trust Network Access) is a security architecture that is designed to provide secure access to network resources for users, devices, and applications. It is based on the principle of "never trust, always verify," which means that all access to network resources is subject to strict verification and authentication.
Two functions of ZTNA are:
ZTNA provides a security posture check: ZTNA checks the security posture of devices and users that are attempting to access network resources. This can include checks on the device's software and hardware configurations, security settings, and the presence of malware.
ZTNA provides role-based access: ZTNA controls access to network resources based on the role of the user or device. Users and devices are granted access to only those resources that are necessary for their role, and all other access is denied. This helps to prevent unauthorized access and minimize the risk of data breaches.
A. ZTNA manages access through the client only. (client or browser)
B. ZTNA manages access for remote users only. (not just remote)
C. ZTNA provides a security posture check.
D. ZTNA provides role-based access.
ZTNA is an access control method that uses client device identification, authentication, and zero-trust tags to provide role-based application access.
IP/MAC filtering uses ZTNA tags to provide an additional factor for identification, and a security posture check to implement role-based zero-trust access.
NEW QUESTION # 44
An administrator has configured central DNAT and virtual IPs.
Which item can be selected in the firewall policy Destination field?
- A. A VIP object
- B. The mapped IP address object of the VIP object
- C. A VIP group
- D. An IP pool
Answer: B
Explanation:
- when central NAT is enabled => put the mapped IP address of the VIP object.
- when central NAT is disabled => put the VIP object.
In the context of central DNAT and virtual IPs in FortiGate, the correct option for the firewall policy Destination field is:
D. The mapped IP address object of the VIP object
When configuring central DNAT, you typically select the mapped IP address object associated with the VIP object in the firewall policy Destination field. This mapped IP address represents the internal destination to which traffic will be redirected.
So, the correct choice is D.
NEW QUESTION # 45
Which three statements explain a flow-based antivirus profile? (Choose three.)
- A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
- B. If a virus is detected, the last packet is delivered to the client.
- C. FortiGate buffers the whole file but transmits to the client at the same time.
- D. The IPS engine handles the process as a standalone.
- E. Flow-based inspection optimizes performance compared to proxy-based inspection.
Answer: A,C,E
Explanation:
A: Flow-based inspection mode uses a hybrid of the scanning modes available in proxy-based inspection.
D: the IPS engine reads the payload of each packet, caches a local copy, and forwards the packet to the receiver at the same time. some operations can be offloaded to SPUs to improve performance (not C).
E: If performance is your top priority, then flow inspection mode is more appropriate. Extra explanation:
A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
Flow-based inspection combines aspects of both proxy-based and flow-based inspection methods to optimize performance and scanning effectiveness.
D. FortiGate buffers the whole file but transmits to the client at the same time.
In flow-based inspection, FortiGate buffers the entire file for scanning before transmitting it to the client.
This allows for comprehensive scanning without delaying the transmission to the client.
E. Flow-based inspection optimizes performance compared to proxy-based inspection.
Flow-based inspection is generally more efficient than proxy-based inspection, especially in high-traffic environments, as it does not require the buffering of entire files before delivery.
NEW QUESTION # 46
Which two configuration settings are global settings? (Choose two.)
- A. FortiGuard settings
- B. Firewall policies
- C. HA settings
- D. User & Device settings
Answer: A,C
Explanation:
The two configuration settings that are global settings are:
C. HA settings - High Availability settings are typically configured globally to manage failover and redundancy.
D. FortiGuard settings - FortiGuard settings for security services and updates are also configured globally to ensure consistent protection across the network.
HA configuration overview. The purpose of an HA configuration is to reduce downtime when a zone or instance becomes unavailable. This might happen during a zonal outage, or when an instance runs out of memory. With HA, your data continues to be available to client applications.
FortiGuard > Settings provides a central location for configuring and enabling your FortiManager system's built-in FDS as an FDN override server.
NEW QUESTION # 47
Refer to the FortiGuard connection debug output.
Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
- A. There is at least one server that lost packets consecutively.
- B. A local FortiManager is one of the servers FortiGate communicates with.
- C. FortiGate is using default FortiGuard communication settings.
- D. One server was contacted to retrieve the contract information.
Answer: C,D
Explanation:
B is correct, one server has the flag DI which means it was contacted to retrieve contract information. A:
no server has packets dropped
C: No local(ip) fortimanager can be seen
D:......Anycast is enabled by default(as it says on the study guide) so its not using default settings. still, it uses HTTPS(TCP) and port 443 under tcp so we can consider this a default setting.
"by default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager" We did check ourFortiGate and its configured the same.
Anycast is Enabled by default, but A and C are definitely incorrect.
NEW QUESTION # 48
......
Fortinet FCP_FGT_AD-7.4 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
| Topic 12 |
|
| Topic 13 |
|
Pass Your FCP_FGT_AD-7.4 Dumps as PDF Updated on 2024 With 50 Questions: https://www.passleader.top/Fortinet/FCP_FGT_AD-7.4-exam-braindumps.html
Verified FCP_FGT_AD-7.4 Dumps Q&As - FCP_FGT_AD-7.4 Test Engine with Correct Answers: https://drive.google.com/open?id=1BfLoKIe1ok_z8q1rpot9ooO6ApL5KUfU