Skip to content

FCP-FGT-AD-7-4 FCP - FortiGate 7.4 Administrator Practice Questions

Prepare for FCP-FGT-AD-7-4 with more than an answer.

234 questions in the full set20 sample questionsUpdated Dec 7, 2025
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Deployment and System Configuration20%
  2. Firewall Policies and Authentication25%
  3. Content Inspection20%
  4. Routing15%
  5. VPN20%
  1. 1

    An administrator is investigating high memory usage on a FortiGate device. After running get system performance status, the output shows memory usage at 92%. The default memory thresholds are configured. What is the operational state of the FortiGate, and what is the primary impact on traffic inspection?

    Default Thresholds:
    memory-use-threshold-extreme 95
    memory-use-threshold-red 88
    memory-use-threshold-green 82

    Show answer details

    Correct answer: D

    At 92% memory use the FortiGate is above memory-use-threshold-red (default 88%) but below memory-use-threshold-extreme (default 95%), so it is in conserve mode. Proxy behaviour in conserve mode is controlled by 'config system global / set av-failopen', whose default is 'pass': traffic bypasses the antivirus proxy and continues without proxy-based inspection. (Setting av-failopen off would instead block new sessions that need the antivirus proxy.) Source: FortiOS 7.4 Administration Guide, Conserve mode.

  2. 2

    A security team wants to prevent users from accessing specific web pages containing keywords like confidential-project-alpha, regardless of the website's category. What FortiGate feature is best suited for this requirement?

    Show answer details

    Correct answer: D

    The Web Content Filter feature, part of the Web Filter security profile, is designed specifically to scan the content of web pages for specific patterns or keywords. By creating a content filter entry for confidential-project-alpha, the FortiGate can block any page containing this phrase, providing a more granular level of control than category or URL filtering alone.

  3. 3

    A retail company has deployed SD-WAN across its stores. An administrator is analyzing the SD-WAN performance and notices that one of the two ISP links is consistently marked as 'dead' by the Performance SLA health check, even though the link is up and passing traffic for other non-SD-WAN purposes. What is a common cause for a health check to fail while the underlying interface is still active?

    Show answer details

    Correct answer: D

    SD-WAN health-check probes are self-originated (local-out) traffic from the FortiGate. Self-originated traffic does not need a firewall policy to leave the FortiGate, so a missing or restrictive firewall policy is not why a probe fails. If the probe server drops or rate-limits the probe protocol on that path (common with ICMP to a public resolver such as 8.8.8.8), the FortiGate records loss or latency. After the configured number of consecutive failures it marks the member dead, even though the circuit carries user traffic fine. Fortinet recommends reliable probe servers or several servers per health check. Sources: FortiOS 7.4 Administration Guide, Local out traffic and Performance SLA; Fortinet Community, 'Self-originated traffic and policy-based IPsec'.

  4. 4

    An administrator needs to create a fully meshed IPsec VPN between three branch office FortiGates without manually configuring every tunnel on every device. The solution should allow for dynamic discovery of new spokes and direct spoke-to-spoke communication. Which technology should be used?

    Show answer details

    Correct answer: A

    Auto-Discovery VPN (ADVPN) is a Fortinet technology built on top of a standard hub-and-spoke IPsec VPN. It allows spokes to create dynamic, on-demand tunnels directly with other spokes, bypassing the hub for data traffic. This creates a fully meshed topology without the administrative overhead of manually configuring n(n-1)/2 tunnels, and it supports dynamic discovery of peers.

  5. 5

    An administrator is troubleshooting a connectivity issue for a user at 10.1.1.50 trying to reach a server at 172.16.10.100. They run a debug flow and observe that the traffic is matching policyid=0.

    Based on the diagram and the debug flow finding, what is the reason for the connection failure?

    flowchart TD User(User 10.1.1.50) -- 1. SYN --> FGT[FortiGate] FGT -- 2. Policy ID 0 --> Deny((Implicit Deny)) FGT -. 3. No Reply .-> User

    Show answer details

    Correct answer: B

    In a diagnose debug flow output, policyid=0 specifically refers to the implicit deny rule. This rule is at the very end of the policy table and is not visible in the GUI. It denies any traffic that has not been explicitly allowed by a preceding firewall policy. Therefore, seeing policyid=0 is a clear indication that no configured firewall policy matched the traffic's parameters (source, destination, service, etc.).

  6. 6

    A financial services company is deploying a new FortiGate 200F cluster. The primary requirement is to ensure that if the primary unit fails, all active sessions, including long-lived TCP sessions for stock market data feeds, are seamlessly transferred to the secondary unit without interruption. Which FortiGate Clustering Protocol (FGCP) configuration setting is essential to meet this requirement?

    Show answer details

    Correct answer: D

    The set session-pickup enable command is critical for ensuring stateful failover in an FGCP cluster. When enabled, the primary unit synchronizes its session table with the secondary unit. In the event of a failover, the new primary unit can use this synchronized information to take over existing sessions without requiring them to be re-established, which is essential for applications like financial data feeds.

  7. 7

    An administrator is configuring a destination NAT (DNAT) policy using a virtual IP (VIP) to forward inbound traffic from the internet to an internal web server. Internet users connect on TCP port 80, but the web server listens on TCP port 8080. The external IP for the VIP is 203.0.113.10, and the internal server's IP is 192.168.1.100. Which two of the following VIP configurations are required to correctly translate both the destination IP address and the port? (Choose two.)

    Show answer details

    Correct answer: C, D

    Translating the destination port requires enabling Port Forwarding on the VIP; this exposes the External service port (CLI extport) and Map to IPv4 port (CLI mappedport) fields, which must be set to 80 and 8080. Without port forwarding, the FortiGate translates only the IP and forwards to port 80. ARP reply is enabled by default and static NAT is already the default VIP type. Source: FortiOS 7.4 Administration Guide, Static virtual IPs.

    Translating the destination port requires enabling Port Forwarding on the VIP; this exposes the External service port (CLI extport) and Map to IPv4 port (CLI mappedport) fields, which must be set to 80 and 8080. Without port forwarding, the FortiGate translates only the IP and forwards to port 80. ARP reply is enabled by default and static NAT is already the default VIP type. Source: FortiOS 7.4 Administration Guide, Static virtual IPs.

  8. 8

    A hospital's FortiGate uses web filtering to block social media sites for clinical staff. However, IT staff need access to these sites for research and support, whichever workstation they log on to. The administrator has created two Active Directory groups, Clinical_Staff and IT_Staff, which are monitored by the FSSO Collector Agent and mapped to FSSO user groups on the FortiGate. What is the most efficient way to enforce this requirement using FSSO?

    Show answer details

    Correct answer: A

    FortiGate evaluates firewall policies from top to bottom and applies the first match. With both AD groups mapped to FSSO user groups on the FortiGate, a policy for IT_Staff with a lenient web filter placed above a policy for Clinical_Staff with a restrictive web filter ensures IT users match their rule first, wherever they log on, while clinical staff match the restrictive rule. This is the standard way to apply different security profiles to different user groups. Source: FortiOS 7.4 Administration Guide, Firewall policy / FSSO.

  9. 9

    True or False: When using full SSL inspection on a FortiGate, the Fortinet_CA_SSL certificate must be installed on the FortiGate itself, but does not need to be installed on end-user client browsers.

    Show answer details

    Correct answer: B

    This statement is false. For full SSL inspection (deep inspection) to work without causing certificate errors, the FortiGate's certificate authority (CA) certificate (e.g., Fortinet_CA_SSL) must be trusted by the end-user's client browser. This requires installing the CA certificate into the trusted root certificate store of each client machine or browser.

  10. 10

    A network administrator is troubleshooting an issue where traffic to 10.50.20.5 is leaving the FortiGate through the default route instead of the more specific static route. The routing table shows both the specific static route and the default route are active. The specific route is for network 10.50.0.0/16 via gateway 10.100.1.1, and the default route is 0.0.0.0/0 via gateway 192.168.1.254. What is the most likely reason for this behavior?

    Show answer details

    Correct answer: C

    For a destination such as 10.50.20.5, the routing table lookup would select the 10.50.0.0/16 static route because of longest prefix match; administrative distance and priority are only compared between routes to the same prefix. However, FortiGate checks policy-based routes before the routing table (FIB). If a policy route matches the traffic and its action is to forward it to 192.168.1.254, that decision overrides the routing table. Check with 'diagnose firewall proute list' or the Policy Routes list. Source: FortiOS 7.4 Administration Guide, 'Routing concepts' (Route look-up).

Create an account to continue.