Fortinet Certified Professional - FortiGate 7.4 Administrator Free Sample Questions

20 free sample questions234 in the full practice test

Try simulator

FCP-FGT-AD-7-4 Sample Questions

  1. Question 1

    A financial services company is deploying a new FortiGate 200F cluster. The primary requirement is to ensure that if the primary unit fails, all active sessions, including long-lived TCP sessions for stock market data feeds, are seamlessly transferred to the secondary unit without interruption. Which FortiGate Clustering Protocol (FGCP) configuration setting is essential to meet this requirement?

    Answer and explanation

    Correct answer: B

    The set session-pickup enable command is critical for ensuring stateful failover in an FGCP cluster. When enabled, the primary unit synchronizes its session table with the secondary unit. In the event of a failover, the new primary unit can use this synchronized information to take over existing sessions without requiring them to be re-established, which is essential for applications like financial data feeds.

  2. Question 2

    Multiple answers

    An administrator is configuring a destination NAT (DNAT) policy using a virtual IP (VIP) to forward inbound traffic from the internet to an internal web server. Internet users connect on TCP port 80, but the web server listens on TCP port 8080. The external IP for the VIP is 203.0.113.10, and the internal server's IP is 192.168.1.100. Which two of the following VIP configurations are required to correctly translate both the destination IP address and the port? (Choose two.)

    Answer and explanation

    Correct answers: A, B

    Translating the destination port requires enabling Port Forwarding on the VIP; this exposes the External service port (CLI extport) and Map to IPv4 port (CLI mappedport) fields, which must be set to 80 and 8080. Without port forwarding, the FortiGate translates only the IP and forwards to port 80. ARP reply is enabled by default and static NAT is already the default VIP type. Source: FortiOS 7.4 Administration Guide, Static virtual IPs.

  3. Question 3

    A hospital's FortiGate uses web filtering to block social media sites for clinical staff. However, IT staff need access to these sites for research and support, whichever workstation they log on to. The administrator has created two Active Directory groups, Clinical_Staff and IT_Staff, which are monitored by the FSSO Collector Agent and mapped to FSSO user groups on the FortiGate. What is the most efficient way to enforce this requirement using FSSO?

    Answer and explanation

    Correct answer: A

    FortiGate evaluates firewall policies from top to bottom and applies the first match. With both AD groups mapped to FSSO user groups on the FortiGate, a policy for IT_Staff with a lenient web filter placed above a policy for Clinical_Staff with a restrictive web filter ensures IT users match their rule first, wherever they log on, while clinical staff match the restrictive rule. This is the standard way to apply different security profiles to different user groups. Source: FortiOS 7.4 Administration Guide, Firewall policy / FSSO.

  4. Question 4

    True or False: When using full SSL inspection on a FortiGate, the Fortinet_CA_SSL certificate must be installed on the FortiGate itself, but does not need to be installed on end-user client browsers.

    Answer and explanation

    Correct answer: B

    This statement is false. For full SSL inspection (deep inspection) to work without causing certificate errors, the FortiGate's certificate authority (CA) certificate (e.g., Fortinet_CA_SSL) must be trusted by the end-user's client browser. This requires installing the CA certificate into the trusted root certificate store of each client machine or browser.

  5. Question 5

    A network administrator is troubleshooting an issue where traffic to 10.50.20.5 is leaving the FortiGate through the default route instead of the more specific static route. The routing table shows both the specific static route and the default route are active. The specific route is for network 10.50.0.0/16 via gateway 10.100.1.1, and the default route is 0.0.0.0/0 via gateway 192.168.1.254. What is the most likely reason for this behavior?

    Answer and explanation

    Correct answer: C

    For a destination such as 10.50.20.5, the routing table lookup would select the 10.50.0.0/16 static route because of longest prefix match; administrative distance and priority are only compared between routes to the same prefix. However, FortiGate checks policy-based routes before the routing table (FIB). If a policy route matches the traffic and its action is to forward it to 192.168.1.254, that decision overrides the routing table. Check with 'diagnose firewall proute list' or the Policy Routes list. Source: FortiOS 7.4 Administration Guide, 'Routing concepts' (Route look-up).

  6. Question 6

    Multiple answers

    A company has two WAN connections, WAN1 (Fiber) and WAN2 (Cable), and wants to use SD-WAN to route business-critical traffic (Salesforce, Office 365) over the link with the lowest latency. All other traffic should be load-balanced based on volume. Which SD-WAN components must be configured to achieve this? (Choose three.)

    Answer and explanation

    Correct answers: A, B, C

    A Performance SLA (Service Level Agreement) is required to actively monitor the quality of the WAN links. To make decisions based on latency, an SLA must be configured to probe the links and measure this specific metric.

    An SD-WAN rule is needed to identify the specific traffic (Salesforce, O365) and apply a routing strategy. The Best Quality strategy, tied to the latency-measuring Performance SLA, will ensure this traffic is sent over the link that currently has the lowest latency.

    The implicit rule, which is the last rule in the list, catches all traffic not matched by previous rules. To meet the requirement for all other traffic, this rule must be configured with a volume-based load-balancing algorithm.

  7. Question 7

    When configuring an SSL VPN in web mode, what is the primary function of a bookmark?

    Answer and explanation

    Correct answer: A

    In SSL VPN web mode, bookmarks are shortcuts displayed on the portal page that allow users to easily access internal resources like web servers, RDP, or SSH without needing to know the internal IP address or URL. The FortiGate proxies the connection on behalf of the user.

  8. Question 8

    During the configuration of a site-to-site IPsec VPN tunnel, the administrator is setting up the Phase 1 parameters. Which of the following settings must match exactly on both peers for the Phase 1 tunnel to establish successfully?

    Answer and explanation

    Correct answer: B

    For a Phase 1 IKE negotiation to succeed, both VPN peers must be configured with an identical set of proposals. This includes the preshared key (or certificate), the encryption algorithm (e.g., AES256), the authentication algorithm (e.g., SHA256), and the Diffie-Hellman group. A mismatch in any of these will cause the Phase 1 negotiation to fail.

  9. Question 9

    A systems administrator is configuring a new administrator account on a FortiGate. The security policy requires that this administrator should only be able to view and manage firewall policies and routing settings, without the ability to change system-level settings or other security profiles. Which feature should be used to enforce this level of access?

    Answer and explanation

    Correct answer: C

    Admin Profiles provide granular, role-based access control (RBAC) for FortiGate administrators. By creating a custom admin profile, you can specify read, write, or no access for each functional area of the configuration, such as Firewall, Router, System, and Security Profiles. This is the correct method for limiting an administrator's permissions to specific tasks.

  10. Question 10

    An e-commerce company uses a FortiGate firewall. They have a firewall policy allowing outbound traffic from their internal network to the internet. This policy uses an IP Pool configured for One-to-One NAT with a small range of public IPs. During peak sales, some internal users report they cannot access the internet. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    One-to-One NAT creates a direct mapping between an internal source IP and an external IP from the pool. This means the number of concurrent users who can access the internet is limited to the number of available IPs in the pool. During peak times, the company has more internal users than available public IPs, leading to NAT exhaustion. The solution would be to change the IP Pool type to Overload.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 234 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon