Skip to content

NSE4_FGT_AD-7.6 Fortinet NSE 4 - FortiOS 7.6 Administrator Practice Questions

Prepare for NSE4_FGT_AD-7.6 with more than an answer.

125 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$200 USD
Time limit
90 minutes
Questions on the exam
50
Passing score
Pass/Fail (scale Pass/Fail)
Level
Professional
Valid for
2 years (from date of second exam in FCP track)
Domains covered on the exam 5
  1. Deployment and System Configuration24%
  2. Firewall Policies and Authentication24%
  3. Content Inspection28%
  4. Routing12%
  5. VPN12%
  1. 1

    An organization requires that all traffic to banking websites is NOT decrypted by the FortiGate due to privacy compliance, while all other HTTPS traffic should be inspected for malware. Which configuration step ensures this exemption?

    Show answer details

    Correct answer: D

    FortiOS SSL/TLS inspection profiles include an 'Exempt from SSL Inspection' table. By adding the FortiGuard category 'Finance and Banking' to this list, the FortiGate will bypass Deep Inspection for sites matching this category, maintaining user privacy while still inspecting other categories.

  2. 2

    What is the primary function of the diagnose debug flow command when troubleshooting traffic issues on a FortiGate?

    Show answer details

    Correct answer: B

    diagnose debug flow is a packet tracing tool that shows the step-by-step processing of a packet by the kernel. It reveals ingress interface, route lookup, policy matching (ID), NAT application, and egress interface. It is distinct from packet sniffing which only captures the raw data.

  3. 3

    Which of the following routing attributes is used to determine the best route when two static routes to the same destination have the same distance but different priorities?

    Show answer details

    Correct answer: C

    FortiGate route selection: most specific prefix first, then lowest administrative distance. When the distance is equal, both routes are added to the routing table, and the route with the lower priority value is preferred for traffic. If distance and priority are both equal, the routes are used for ECMP.

  4. 4

    An administrator is configuring an FGCP active-passive HA cluster between two FortiGate 100F devices (FortiOS 7.6). If the primary device (FGT-A) fails, the secondary must take over. The administrator also wants FGT-A to automatically take back the primary role whenever it rejoins the cluster, even though its HA uptime is then lower than the secondary's.

    Which configuration achieves this preemption behavior?

    Show answer details

    Correct answer: D

    With override disabled (the default), primary selection compares monitored interfaces, then HA uptime (differences below ha-uptime-diff-margin, default 300 s, are ignored), then priority, then serial number. A unit that rebooted has its uptime reset, so it does not reclaim the primary role. Enabling override makes device priority count before uptime (monitored interfaces, priority, uptime, serial). FGT-A, configured with the higher priority (default 128), therefore becomes primary again when it rejoins. Enable override on the cluster members; override-wait-time (default 0) can delay renegotiation to reduce flapping. session-pickup-delay only limits session sync to sessions older than 30 seconds.

  5. 5

    A network architect has deployed a Fortinet Security Fabric (FortiOS 7.6) across three sites. The Headquarters (HQ) FortiGate is the root, and two branch FortiGates are downstream devices. Both branches appear as authorized, online members in the Fabric topology. However, address objects created on the root with Fabric synchronization enabled are not appearing on the branches. Referring to the exhibit, what is the most likely cause?

    graph TD HQ["HQ FortiGate (Root)"] -- TCP/8013 --> SW[Switch] SW -- TCP/8013 --> B1["Branch 1 (Downstream)"] SW -- TCP/8013 --> B2["Branch 2 (Downstream)"] style HQ fill:#f9f,stroke:#333,stroke-width:2px style B1 fill:#ccf,stroke:#333,stroke-width:2px style B2 fill:#ccf,stroke:#333,stroke-width:2px
    Show answer details

    Correct answer: D

    When the Security Fabric is enabled, global objects such as addresses, services and schedules are synchronized from the upstream FortiGate to downstream devices by default. This is controlled on the root by config system csf > set fabric-object-unification {default | local}: with default, global CMDB objects are synchronized, and with local they are not. Individual objects must also have Fabric synchronization (fabric-object) enabled. Because the branches are already authorized and online, the Fabric link on TCP 8013 (the default upstream-port) is working and authorization is not the problem.

  6. 6

    An administrator is troubleshooting a connectivity issue where users cannot access a specific web server. The administrator runs the diagnose debug flow command. Based on the output below, what is the specific reason the packet is being dropped?

    id=20085 trace_id=1 func=print_pkt_detail line=5844 msg="vd-root:0 received a packet(proto=6, 192.168.1.10:54322->10.0.2.50:80) from port2. flag [S], seq 3452345234, ack 0, win 65535"
    id=20085 trace_id=1 func=init_ip_session_common line=5561 msg="allocate a new session-0000a1b2"
    id=20085 trace_id=1 func=vf_ip_route_input_common line=2605 msg="find a route: flag=04000000 gw-10.0.2.50 via port3"
    id=20085 trace_id=1 func=fw_forward_handler line=832 msg="Denied by forward policy check (policy 0)"

    Show answer details

    Correct answer: A

    The debug message 'Denied by forward policy check (policy 0)' specifically indicates that the packet failed to match any user-defined firewall policy and hit the default implicit deny policy, which has an ID of 0. This means there is no valid firewall policy allowing traffic from 192.168.1.10 to 10.0.2.50 on port 80.

Create an account to continue.