Fortinet

FCP_FGT_AD-7.4 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 88-question bank.

Provider
Fortinet
Question bank
88
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for FCP_FGT_AD-7.4, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit. Which two statements are true about the routing entries in this database table? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • All of the entries in the routing database table are installed in the FortiGate routing table.
    • The port2 interface is marked as inactive.
    • Both default routes have different administrative distances.
    • The default route on port2 is marked as the standby route.
  2. Question 2 · 1

    A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover. Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)

    Choose all answers that apply.

    • Enable Dead Peer Detection.
    • Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
    • Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
    • Configure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
  3. Question 3 · 1

    Refer to the exhibits. The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details. Based on the configuration, what will happen to Apple FaceTime if there are only a few calls originating or incoming?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Apple FaceTime will be allowed, based on the Video/Audio category configuration.
    • Apple FaceTime will be allowed, based on the Apple filter configuration.
    • Apple FaceTime will be allowed only if the Apple filter in Application and Filter Overrides is set to Allow.
    • Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration.
  4. Question 4 · 1

    An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?

    Choose one answer.

    • SSL VPN idle-timeout
    • SSL VPN login-timeout
    • SSL VPN dtls-hello-timeout
    • SSL VPN session-ttl
  5. Question 5 · 1

    When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate. Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choose three.)

    Choose all answers that apply.

    • Allow & Warning
    • Trust & Allow
    • Allow
    • Block & Warning
    • Block
  6. Question 6 · 1

    Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The sensor will gather a packet log for all matched traffic.
    • The sensor will reset all connections that match these signatures.
    • The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature.
    • The sensor will block all attacks aimed at Windows servers.
  7. Question 7 · 1

    Which statement is a characteristic of automation stitches?

    Choose one answer.

    • They can be run only on devices in the Security Fabric.
    • They can be created only on downstream devices in the fabric.
    • They can have one or more triggers.
    • They can run multiple actions at the same time.
  8. Question 8 · 1

    What is the primary FortiGate election process when the HA override setting is disabled?

    Choose one answer.

    • Connected monitored ports > Priority > System uptime > FortiGate serial number
    • Connected monitored ports > System uptime > Priority > FortiGate serial number
    • Connected monitored ports > Priority > HA uptime > FortiGate serial number
    • Connected monitored ports > HA uptime > Priority > FortiGate serial number
  9. Question 9 · 1

    Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)

    Choose all answers that apply.

    • The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
    • The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
    • The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
    • The client FortiGate requires a manually added route to remote subnets.
  10. Question 10 · 1

    Refer to the exhibit. Which statement about this firewall policy list is true?

    Choose one answer.

    Question illustration 1
    • The Implicit group can include more than one deny firewall policy.
    • The firewall policies are listed by ID sequence view.
    • The firewall policies are listed by ingress and egress interfaces pairing view.
    • LAN to WAN, WAN to LAN, and Implicit are sequence grouping view lists.
  11. Question 11 · 1

    Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?

    Choose one answer.

    Question illustration 1
    • The underlay zone contains port1 and port2.
    • The d-wan zone contains no member.
    • The d-wan zone cannot be deleted.
    • The virtual-wan-link zone contains no member.
  12. Question 12 · 1

    Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

    Choose all answers that apply.

    • The host field in the HTTP header.
    • The server name indication (SNI) extension in the client hello message.
    • The subject alternative name (SAN) field in the server certificate.
    • The subject field in the server certificate.
    • The serial number in the server certificate.
  13. Question 13 · 1

    Which two statements describe how the RPF check is used? (Choose two.)

    Choose all answers that apply.

    • The RPF check is run on the first sent packet of any new session.
    • The RPF check is run on the first reply packet of any new session.
    • The RPF check is run on the first sent and reply packet of any new session.
    • The RPF check is a mechanism that protects FortiGate and the network from IP spoofing attacks.
  14. Question 14 · 1

    Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)

    Choose all answers that apply.

    • Manual with load balancing
    • Lowest Cost (SLA) with load balancing
    • Best Quality with load balancing
    • Lowest Quality (SLA) with load balancing
    • Lowest Cost (SLA) without load balancing
  15. Question 15 · 1

    Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)

    Choose all answers that apply.

    • Pre-shared key and certificate signature as authentication methods
    • Extended authentication (XAuth) to request the remote peer to provide a username and password
    • Extended authentication (XAuth) for faster authentication because fewer packets are exchanged
    • No certificate is required on the remote peer when you set the certificate signature as the authentication method

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free