Skip to content

FCP-FWF-AD-7-4 Fortinet FCP - Secure Wireless LAN 7.4 Administrator Practice Questions

Prepare for FCP-FWF-AD-7-4 with more than an answer.

220 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 4
  1. Wireless fundamentals and FortiAP management25%
  2. Wireless network security and access25%
  3. Wireless monitoring and protection25%
  4. Wireless diagnostics and analytics25%
  1. 1

    Which two statements accurately describe the behavior and purpose of Protected Management Frames (PMF), also known as 802.11w? (Select TWO)

    Show answer details

    Correct answer: B, D

    The primary purpose of PMF is to ensure the integrity and authenticity of specific management frames, preventing attackers from spoofing them to launch denial-of-service attacks. WPA3 certification requires PMF to be enabled, making it a core component of the enhanced security standard.

    The primary purpose of PMF is to ensure the integrity and authenticity of specific management frames, preventing attackers from spoofing them to launch denial-of-service attacks. WPA3 certification requires PMF to be enabled, making it a core component of the enhanced security standard.

  2. 2

    A FortiGate is managing 50 FortiAPs. The administrator needs to reboot a single, specific FortiAP that is experiencing issues, without affecting any other APs. Which is the most direct method to accomplish this from the FortiGate GUI?

    Show answer details

    Correct answer: B

    The FortiGate GUI provides a simple, direct way to manage individual APs. Navigating to the Managed FortiAPs list allows an administrator to perform actions like restarting, deauthorizing, or upgrading firmware on a per-AP basis.

  3. 3

    What is the function of the AC_IPADDR_1 and AC_CTL_PORT variables when manually configuring a FortiAP from its CLI with cfg -a?

    Show answer details

    Correct answer: C

    On the FortiAP CLI, cfg -a AC_IPADDR_1= (up to AC_IPADDR_3) statically sets the wireless controller address for static discovery. cfg -a AC_CTL_PORT= sets the CAPWAP control port, which defaults to UDP 5246. cfg -c commits the changes. These variables are not used for the local management GUI, RADIUS or syslog.

  4. 4

    A wireless network is experiencing intermittent connectivity issues. The administrator suspects RF interference. Which FortiGate GUI tool provides a real-time graphical view of the radio frequency spectrum, helping to identify sources of non-802.11 interference?

    Show answer details

    Correct answer: B

    The Spectrum Analysis tool, available from the Managed FortiAPs page, uses a FortiAP's radio to scan the RF environment and display a real-time spectrogram. This allows administrators to visually identify sources of interference, such as microwave ovens, cordless phones, or Bluetooth devices, that are not Wi-Fi traffic but can disrupt wireless communications.

  5. 5

    True or False: When configuring a FortiAP mesh topology, the mesh backhaul SSID must be broadcast on a different radio band than the SSIDs serving clients.

    Show answer details

    Correct answer: B

    While it is a best practice to use a dedicated band (typically 5 GHz or 6 GHz) for the mesh backhaul to avoid performance degradation, it is not a strict requirement. A FortiAP can use the same radio to both serve clients and connect to the mesh backhaul, though this will result in reduced throughput for clients connected to the leaf AP.

  6. 6

    A hospital is deploying a Fortinet wireless network for both medical staff and patients. The security policy mandates that staff devices using 802.1X authentication are placed in VLAN 10, while patient guest devices using a FortiGate-hosted captive portal are placed in VLAN 20. Both SSIDs are broadcast from the same FortiAP-U series access points, and the policy also requires that all wireless client traffic be carried to the FortiGate over CAPWAP so that the FortiGate enforces the firewall policies for both groups. Which FortiAP SSID traffic mode meets these requirements?

    Show answer details

    Correct answer: C

    In Tunnel mode, all wireless client traffic is encapsulated in CAPWAP and delivered to the FortiGate wireless controller, where each SSID (and its VLAN) terminates on a FortiGate interface. The FortiGate therefore enforces firewall policies and hosts the captive portal for both groups. In Bridge mode, traffic is placed directly onto the local LAN at the FortiAP and is not carried to the FortiGate over CAPWAP.

  7. 7

    A retail company is experiencing poor wireless performance in its high-density warehouse environment. The administrator observes that a few older 802.11n clients are consuming a disproportionate amount of airtime, slowing down newer 802.11ax clients. Which two FortiAP profile features should be configured to mitigate this issue? (Select TWO)

    Show answer details

    Correct answer: A, C

    Airtime fairness is aimed at the case where slow or distant clients monopolize airtime. In FortiOS it applies to downlink data, and each SSID (VAP) gets airtime by its configured weight (atf-weight, default 20%), so slower clients cannot starve the others. Band steering (frequency handoff) keeps dual-band clients that have a strong 5 GHz signal off 2.4 GHz, which reduces contention with legacy clients. Client load balancing responds to per-AP client counts, channel bonding widens channels, and WMM prioritizes traffic classes; none of these address slow clients taking airtime.

    Airtime fairness is aimed at the case where slow or distant clients monopolize airtime. In FortiOS it applies to downlink data, and each SSID (VAP) gets airtime by its configured weight (atf-weight, default 20%), so slower clients cannot starve the others. Band steering (frequency handoff) keeps dual-band clients that have a strong 5 GHz signal off 2.4 GHz, which reduces contention with legacy clients. Client load balancing responds to per-AP client counts, channel bonding widens channels, and WMM prioritizes traffic classes; none of these address slow clients taking airtime.

  8. 8

    A wireless administrator is troubleshooting a client connectivity issue where a user fails to authenticate to an 802.1X EAP-TLS SSID. The RADIUS server logs show no authentication attempt from the client. The administrator suspects a problem with the CAPWAP tunnel between the FortiAP and the FortiGate. Which CLI command on the FortiGate would provide real-time debug information about CAPWAP control messages to diagnose this issue?

    Show answer details

    Correct answer: A

    The diagnose debug application cw_acd -1 command enables debugging for the CAPWAP AC daemon (cw_acd), which handles the CAPWAP control plane communication between the FortiGate (AC) and FortiAPs. This output would show messages related to tunnel establishment, keepalives, and configuration pushes, helping to identify if the control channel is functioning correctly.

  9. 9

    True or False: When a FortiAP is operating in dedicated monitor mode, it can simultaneously serve wireless clients and perform background scanning for rogue APs.

    Show answer details

    Correct answer: B

    In dedicated monitor mode, the FortiAP's radios are used exclusively for scanning the RF environment for threats like rogue APs and do not broadcast any SSIDs or serve clients. Background scanning is a feature of APs operating in standard AP mode.

  10. 10

    A university is deploying a large number of new FortiAPs across many campus subnets that are routed to a central FortiGate wireless controller. The team wants every new FortiAP to find the controller automatically, with no per-AP configuration. Which method should be implemented?

    Show answer details

    Correct answer: B

    FortiAPs try discovery methods automatically in the order static, DHCP, DNS, FortiCloud, multicast, broadcast. With DHCP discovery, the campus DHCP servers return option 138 containing the controller IP (hex encoded, for example C0A80001 for 192.168.0.1). Every new FortiAP learns where its controller is with no per-AP configuration, even on subnets other than the controller's. Broadcast works only in the controller's Layer 2 domain, and a manual AC_IPADDR setting needs per-AP work.

Create an account to continue.