Skip to content

FCP-FCT-AD-7-2 Fortinet Certified Professional - FortiClient EMS 7.2 Administrator Practice Questions

Prepare for FCP-FCT-AD-7-2 with more than an answer.

240 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 4
  1. FortiClient EMS Setup25%
  2. FortiClient Provisioning and Deployment25%
  3. Security Fabric Integration35%
  4. Diagnostics15%
  1. 1

    True or False: An endpoint profile created in FortiClient EMS can be configured to have different Web Filter settings depending on whether the endpoint is on-fabric or off-fabric.

    Show answer details

    Correct answer: A

    True. FortiClient EMS profiles allow for location-aware policies. Within a single Web Filter profile, an administrator can define separate policies for when an endpoint is connected to the corporate network (on-fabric) versus when it is on an external network (off-fabric). This allows for more granular control, such as applying stricter filtering when users are off the protected corporate network.

  2. 2

    An administrator is reviewing the ZTNA connection process. They want to understand the exact sequence of events when a FortiClient endpoint attempts to access a resource protected by a ZTNA rule on a FortiGate. Which diagram accurately represents this flow?

    sequenceDiagram participant C as Client participant FG as FortiGate (Proxy) participant EMS participant S as Server C->>FG: HTTPS Request to Server FG->>EMS: Query Endpoint Tags (Device UID) EMS-->>FG: Return ZTNA Tags FG->>FG: Evaluate ZTNA Policy alt Policy Match FG->>S: Forward Request S-->>FG: Response FG-->>C: Forward Response else Policy Deny FG-->>C: Access Denied Page end

    Show answer details

    Correct answer: B

    The diagram correctly illustrates the ZTNA flow. The client's request is intercepted by the FortiGate acting as a proxy. The FortiGate then contacts the EMS server to retrieve the endpoint's current posture tags. Based on these tags and the user's identity, the FortiGate evaluates its ZTNA policy to grant or deny the connection. The client does not directly interact with EMS during the access request.

  3. 3

    A deployment of FortiClient using a basic MSI installer without any customization has completed on 100 new laptops. The laptops are powered on, but they do not appear in the FortiClient EMS console. What is the most probable cause for this issue?

    Show answer details

    Correct answer: C

    A basic, uncustomized MSI installer for FortiClient does not contain information about which EMS server to connect to. Without this information, the clients install successfully but do not know where to register. The installer must be customized using the FortiClient Configurator tool or deployed with command-line arguments specifying the EMS address.

  4. 4

    When troubleshooting a ZTNA connection issue, an administrator uses the FortiGate CLI to verify if the endpoint's IP and MAC addresses have been learned from EMS. Which command would they use to display this information?

    Show answer details

    Correct answer: D

    The command diagnose endpoint record list is used on the FortiGate CLI to display the list of endpoints registered via the Security Fabric connector from FortiClient EMS. This output includes crucial information for ZTNA troubleshooting, such as the learned IP address, MAC address, online status, and any assigned ZTNA tags.

  5. 5

    What is the purpose of the 'Sandbox Scan' feature within a FortiClient endpoint profile?

    Show answer details

    Correct answer: C

    The Sandbox Scan feature integrates FortiClient with a FortiSandbox appliance or cloud service. When enabled, FortiClient will automatically send suspicious files that are not identified by its local AV engine to the sandbox for deeper behavioral analysis to detect zero-day threats and advanced malware.

  6. 6

    A financial services company is implementing a Zero Trust Network Access (ZTNA) solution. The security policy requires that only corporate-owned Windows devices with the latest OS security patches and active antivirus protection can access the internal accounting application. An administrator has configured ZTNA tags in FortiClient EMS for these posture checks. Which component is responsible for enforcing the access decision based on these tags?

    Show answer details

    Correct answer: C

    In a Fortinet ZTNA solution, the FortiGate acts as the access proxy and enforcement point. It receives the connection request, queries the FortiClient EMS for the endpoint's posture tags, and then evaluates its ZTNA policy rules to either grant or deny access. FortiClient reports the posture, and EMS manages the tags, but FortiGate makes the final enforcement decision.

  7. 7

    An administrator is deploying FortiClient 7.2 to macOS endpoints using a Mobile Device Management (MDM) solution. The deployment package is pushed successfully, but the clients are not registering to the on-premise FortiClient EMS. Which of the following is the most likely reason for this failure?

    Show answer details

    Correct answer: B

    For macOS deployments via MDM, the FortiClient installer package (.pkg) itself does not contain the EMS server information. A separate configuration profile (.mobileconfig) must be created and deployed to the endpoints. This profile contains the necessary settings, including the EMS IP address, to allow the client to register.

  8. 8

    A system administrator is analyzing the FortiClient EMS dashboard and notices several endpoints are flagged with high-risk vulnerabilities related to outdated Adobe Acrobat Reader versions. A compliance rule is in place to automatically quarantine devices with critical vulnerabilities. However, none of the affected devices are being quarantined. What is the most likely misconfiguration?

    Show answer details

    Correct answer: C

    For a compliance rule to take an enforcement action like quarantine, the action must be explicitly set to 'Quarantine'. If it is set to 'Monitor', EMS will detect the non-compliance and report it, but it will not automatically isolate the device. Since vulnerabilities are being reported but no quarantine is happening, this is the most probable cause.

  9. 9

    Which two of the following are required to successfully deploy and manage FortiClient on Chromebooks using FortiClient EMS? (Select TWO).

    Show answer details

    Correct answer: B, D

  10. 10

    True or False: When using FortiClient EMS to deploy a configuration to Windows endpoints via an MSI package, the EMS server IP address and other settings can be embedded directly into the MSI file itself using the FortiClient Configurator tool.

    Show answer details

    Correct answer: A

    True. The FortiClient Configurator tool allows an administrator to customize the FortiClient MSI installer. This includes embedding the EMS server IP address, pre-configuring features, and setting a silent installation flag, which simplifies mass deployment through tools like GPO or SCCM.

Create an account to continue.