FCP-FCT-AD-7-2 Sample Questions & Answers
Security Fabric integration, automatic quarantine, and full ZTNA deployment carry the most weight, next to installing and configuring FortiClient EMS, deploying FortiClient across platforms and endpoint profiles, and resolving common issues.
Launch the full FCP-FCT-AD-7-2 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Security Fabric Integration · Deploy the full ZTNA solution
An administrator needs to configure a ZTNA access rule on a FortiGate that grants access to an internal web server only for users in the 'Developers' Active Directory group whose endpoints are running a company-approved OS version. What is the correct sequence of objects needed in the FortiGate ZTNA rule?
Show answer & explanation
Correct answer: A
A correct ZTNA rule on FortiGate requires a ZTNA server object defining the destination, a firewall policy that specifies the source user/group (from AD) and the ZTNA server as the destination, and includes the EMS ZTNA tag for posture checking (approved OS version). This combination ensures both user identity and device posture are verified.
- Question 2Intermediate
FortiClient Provisioning and Deployment · Configure endpoint profiles to provision FortiClient devices
A hospital uses FortiClient EMS to manage endpoints on medical carts. To comply with healthcare regulations, these carts must be prevented from accessing non-medical websites. The administrator has created a Web Filter profile that blocks categories like 'Social Networking' and 'Streaming Media'. Which additional feature should be enabled in the profile to prevent users from accessing blocked sites by typing in their IP addresses?
Show answer & explanation
Correct answer: D
The Web Filter profile's category-based blocking works on domain names. To prevent users from bypassing this by using a website's direct IP address, the 'Block HTTP and HTTPS traffic by IP address' option must be explicitly enabled. This ensures that any web requests made directly to an IP are also blocked.
- Question 3Beginner
FortiClient EMS Setup · Install and perform the initial configuration of FortiClient EMS
During the initial setup of a new FortiClient EMS 7.2 instance, the administrator needs to configure the database. The organization has a dedicated Microsoft SQL Server cluster for all applications. Which setting must be configured in the EMS setup wizard to connect to this external database?
Show answer & explanation
Correct answer: A
When installing FortiClient EMS and opting to use an external Microsoft SQL Server, the setup wizard requires the server's address (either FQDN or IP), the port (if not the default), and authentication credentials (like a service account) that have sufficient permissions to create and manage the EMS database.
- Question 4Intermediate
Diagnostics · Analyze diagnostic information to troubleshoot FortiClient EMS and FortiClient issues
An administrator is troubleshooting why a specific Windows endpoint is not receiving the latest endpoint profile update from FortiClient EMS. The endpoint is online and shows as registered in the EMS console. Which diagnostic step should the administrator take first on the affected endpoint?
Show answer & explanation
Correct answer: B
The FortiClient console on the endpoint has a built-in 'Diagnostic Tool'. This tool provides a quick and easy way to verify the client's connection status to the EMS server, check the last profile update time, and see if any communication errors are logged. This is the most efficient first step to diagnose profile update issues directly from the client side.
- Question 5Advanced
Diagnostics · Analyze diagnostic information to troubleshoot FortiClient EMS and FortiClient issues
What is the primary function of the
fctservctl.exeutility in the context of FortiClient EMS?Show answer & explanation
Correct answer: C
The
fctservctl.execommand-line utility is the FortiClient EMS Service Controller. It is used to manage the core services of the EMS server itself. Administrators can use it to stop, start, restart, and query the status of all related services, which is particularly useful for troubleshooting and scripted maintenance. - Question 6Intermediate
FortiClient Provisioning and Deployment · Configure endpoint profiles to provision FortiClient devices
A company has two distinct groups of users: 'Sales' and 'Engineering'. The Sales team requires a lenient web filter policy, while the Engineering team needs a very strict policy. The administrator has created two separate endpoint profiles with the appropriate web filter settings. How can the administrator ensure that endpoints are automatically assigned the correct profile based on their Active Directory group membership?
Show answer & explanation
Correct answer: C
FortiClient EMS can integrate with Active Directory. After adding the AD domain, an administrator can create endpoint policy assignment rules. These rules map specific AD user or computer groups (e.g., 'Sales', 'Engineering') to the corresponding endpoint profiles. When a user from that group logs into an endpoint, EMS automatically applies the correct profile.
- Question 7AdvancedSelect 2
Security Fabric Integration · Configure Security Fabric integration with FortiClient EMS
A FortiClient EMS administrator has integrated EMS with a FortiGate in the Security Fabric. They want to create a firewall policy on the FortiGate that allows access to a specific server only for endpoints that are confirmed to be managed by EMS and are currently online. Which two objects would be used in the source field of this firewall policy? (Select TWO).
Show answer & explanation
Correct answers: B, C
- Question 8Beginner
FortiClient Provisioning and Deployment · Configure endpoint profiles to provision FortiClient devices
When configuring a FortiClient deployment package, an administrator wants to ensure that end-users cannot uninstall or stop the FortiClient service on their Windows machines. Which feature should be configured in the System Settings of the endpoint profile?
Show answer & explanation
Correct answer: B
To prevent unauthorized removal or tampering with the FortiClient agent, the administrator can set an uninstall password in the System Settings section of the endpoint profile. Once this profile is applied, any attempt to uninstall FortiClient or stop its services will prompt for this password.
- Question 9Beginner
FortiClient EMS Setup · Install and perform the initial configuration of FortiClient EMS
The FortiClient EMS server uses port ______ by default for endpoint registration and management traffic.
Show answer & explanation
Correct answer: A
FortiClient endpoints communicate with the FortiClient EMS server for registration, profile updates, and telemetry data over TCP port 8013. This port must be open on any firewalls between the endpoints and the EMS server.
- Question 10IntermediateSelect 2
Security Fabric Integration · Configure automatic quarantine of compromised endpoints
A university is deploying FortiClient EMS to manage student laptops in a dormitory network. The goal is to automatically isolate any endpoint that is detected with an active malware infection. The isolation should redirect all web traffic from the infected device to a remediation portal. Which two components are essential to achieve this automated quarantine with a captive portal? (Select TWO).
Show answer & explanation
Correct answers: B, C
Ready for the real thing?
The full FCP-FCT-AD-7-2 simulator has every exam-style question, timed mode, and instant scoring.