Fortinet FCP - Secure Wireless LAN 7.4 Administrator Free Sample Questions

Description

Covers wireless fundamentals and FortiAP deployment, secure wireless network design with VLANs and NAC, monitoring access point health, and wireless diagnostics and log analysis.

20 free sample questions220 in the full practice test

Try simulator

FCP-FWF-AD-7-4 Sample Questions

  1. Question 1

    Intermediate

    Wireless network security and access · Deploy VLANs and NAC for wireless segmentation

    A hospital is deploying a Fortinet wireless network for both medical staff and patients. The security policy mandates that staff devices using 802.1X authentication are placed in VLAN 10, while patient guest devices using a FortiGate-hosted captive portal are placed in VLAN 20. Both SSIDs are broadcast from the same FortiAP-U series access points, and the policy also requires that all wireless client traffic be carried to the FortiGate over CAPWAP so that the FortiGate enforces the firewall policies for both groups. Which FortiAP SSID traffic mode meets these requirements?

    Answer and explanation

    Correct answer: B

    In Tunnel mode, all wireless client traffic is encapsulated in CAPWAP and delivered to the FortiGate wireless controller, where each SSID (and its VLAN) terminates on a FortiGate interface. The FortiGate therefore enforces firewall policies and hosts the captive portal for both groups. In Bridge mode, traffic is placed directly onto the local LAN at the FortiAP and is not carried to the FortiGate over CAPWAP.

  2. Question 2

    AdvancedMultiple answers

    Wireless fundamentals and FortiAP management · Use custom access point profiles to configure FortiAP devices

    A retail company is experiencing poor wireless performance in its high-density warehouse environment. The administrator observes that a few older 802.11n clients are consuming a disproportionate amount of airtime, slowing down newer 802.11ax clients. Which two FortiAP profile features should be configured to mitigate this issue? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    Airtime fairness is aimed at the case where slow or distant clients monopolize airtime. In FortiOS it applies to downlink data, and each SSID (VAP) gets airtime by its configured weight (atf-weight, default 20%), so slower clients cannot starve the others. Band steering (frequency handoff) keeps dual-band clients that have a strong 5 GHz signal off 2.4 GHz, which reduces contention with legacy clients. Client load balancing responds to per-AP client counts, channel bonding widens channels, and WMM prioritizes traffic classes; none of these address slow clients taking airtime.

  3. Question 3

    Advanced

    Wireless diagnostics and analytics · Analyze wireless logs and debugs

    A wireless administrator is troubleshooting a client connectivity issue where a user fails to authenticate to an 802.1X EAP-TLS SSID. The RADIUS server logs show no authentication attempt from the client. The administrator suspects a problem with the CAPWAP tunnel between the FortiAP and the FortiGate. Which CLI command on the FortiGate would provide real-time debug information about CAPWAP control messages to diagnose this issue?

    Answer and explanation

    Correct answer: C

    The diagnose debug application cw_acd -1 command enables debugging for the CAPWAP AC daemon (cw_acd), which handles the CAPWAP control plane communication between the FortiGate (AC) and FortiAPs. This output would show messages related to tunnel establishment, keepalives, and configuration pushes, helping to identify if the control channel is functioning correctly.

  4. Question 4

    Beginner

    Wireless monitoring and protection · Identify wireless threats and malicious activities

    True or False: When a FortiAP is operating in dedicated monitor mode, it can simultaneously serve wireless clients and perform background scanning for rogue APs.

    Answer and explanation

    Correct answer: B

    In dedicated monitor mode, the FortiAP's radios are used exclusively for scanning the RF environment for threats like rogue APs and do not broadcast any SSIDs or serve clients. Background scanning is a feature of APs operating in standard AP mode.

  5. Question 5

    Intermediate

    Wireless fundamentals and FortiAP management · Deploy FortiAP devices using the FortiOS integrated wireless controller

    A university is deploying a large number of new FortiAPs across many campus subnets that are routed to a central FortiGate wireless controller. The team wants every new FortiAP to find the controller automatically, with no per-AP configuration. Which method should be implemented?

    Answer and explanation

    Correct answer: D

    FortiAPs try discovery methods automatically in the order static, DHCP, DNS, FortiCloud, multicast, broadcast. With DHCP discovery, the campus DHCP servers return option 138 containing the controller IP (hex encoded, for example C0A80001 for 192.168.0.1). Every new FortiAP learns where its controller is with no per-AP configuration, even on subnets other than the controller's. Broadcast works only in the controller's Layer 2 domain, and a manual AC_IPADDR setting needs per-AP work.

  6. Question 6

    Advanced

    Wireless fundamentals and FortiAP management · Deploy FortiAP devices using the FortiOS integrated wireless controller

    Case Study:

    Global Retail Corp is upgrading the wireless infrastructure across its 200 stores. Each store has a single FortiGate managing local FortiAPs. The corporate IT team needs to enforce a standardized wireless configuration across all stores but allow local store managers to customize the guest Wi-Fi captive portal message. The corporate team must be able to push updates to AP radio settings and security policies centrally, while preventing store managers from altering these critical configurations.

    The requirements are as follows:

    1. Centralized management of AP profiles, SSIDs, and security settings.
    2. Delegated management for guest captive portals on a per-store basis.
    3. Ability to deploy new FortiAPs to stores with zero-touch provisioning.
    4. Scalable management for all 200 store FortiGates and their associated APs.

    Which Fortinet solution best meets all of Global Retail Corp's requirements?

    Answer and explanation

    Correct answer: B

    FortiManager is the ideal solution for this scenario. It provides centralized management for hundreds of FortiGates. Using provisioning templates, the corporate team can enforce standard configurations for SSIDs and AP profiles. By creating custom administrator profiles with restricted access within the ADOM, they can delegate the specific task of editing guest portals to store managers while protecting critical settings. New devices can be brought online with zero-touch provisioning through FortiZTP (formerly FortiDeploy), which directs them to their management target.

  7. Question 7

    Intermediate

    Wireless network security and access · Configure secure wireless access

    A wireless network administrator has configured WPA3-Enterprise with 802.1X authentication. During testing, it is discovered that some older, mission-critical devices do not support WPA3. The administrator needs to allow both WPA3-capable and WPA2-capable clients to connect to the same corporate SSID. What security mode should be configured on the SSID?

    Answer and explanation

    Correct answer: C

    WPA3-Enterprise Transition Mode is specifically designed for this purpose. It allows the SSID to simultaneously advertise support for both WPA3 and WPA2, enabling clients to connect using the highest security protocol they support. This provides a seamless migration path without requiring a separate legacy SSID.

  8. Question 8

    Intermediate

    Wireless diagnostics and analytics · Gather information about clients and wireless components

    An administrator is analyzing the output of diagnose wireless-controller wlac -d sta to troubleshoot a client's roaming issue. The client is frequently disconnecting and reconnecting while moving through the facility. Which piece of information in the command output is most critical for diagnosing poor roaming performance?

    Answer and explanation

    Correct answer: B

    The RSSI value indicates the signal strength received by the AP from the client. Monitoring the RSSI as the client moves is crucial for diagnosing roaming issues. If the RSSI drops to a very low level before a roam occurs, it indicates potential coverage gaps or that roaming thresholds are not tuned correctly, causing the client to disconnect before it can find and roam to a better AP.

  9. Question 9

    Advanced

    Wireless monitoring and protection · Identify wireless threats and malicious activities

    A security audit reveals that an unauthorized device has been connected to a corporate LAN port and is broadcasting a rogue SSID with the same name as the corporate network (an "evil twin"). The FortiAP WIDS has detected this rogue AP. Which specific Fortinet feature can actively prevent clients from connecting to this on-wire rogue AP?

    Answer and explanation

    Correct answer: C

    When an AP is set to Suppressed Rogue AP, the FortiGate WiFi controller uses the monitoring radio to send deauthentication messages to the rogue AP's clients (posing as the rogue AP) and to the rogue AP (posing as its clients). This stops users from staying connected to it. It requires on-wire rogue detection and a radio in Dedicated Monitor mode. Client isolation and PMF protect your own SSIDs but do not act against a rogue AP.

  10. Question 10

    IntermediateMultiple answers

    Wireless network security and access · Deploy VLANs and NAC for wireless segmentation

    A consultant needs to configure dynamic VLAN assignment for wireless clients based on their department, which is stored as an attribute in a RADIUS server. Which three components are essential for this configuration to work? (Select THREE)

    Answer and explanation

    Correct answers: A, B, D

    The RADIUS server is responsible for authenticating the user and sending back the appropriate VLAN ID in its Access-Accept message. WPA2/WPA3-Enterprise (802.1X) is the authentication framework that directs authentication requests to the RADIUS server. The FortiGate must have the VLANs defined as interfaces and have appropriate firewall policies to allow traffic from those VLANs to the intended destinations. On the FortiGate, Dynamic VLAN assignment must also be enabled on the SSID (set dynamic-vlan enable) so that the returned Tunnel-Private-Group-ID is honored.

Register free for 10 more questions

Or unlock all 220 FCP-FWF-AD-7-4 questions with explanations, timed mode and flashcards.