Fortinet

FCSS_EFW_AD-7.4 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 55-question bank.

Provider
Fortinet
Question bank
55
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for FCSS_EFW_AD-7.4, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    A company that acquired multiple branches across different countries needs to install new FortiGate devices on each of those branches. However, the IT staff lacks sufficient knowledge to implement the initial configuration on the FortiGate devices. Which three approaches can the company take to successfully deploy advanced initial configurations on remote branches? (Choose three.)

    Choose all answers that apply.

    • Use metadata variables to dynamically assign values according to each FortiGate device.
    • Use provisioning templates and install configuration settings at the device layer.
    • Use the Global ADOM to deploy global object configurations to each FortiGate device.
    • Apply Jinja in the FortiManager scripts for large-scale and advanced deployments.
    • Add FortiGate devices on FortiManager as model devices, and use ZTP or LTP to connect to FortiGate devices.
  2. Question 2 · 1

    What is the initial step performed by FortiGate when handling the first packets of a session?

    Choose one answer.

    • Installation of the session key in the network processor (NP)
    • Data encryption and decryption
    • Security inspections such as ACL, HPE, and IP integrity header checking
    • Offloading the packets directly to the content processor (CP)
  3. Question 3 · 1

    An administrator applied a block-all IPS profile for client and server targets to secure the server, but the database team reported the application stopped working immediately after. How can an administrator apply IPS in a way that ensures it does not disrupt existing applications in the network?

    Choose one answer.

    • Use an IPS profile with all signatures in monitor mode and verify patterns before blocking.
    • Limit the IPS profile to server targets only to avoid blocking connections from the server to clients.
    • Select flow mode in the IPS profile to accurately analyze application patterns.
    • Set the IPS profile signature action to default to discard all possible false positives.
  4. Question 4 · 1

    An administrator is extensively using VXLAN on FortiGate. Which specialized acceleration hardware does FortiGate need to improve its performance?

    Choose one answer.

    • NP7
    • SP5
    • СР9
    • NTurbo
  5. Question 5 · 1

    Refer to the exhibit, which shows a partial enterprise network. An administrator would like the area 0.0.0.0 to detect the external network. What must the administrator configure?

    Choose one answer.

    Question illustration 1
    • Enable RIP redistribution on FortiGate B.
    • Configure a distribute-route-map-in on FortiGate B.
    • Configure a virtual link between FortiGate A and B.
    • Set the area 0.0.0.l type to stub on FortiGate A and B.
  6. Question 6 · 1

    Refer to the exhibit, which shows the ADVPN network topology and partial BGP configuration. Which two parameters must an administrator configure in the config neighbor range for spokes shown in the exhibit? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • set max-neighbor-num 2
    • set neighbor-group advpn
    • set route-reflector-client enable
    • set prefix 172.16.1.0 255.255.255.0
  7. Question 7 · 1

    Which two statements about IKEv2 are true if an administrator decides to implement IKEv2 in the VPN topology? (Choose two.)

    Choose all answers that apply.

    • It includes stronger Diffie-Hellman (DH) groups, such as Elliptic Curve (ECP) groups.
    • It supports interoperability with devices using IKEv1.
    • It exchanges a minimum of two messages to establish a secure tunnel.
    • It supports the extensible authentication protocol (EAP).
  8. Question 8 · 1

    An administrator must enable direct communication between multiple spokes in a company's network. Each spoke has more than one internet connection. The requirement is for the spokes to connect directly without passing through the hub, and for the links to automatically switch to the best available connection. How can this automatic detection and optimal link utilization between spokes be achieved?

    Choose one answer.

    • Set up OSPF routing over static VPN tunnels between spokes.
    • Utilize ADVPN 2.0 to facilitate dynamic direct tunnels and automatic link optimization.
    • Establish static VPN tunnels between spokes with predefined backup routes.
    • Implement SD-WAN policies at the hub to manage spoke link quality.
  9. Question 9 · 1

    Refer to the exhibit, which shows a physical topology and a traffic log. The administrator is checking on FortiAnalyzer traffic from the device with IP address 10.1.10.1, located behind the FortiGate ISFW device. The firewall policy in on the ISFW device does not have UTM enabled and the administrator is surprised to see a log with the action Malware, as shown in the exhibit. What are the two reasons FortiAnalyzer would display this log? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Security rating is enabled in ISFW.
    • ISFW is in a Security Fabric environment.
    • ISFW is not connected to FortiAnalyzer and must go through NGFW-1.
    • The firewall policy in NGFW-1 has UTM enabled.
  10. Question 10 · 1

    Refer to the exhibit, which contains a partial VPN configuration. What can you conclude from this VPN IPsec phase 1 configuration?

    Choose one answer.

    Question illustration 1
    • This configuration is the best for networks with regular traffic intervals, providing a balance between connectivity assurance and resource utilization.
    • Peer IDs are unencrypted and exposed, creating a security risk.
    • FortiGate will not add a route to its routing or forwarding information base when the dynamic tunnel is negotiated.
    • A separate interface is created for each dial-up tunnel, which can be slower and more resource intensive, especially in large networks.
  11. Question 11 · 1

    An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23:ff:fc:00:86. What two conclusions can the administrator draw? (Choose two.)

    Choose all answers that apply.

    • The suspicious packet is related to a cluster that has VDOMs enabled.
    • The network includes FortiGate devices configured with the FGSP protocol.
    • The suspicious packet is related to a cluster with a group-id value lower than 255.
    • The suspicious packet corresponds to port 7 on a FortiGate device.
  12. Question 12 · 1

    A company's users on an IPsec VPN between FortiGate A and B have experienced intermittent issues since implementing VXLAN. The administrator suspects that packets exceeding the 1500-byte default MTU are causing the problems. In which situation would adjusting the interface’s maximum MTU value help resolve issues caused by protocols that add extra headers to IP packets?

    Choose one answer.

    • Adjust the MTU on interfaces only if FortiGate has the FortiGuard enterprise bundle, which allows MTU modification.
    • Adjust the MTU on interfaces in all FortiGate devices that support the latest family of Fortinet SPUs: NP7, CP9 and SP5.
    • Adjust the MTU on interfaces in controlled environments where all devices along the path allow MTU interface changes.
    • Adjust the MTU on interfaces only in wired connections like PPPoE, optic fiber, and ethernet cable.
  13. Question 13 · 1

    Refer to the exhibit, which shows a command output. FortiGate_A and FortiGate_B are members of an FGSP cluster in an enterprise network. While testing the cluster using the ping command, the administrator monitors packet loss and found that the session output on FortiGate_B is as shown in the exhibit. What could be the cause of this output on FortiGate_B?

    Choose one answer.

    Question illustration 1
    • The session synchronization is encrypted.
    • session-pickup-connectionless is set to disable on FortiGate_B.
    • FortiGate_B is configured in passive mode.
    • FortiGate_A and FortiGate_B have the same standalone-group-id value.
  14. Question 14 · 1

    Refer to the exhibit, which shows a partial troubleshooting command output. An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit. What can the administrator conclude?

    Choose one answer.

    Question illustration 1
    • IPsec SAs cannot be offloaded.
    • The two IPsec SAs, inbound and outbound, are copied to the NPU.
    • Only the outbound IPsec SA is copied to the NPU.
    • Only the inbound IPsec SA is copied to the NPU.
  15. Question 15 · 1

    Refer to the exhibit, which shows a corporate network and a new remote office network. An administrator must integrate the new remote office network with the corporate enterprise network. What must the administrator do to allow routing between the two networks?

    Choose one answer.

    Question illustration 1
    • The administrator must implement BGP to inject the new remote office network into the corporate FortiGate device.
    • The administrator must configure a static route to the subnet 192.168.l.0/24 on the corporate FortiGate device.
    • The administrator must configure virtual links on both FortiGate devices.
    • The administrator must implement OSPF over IPsec on both FortiGate devices.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free