FCP-FWF-AD-7-4 Sample Questions

FCP-FWF-AD-7-4 Sample Questions & Answers

Four areas split the weighting evenly: wireless basics and rolling out FortiAPs, planning secure WLANs that use VLANs and NAC, keeping tabs on access-point health plus guest access, and chasing down issues via wireless logs and debug output.

Launch the full FCP-FWF-AD-7-4 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Wireless fundamentals and FortiAP management · Deploy FortiAP devices using the FortiOS integrated wireless controller

    Case Study:

    Global Retail Corp is upgrading the wireless infrastructure across its 200 stores. Each store has a single FortiGate managing local FortiAPs. The corporate IT team needs to enforce a standardized wireless configuration across all stores but allow local store managers to customize the guest Wi-Fi captive portal message. The corporate team must be able to push updates to AP radio settings and security policies centrally, while preventing store managers from altering these critical configurations.

    The requirements are as follows:

    1. Centralized management of AP profiles, SSIDs, and security settings.
    2. Delegated management for guest captive portals on a per-store basis.
    3. Ability to deploy new FortiAPs to stores with zero-touch provisioning.
    4. Scalable management for all 200 store FortiGates and their associated APs.

    Which Fortinet solution best meets all of Global Retail Corp's requirements?

    Show answer & explanation

    Correct answer: D

    FortiManager is the ideal solution for this scenario. It provides centralized management for hundreds of FortiGates. Using provisioning templates, the corporate team can enforce standard configurations for SSIDs and AP profiles. By creating custom administrator profiles with restricted access within the ADOM, they can delegate the specific task of editing guest portals to store managers while protecting critical settings. New devices can be brought online with zero-touch provisioning through FortiZTP (formerly FortiDeploy), which directs them to their management target.

  2. Question 2Intermediate

    Wireless network security and access · Configure secure wireless access

    A wireless network administrator has configured WPA3-Enterprise with 802.1X authentication. During testing, it is discovered that some older, mission-critical devices do not support WPA3. The administrator needs to allow both WPA3-capable and WPA2-capable clients to connect to the same corporate SSID. What security mode should be configured on the SSID?

    Show answer & explanation

    Correct answer: B

    WPA3-Enterprise Transition Mode is specifically designed for this purpose. It allows the SSID to simultaneously advertise support for both WPA3 and WPA2, enabling clients to connect using the highest security protocol they support. This provides a seamless migration path without requiring a separate legacy SSID.

  3. Question 3Intermediate

    Wireless diagnostics and analytics · Gather information about clients and wireless components

    An administrator is analyzing the output of diagnose wireless-controller wlac -d sta to troubleshoot a client's roaming issue. The client is frequently disconnecting and reconnecting while moving through the facility. Which piece of information in the command output is most critical for diagnosing poor roaming performance?

    Show answer & explanation

    Correct answer: B

    The RSSI value indicates the signal strength received by the AP from the client. Monitoring the RSSI as the client moves is crucial for diagnosing roaming issues. If the RSSI drops to a very low level before a roam occurs, it indicates potential coverage gaps or that roaming thresholds are not tuned correctly, causing the client to disconnect before it can find and roam to a better AP.

  4. Question 4Advanced

    Wireless monitoring and protection · Identify wireless threats and malicious activities

    A security audit reveals that an unauthorized device has been connected to a corporate LAN port and is broadcasting a rogue SSID with the same name as the corporate network (an "evil twin"). The FortiAP WIDS has detected this rogue AP. Which specific Fortinet feature can actively prevent clients from connecting to this on-wire rogue AP?

    Show answer & explanation

    Correct answer: A

    When an AP is set to Suppressed Rogue AP, the FortiGate WiFi controller uses the monitoring radio to send deauthentication messages to the rogue AP's clients (posing as the rogue AP) and to the rogue AP (posing as its clients). This stops users from staying connected to it. It requires on-wire rogue detection and a radio in Dedicated Monitor mode. Client isolation and PMF protect your own SSIDs but do not act against a rogue AP.

  5. Question 5IntermediateSelect 3

    Wireless network security and access · Deploy VLANs and NAC for wireless segmentation

    A consultant needs to configure dynamic VLAN assignment for wireless clients based on their department, which is stored as an attribute in a RADIUS server. Which three components are essential for this configuration to work? (Select THREE)

    Show answer & explanation

    Correct answers: B, C, E

    The RADIUS server is responsible for authenticating the user and sending back the appropriate VLAN ID in its Access-Accept message. WPA2/WPA3-Enterprise (802.1X) is the authentication framework that directs authentication requests to the RADIUS server. The FortiGate must have the VLANs defined as interfaces and have appropriate firewall policies to allow traffic from those VLANs to the intended destinations. On the FortiGate, Dynamic VLAN assignment must also be enabled on the SSID (set dynamic-vlan enable) so that the returned Tunnel-Private-Group-ID is honored.

    The RADIUS server is responsible for authenticating the user and sending back the appropriate VLAN ID in its Access-Accept message. WPA2/WPA3-Enterprise (802.1X) is the authentication framework that directs authentication requests to the RADIUS server. The FortiGate must have the VLANs defined as interfaces and have appropriate firewall policies to allow traffic from those VLANs to the intended destinations. On the FortiGate, Dynamic VLAN assignment must also be enabled on the SSID (set dynamic-vlan enable) so that the returned Tunnel-Private-Group-ID is honored.

    The RADIUS server is responsible for authenticating the user and sending back the appropriate VLAN ID in its Access-Accept message. WPA2/WPA3-Enterprise (802.1X) is the authentication framework that directs authentication requests to the RADIUS server. The FortiGate must have the VLANs defined as interfaces and have appropriate firewall policies to allow traffic from those VLANs to the intended destinations. On the FortiGate, Dynamic VLAN assignment must also be enabled on the SSID (set dynamic-vlan enable) so that the returned Tunnel-Private-Group-ID is honored.

  6. Question 6Beginner

    Wireless monitoring and protection · Implement location-based presence and guest services

    An administrator is setting up a guest wireless network and wants to leverage social media logins for authentication. They are also interested in collecting analytics on guest traffic patterns and dwell times. Which Fortinet product is specifically designed to provide these capabilities?

    Show answer & explanation

    Correct answer: B

    FortiPresence is a cloud-based analytics and engagement platform. It integrates with FortiAP infrastructure to provide location-based analytics, visitor tracking, and advanced guest Wi-Fi services, including social media logins and customizable captive portals.

  7. Question 7Intermediate

    Wireless fundamentals and FortiAP management · Use custom access point profiles to configure FortiAP devices

    True or False: The DARRP (Distributed Automatic Radio Resource Provisioning) feature in a FortiGate wireless controller allows it to dynamically adjust the channel and transmit power of FortiAPs based on real-time RF environment monitoring.

    Show answer & explanation

    Correct answer: B

    False. FortiOS 7.4 describes DARRP (Distributed Automatic Radio Resource Provisioning) as channel optimization: each FortiAP autonomously and periodically finds the best channel through channel selection and scoring, and changes channel when TX retries or RX errors exceed thresholds. Transmit power is adjusted by a separate feature, automatic TX power control (auto-power-level enable with auto-power-high and auto-power-low).

  8. Question 8Intermediate

    Wireless network security and access · Deploy VLANs and NAC for wireless segmentation

    A network engineer is deploying FortiAPs in a multi-tenant building and must ensure that wireless traffic from different tenants is completely isolated. The engineer has decided to use Bridge mode for the SSIDs. What is the primary implication of using Bridge mode in this scenario?

    flowchart TD Client1 -->|Tenant A SSID| FAP Client2 -->|Tenant B SSID| FAP subgraph FortiAP [FortiAP in Bridge Mode] direction LR SSID_A(SSID A - VLAN 100) SSID_B(SSID B - VLAN 200) end FAP --> Switch Switch -->|Tagged VLAN 100| RouterA[Tenant A Router] Switch -->|Tagged VLAN 200| RouterB[Tenant B Router]
    Show answer & explanation

    Correct answer: D

    In Bridge (local bridge) mode, the FortiAP forwards wireless client traffic directly onto the wired network instead of tunneling it to the FortiGate. Each SSID is mapped to a VLAN ID (config wireless-controller vap / set vlanid), so the FortiAP tags Tenant A traffic with VLAN 100 and Tenant B traffic with VLAN 200. The switch port connected to the AP must be configured as a trunk to carry the tagged traffic to each tenant's router.

  9. Question 9Intermediate

    Wireless diagnostics and analytics · Troubleshoot common wireless issues and apply remediation

    During a wireless site survey using FortiPlanner, an administrator identifies an area with high co-channel interference from a neighboring company's network. What is the most effective immediate action that can be taken within the FortiAP profile to mitigate this interference?

    Show answer & explanation

    Correct answer: D

    Co-channel interference occurs when multiple APs operate on the same channel. The most direct and effective way to mitigate this is to manually change the channel of the affected FortiAP to a different, non-overlapping channel (like 1, 6, or 11 in the 2.4 GHz band, or a clear channel in the 5 GHz band) that is not being used by the interfering network.

  10. Question 10Advanced

    Wireless network security and access · Configure secure wireless access

    Case Study:

    A large logistics company, Freight Movers Inc., is securing its warehouse environment. The company uses Wi-Fi-enabled handheld scanners that are critical for operations. These scanners are older devices that only support WPA2-Personal (PSK). The security team is concerned about the risk of a lost or stolen scanner being used to access the network. They also want to ensure that only company-owned scanners can connect.

    The requirements are:

    1. Use a secure method to authenticate the known, company-owned scanners.
    2. Prevent unauthorized devices from connecting, even if they know the Wi-Fi password.
    3. The solution must work with devices that only support WPA2-PSK.
    4. The solution should be centrally manageable through the FortiGate.

    Which configuration provides the best security posture while meeting all device compatibility requirements?

    Show answer & explanation

    Correct answer: C

    WPA2-Personal satisfies the device compatibility constraint, and the SSID is managed centrally from the FortiGate. A MAC filter on the SSID (an address group of the scanners' MAC addresses applied with set address-group and set address-group-policy allow under config wireless-controller vap) denies association to devices that are not on the list, even if they know the PSK. MAC addresses can be spoofed, so a MAC filter should be used together with encryption, which is the case here. WPA2-Enterprise does not meet the requirement because the scanners only support WPA2-PSK.

Ready for the real thing?

The full FCP-FWF-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.