Skip to content

FCSS-EFW-AD-7-4 FCSS - Enterprise Firewall 7.4 Administrator Practice Questions

Prepare for FCSS-EFW-AD-7-4 with more than an answer.

204 questions in the full set20 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Version 1 204 questions Current
  • NSE7_EFW-6.2Legacy Fortinet NSE 7 - Enterprise Firewall 6.2 53 questions Locked
  • NSE7-EFW-7-0Legacy Fortinet NSE 7 - Enterprise Firewall 7.0 222 questions Locked
  • NSE7-EFW-7-2Legacy Fortinet NSE 7 - Enterprise Firewall 7.2 203 questions Locked
Exam fee
$200 USD
Level
Solution Specialist
Valid for
2 years from second exam completion
Domains covered on the exam 5
  1. System Configuration
  2. Central Management
  3. Security Profiles
  4. Routing
  5. VPN Configuration
  1. 1

    A global logistics company, GlobaLink, is deploying a large-scale SD-WAN and ADVPN solution managed by FortiManager. The goal is to provide resilient connectivity for over 300 branch offices to two main data centers (DC1 and DC2).

    Company Background:
    GlobaLink operates on a global scale with critical applications hosted in DC1 and DC2. Branch offices rely on dual-WAN links (MPLS and Broadband) for connectivity. The company wants to leverage SD-WAN to optimize application performance and reduce MPLS costs, while using ADVPN for efficient branch-to-branch communication without hair-pinning traffic through the data centers.

    Current Situation & Requirements:
    The network team has configured FortiManager with a single ADOM for all 300+ devices. They are using provisioning templates with metadata variables to handle unique branch settings. The design calls for two ADVPN hubs, one in each data center, for redundancy. All branches (spokes) must be able to build dynamic tunnels to each other and fail over between the hubs if one becomes unreachable. The primary requirement is to ensure the ADVPN shortcut traffic (branch-to-branch) is correctly routed and does not interfere with the SD-WAN's primary path selection for DC-bound traffic.

    Problem:
    After deployment, administrators notice that branch-to-branch traffic is intermittently being sent to the data center hubs instead of directly between spokes. This increases latency and consumes unnecessary bandwidth at the data centers. The SD-WAN rules are correctly steering application traffic to the data centers over the best available link. The issue appears to be with how ADVPN shortcut traffic is handled. Which configuration is essential to ensure ADVPN shortcut traffic is prioritized for the dynamic spoke-to-spoke tunnels and does not get routed through the hub?

    graph TD subgraph Data Center 1 Hub1[ADVPN Hub 1] end subgraph Data Center 2 Hub2[ADVPN Hub 2] end Spoke1[Branch 1] -- Overlay --> Hub1 Spoke1 -- Overlay --> Hub2 Spoke2[Branch 2] -- Overlay --> Hub1 Spoke2 -- Overlay --> Hub2 SpokeN[Branch N] -- Overlay --> Hub1 SpokeN -- Overlay --> Hub2 Spoke1 |ADVPN Shortcut (Issue)| Spoke2 Spoke1 -->|Hair-pinning| Hub1 --> Spoke2 style Spoke1 fill:#f9f,stroke:#333,stroke-width:2px style Spoke2 fill:#f9f,stroke:#333,stroke-width:2px style SpokeN fill:#f9f,stroke:#333,stroke-width:2px

    Show answer details

    Correct answer: B

    In a combined ADVPN and SD-WAN environment, routing decisions are critical. When a spoke learns a route to another spoke's subnet from both the hub and directly from the spoke via a newly formed shortcut, it needs a way to prefer the shortcut path. By using iBGP as the routing protocol over the overlay, you can leverage the advpn-shortcut-priority setting. Setting a higher priority for routes learned directly from spokes ensures the FortiGate prefers the dynamic tunnel, resolving the hair-pinning issue.

  2. 2

    A system administrator is tasked with backing up the configuration of a standalone FortiGate device that is not managed by FortiManager. The administrator needs to ensure the backup file includes all settings, certificates, and firmware. Which backup method should be used?

    Show answer details

    Correct answer: C

    A standard, unencrypted backup from the FortiGate GUI saves the configuration file but excludes sensitive information like private keys for certificates and user passwords. To perform a complete backup that includes all system data, including certificates, you must select the option to encrypt the backup file and provide a password.

  3. 3

    A retail chain, 'ShopSmart', is deploying FortiGate devices at 150 stores. The central IT team uses FortiManager for zero-touch provisioning (ZTP). The process involves a store employee plugging in the FortiGate, which then connects to FortiDeploy to get the FortiManager's IP address.

    Deployment Plan:
    The core of the ZTP process relies on FortiDeploy, a cloud-based service, to direct the new FortiGates to the on-premise FortiManager. Once connected to FortiManager, a provisioning template is applied, which configures basic networking, security policies, and an IPsec tunnel back to the corporate headquarters.

    Current Situation & Problem:
    A new batch of 20 FortiGates is being deployed. One specific store reports that its new FortiGate is online and has internet access, but it never appears in the FortiManager's 'Model Devices' list for authorization. The IT team has confirmed the device's serial number was correctly added to the FortiDeploy portal. They have also verified that other devices from the same batch have connected successfully. The local store employee confirms the device is powered on and connected to the internet modem.

    Troubleshooting Goal:
    What is the most probable reason for this specific FortiGate failing to register with FortiManager, despite having internet access and being correctly listed in FortiDeploy?

    sequenceDiagram participant FG as New FortiGate participant ISP participant FD as FortiDeploy participant FM as FortiManager FG->>ISP: DHCP Request ISP-->>FG: IP Address & DNS FG->>FD: Registration (Serial Number) FD-->>FG: FortiManager IP & Key FG->>FM: Authorization Request Note right of FM: This step is failing!

    Show answer details

    Correct answer: B

    The sequence diagram shows the FortiGate successfully contacts FortiDeploy and receives the FortiManager's IP. The failure occurs at the next step: the FortiGate's attempt to contact the FortiManager. Since the device has general internet access but cannot reach a specific public IP, the most likely cause is a network-level block. This could be an upstream firewall at the store's location or the ISP filtering the specific ports (typically TCP/541) required for FortiManager communication.

  4. 4

    A FortiGate is configured to use the FortiGuard Botnet C&C database for DNS lookups. An internal client attempts to resolve a domain name that is listed in this database. What action will the FortiGate take?

    Show answer details

    Correct answer: C

    When the Botnet C&C feature is enabled in a DNS Filter profile, the FortiGate intercepts DNS requests. If a requested domain matches an entry in the FortiGuard botnet database, the FortiGate will not forward the query. Instead, it will return a fake response, typically pointing the client to a sinkhole IP address, which prevents the client from connecting to the malicious command-and-control server.

  5. 5

    When troubleshooting a high CPU issue on a FortiGate, the output of the get system performance status command shows that the ipsengine process is consuming 80% of the CPU resources. What is the most effective next step to diagnose the cause of the high CPU utilization by the IPS engine?

    Show answer details

    Correct answer: B

    The command diag test application ipsmonitor 99 provides detailed, real-time statistics from the IPS engine, including information about specific signatures, protocols being scanned, and potential performance bottlenecks. This is the most direct and effective diagnostic tool to understand exactly what the ipsengine process is doing that is causing the high CPU load.

  6. 6

    A financial services company is using FortiManager to centrally manage 50 FortiGate devices. An administrator needs to push a standardized web filtering security profile to all devices, but each device requires a unique override for a specific local regulatory website. What is the most efficient method to achieve this in FortiManager?

    Show answer details

    Correct answer: B

    The most efficient method is to use a single policy package for consistency and apply per-device mapping for the specific objects that need to be unique, such as the URL filter entry. This avoids the massive overhead of managing 50 separate policy packages and leverages FortiManager's dynamic object capabilities.

  7. 7

    An e-commerce platform uses an Auto-Discovery VPN (ADVPN) network with one hub and 20 spokes. The lead network architect wants to ensure that if the primary hub fails, ADVPN functionality remains operational with minimal downtime. Which two design choices should be implemented to achieve high availability for the ADVPN hub? (Select TWO)

    Show answer details

    Correct answer: A, B

    To achieve hub redundancy in an ADVPN setup, you can either use a standard FortiGate HA cluster for the hub role, which provides device-level failover, or deploy two independent hubs and configure spokes to establish tunnels to both. The latter provides greater resiliency, including against ISP or site failure at the primary hub location.

  8. 8

    True or False: In a FortiGate Active-Passive HA cluster, enabling session pickup (session-pickup enable) guarantees that all active sessions, including UDP and ICMP, will be seamlessly transferred to the secondary unit upon a failover event.

    Show answer details

    Correct answer: B

    This statement is false. While session pickup synchronizes TCP sessions, it does not synchronize connectionless sessions like UDP and ICMP by default. These sessions will be dropped and must be re-established after a failover. For some specific protocols like SIP, session helpers can assist, but it is not a universal guarantee for all session types.

  9. 9

    A hospital's security team is deploying deep SSL inspection on their FortiGate. They need to exempt traffic destined for specific healthcare record services that use certificate pinning and will break if inspected. However, they must inspect all other HTTPS traffic for compliance. What is the recommended approach to configure this exclusion within the SSL Inspection profile?

    Show answer details

    Correct answer: B

    The correct and most direct method is to add the fully qualified domain names (FQDNs) of the problematic services to the exemption list within the SSL/SSH Inspection profile itself. This allows the firewall policy to remain simple while giving granular control over which destinations are bypassed by the deep inspection engine.

  10. 10

    During a security audit, an administrator discovers that a FortiGate is configured with two default routes with the same distance but different priorities. Route 1 has a priority of 10 and Route 2 has a priority of 20. Both routes are active in the routing table. How will the FortiGate handle traffic matching these routes?

    Show answer details

    Correct answer: B

    In FortiOS, when two static routes have the same destination and administrative distance, the route with the lower priority value is considered superior and will be installed as the active route in the routing table. The higher priority route will only be used if the lower priority route becomes inactive.

Create an account to continue.