FCP-FGT-AD-7-4 Sample Questions & Answers
Firewall policy configuration, authentication, and Fortinet Single Sign-On top the weighting, alongside initial setup with the Security Fabric and HA, SSL inspection and security profiles, SD-WAN routing choices, and SSL plus IPsec VPNs.
Launch the full FCP-FGT-AD-7-4 simulator →Showing 10 of 20 free samples.
- Question 1AdvancedSelect 3
Routing · SD-WAN Rule Configuration
A company has two WAN connections, WAN1 (Fiber) and WAN2 (Cable), and wants to use SD-WAN to route business-critical traffic (Salesforce, Office 365) over the link with the lowest latency. All other traffic should be load-balanced based on volume. Which SD-WAN components must be configured to achieve this? (Choose three.)
Show answer & explanation
Correct answers: A, C, D
The implicit rule, which is the last rule in the list, catches all traffic not matched by previous rules. To meet the requirement for all other traffic, this rule must be configured with a volume-based load-balancing algorithm.
A Performance SLA (Service Level Agreement) is required to actively monitor the quality of the WAN links. To make decisions based on latency, an SLA must be configured to probe the links and measure this specific metric.
An SD-WAN rule is needed to identify the specific traffic (Salesforce, O365) and apply a routing strategy. The
Best Qualitystrategy, tied to the latency-measuring Performance SLA, will ensure this traffic is sent over the link that currently has the lowest latency. - Question 2Beginner
VPN · SSL VPN Web Mode
When configuring an SSL VPN in web mode, what is the primary function of a bookmark?
Show answer & explanation
Correct answer: C
In SSL VPN web mode, bookmarks are shortcuts displayed on the portal page that allow users to easily access internal resources like web servers, RDP, or SSH without needing to know the internal IP address or URL. The FortiGate proxies the connection on behalf of the user.
- Question 3Intermediate
VPN · IPsec VPN Phase 1 Configuration
During the configuration of a site-to-site IPsec VPN tunnel, the administrator is setting up the Phase 1 parameters. Which of the following settings must match exactly on both peers for the Phase 1 tunnel to establish successfully?
Show answer & explanation
Correct answer: C
For a Phase 1 IKE negotiation to succeed, both VPN peers must be configured with an identical set of proposals. This includes the preshared key (or certificate), the encryption algorithm (e.g., AES256), the authentication algorithm (e.g., SHA256), and the Diffie-Hellman group. A mismatch in any of these will cause the Phase 1 negotiation to fail.
- Question 4Beginner
Deployment and System Configuration · Administrator Access Control
A systems administrator is configuring a new administrator account on a FortiGate. The security policy requires that this administrator should only be able to view and manage firewall policies and routing settings, without the ability to change system-level settings or other security profiles. Which feature should be used to enforce this level of access?
Show answer & explanation
Correct answer: D
Admin Profiles provide granular, role-based access control (RBAC) for FortiGate administrators. By creating a custom admin profile, you can specify read, write, or no access for each functional area of the configuration, such as Firewall, Router, System, and Security Profiles. This is the correct method for limiting an administrator's permissions to specific tasks.
- Question 5Intermediate
Firewall Policies and Authentication · SNAT Configuration
An e-commerce company uses a FortiGate firewall. They have a firewall policy allowing outbound traffic from their internal network to the internet. This policy uses an IP Pool configured for
One-to-OneNAT with a small range of public IPs. During peak sales, some internal users report they cannot access the internet. What is the most likely cause of this issue?Show answer & explanation
Correct answer: A
One-to-OneNAT creates a direct mapping between an internal source IP and an external IP from the pool. This means the number of concurrent users who can access the internet is limited to the number of available IPs in the pool. During peak times, the company has more internal users than available public IPs, leading to NAT exhaustion. The solution would be to change the IP Pool type toOverload. - Question 6Intermediate
Content Inspection · Antivirus Scanning Modes
A security architect needs to configure a FortiGate to inspect traffic for malware. The primary concern is security effectiveness, and they are willing to accept a minor increase in latency for more thorough inspection. Which antivirus scanning mode should be selected, and why?
Show answer & explanation
Correct answer: C
Proxy-based inspection provides higher security effectiveness. It buffers the complete file or web page before delivering it to the end user, which allows the antivirus engine to perform a more comprehensive scan. This method can identify threats that flow-based inspection might miss, making it the preferred choice when security is the top priority over minimal latency.
- Question 7IntermediateSelect 2
Routing · Policy-Based Routing
Which two statements accurately describe the function of policy-based routing on a FortiGate? (Choose two.)
Show answer & explanation
Correct answers: A, D
FortiGate looks up policy routes first and consults the FIB (kernel routing table) only when no policy route matches. Source: FortiOS 7.4 Administration Guide, Routing concepts > Route look-up.
Policy routes can match on incoming interface, source and destination address, protocol, port and ToS, not only on the destination address as the routing table does. Source: FortiOS 7.4 Administration Guide, Policy routes.
- Question 8Intermediate
VPN · SSL VPN Modes
An organization wants to provide remote access to its developers. The requirements are:
- Users should connect using any standard web browser without installing any client software.
- Users need access to an internal SFTP server and an internal web application.
- The solution must be secure and easy to manage.
Which FortiGate VPN configuration best meets all these requirements?
Show answer & explanation
Correct answer: B
SSL VPN in web mode provides clientless access through a web browser, fulfilling the first requirement. By creating bookmarks within the web portal, you can provide proxied access to internal services like web applications and SFTP, meeting the second and third requirements. This solution is secure and avoids the need for software installation on client machines.
- Question 9Beginner
Deployment and System Configuration · FGCP HA Cluster Modes
True or False: In a FortiGate Active-Active HA cluster, all traffic processing is handled by the primary unit, while the secondary unit remains in a standby state, only synchronizing configuration and session data.
Show answer & explanation
Correct answer: B
The statement describes an Active-Passive HA cluster. In an Active-Active HA cluster, traffic processing is load-balanced across all cluster members. While one unit acts as the primary for management and some session scheduling, multiple units actively process traffic, thereby increasing throughput.
- Question 10Intermediate
Firewall Policies and Authentication · Firewall Authentication Methods
A university is setting up a guest wireless network. They want to require guests to authenticate before gaining internet access. The requirements are that guests should be presented with a login page to enter a username and password provided by the front desk. This authentication should be handled directly by the FortiGate. Which authentication method should the administrator configure?
Show answer & explanation
Correct answer: B
A captive portal is the feature designed for this exact scenario. It intercepts the user's first web request and redirects them to a login page (the portal). By creating local user accounts on the FortiGate for the guests, the firewall can authenticate them directly before allowing access. This method is commonly used for guest networks.
Ready for the real thing?
The full FCP-FGT-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.