ExamDumpster

Free FCP-FGT-AD-7-4 sample questions

Real questions from the FCP - FortiGate 7.4 Administrator practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial services company is deploying a new FortiGate 200F cluster. The primary requirement is to ensure that if the primary unit fails, all active sessions, including long-lived TCP sessions for stock market data feeds, are seamlessly transferred to the secondary unit without interruption. Which FortiGate Clustering Protocol (FGCP) configuration setting is essential to meet this requirement?

Question 2Choose 2

An administrator is configuring a destination NAT (DNAT) policy using a virtual IP (VIP) to forward inbound traffic from the internet to an internal web server. Internet users connect on TCP port 80, but the web server listens on TCP port 8080. The external IP for the VIP is 203.0.113.10, and the internal server's IP is 192.168.1.100. Which two of the following VIP configurations are required to correctly translate both the destination IP address and the port? (Choose two.)

Question 3Choose one

A hospital's FortiGate uses web filtering to block social media sites for clinical staff. However, IT staff need access to these sites for research and support, whichever workstation they log on to. The administrator has created two Active Directory groups, `Clinical_Staff` and `IT_Staff`, which are monitored by the FSSO Collector Agent and mapped to FSSO user groups on the FortiGate. What is the most efficient way to enforce this requirement using FSSO?

Question 4Choose one

True or False: When using full SSL inspection on a FortiGate, the `Fortinet_CA_SSL` certificate must be installed on the FortiGate itself, but does not need to be installed on end-user client browsers.

Question 5Choose one

A network administrator is troubleshooting an issue where traffic to 10.50.20.5 is leaving the FortiGate through the default route instead of the more specific static route. The routing table shows both the specific static route and the default route are active. The specific route is for network 10.50.0.0/16 via gateway 10.100.1.1, and the default route is 0.0.0.0/0 via gateway 192.168.1.254. What is the most likely reason for this behavior?

Question 6Choose 3

A company has two WAN connections, WAN1 (Fiber) and WAN2 (Cable), and wants to use SD-WAN to route business-critical traffic (Salesforce, Office 365) over the link with the lowest latency. All other traffic should be load-balanced based on volume. Which SD-WAN components must be configured to achieve this? (Choose three.)

Question 7Choose one

When configuring an SSL VPN in web mode, what is the primary function of a bookmark?

Question 8Choose one

During the configuration of a site-to-site IPsec VPN tunnel, the administrator is setting up the Phase 1 parameters. Which of the following settings must match exactly on both peers for the Phase 1 tunnel to establish successfully?

Question 9Choose one

A systems administrator is configuring a new administrator account on a FortiGate. The security policy requires that this administrator should only be able to view and manage firewall policies and routing settings, without the ability to change system-level settings or other security profiles. Which feature should be used to enforce this level of access?

Question 10Choose one

An e-commerce company uses a FortiGate firewall. They have a firewall policy allowing outbound traffic from their internal network to the internet. This policy uses an IP Pool configured for `One-to-One` NAT with a small range of public IPs. During peak sales, some internal users report they cannot access the internet. What is the most likely cause of this issue?

10 more free samples are waiting

Create a free account to unlock the whole FCP-FGT-AD-7-4 sample bank, or get full access to all 234 practice questions in the simulator.

Create account