All questions

Fortinet Certified Professional (FCP) FortiGate 7.4 Administrator (FCP_FGT_AD-7.4) Practice Test

Browse all practice questions for the Fortinet Certified Professional (FCP) FortiGate 7.4 Administrator (FCP_FGT_AD-7.4) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Fortinet Certified Professional FCP FortiGate 7.4 Administrator Practice Test 2026 – Your All-in-One Success Guide! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What should a user do to successfully connect to a failing SSL VPN?
  • In FortiGate, what is a hash algorithm used for?
  • Which of the following best describes a VDOM in FortiGate?
  • What action can FortiGate take when detecting a blocked application?
  • What is one effective solution to block access to a specific website while allowing others in the same category?
  • What are two potential reasons for failed virus detection on HTTPS downloads in FortiGate? (Choose two)
  • What is the purpose of the FortiGuard service?
  • What component of Fortinet's FortiOS manages firewall policies and rules?
  • Based on the routing database shown, which two conclusions can be made about the routes?
  • What is the primary purpose of a FortiGate firewall?
  • What is the function of the FortiAnalyzer in a Fortinet deployment?
  • What is a pre-shared key in the context of VPN configuration?
  • What is indicated by a decrease in CPU usage shown in the outcome of an IPS diagnostic command?
  • What is the purpose of a firewall policy?
  • What is true about the DNS connection to a FortiGuard server when configured as DNS servers?
  • Which three strategies are valid SD-WAN rule strategies for member selection?
  • What is a common use case for link aggregation in a FortiGate device?
  • How does strict RPF check function in a FortiGate device?
  • What does the term "VLAN" stand for?
  • What is the purpose of configuring source NAT on a FortiGate device?
  • What type of Firewall mode operates independently, without supporting interfaces in FortiGate?
  • What would be the expected outcome in the HA cluster if FGT-2 has a higher priority and override enable setting than FGT-1?
  • What is the CLI command to display FortiGate's current firmware version?
  • Which three statements best describe a flow-based antivirus profile?
  • What type of network does a VLAN primarily create?
  • Which phase 1 setting can be configured to match users to their respective dial-up VPN tunnels?
  • What method allows management access to the FortiGate CLI without any network connectivity?
  • What happens when adding the FTP.Login.Failed signature to the IPS sensor profile?
  • In FortiGate, what is a Virtual Domain (VDOM)?
  • Which two statements are true regarding FortiGate HA configuration synchronization?
  • Why is the user unable to receive a block replacement message when downloading an infected file?
  • Which attribute is added to a firewall policy to support recording logs to FortiAnalyzer or FortiManager?
  • How does FortiGate handle DoS attacks?
  • What do you need to configure to set up a VPN tunnel?
  • What must be added to a FortiGate device configured for agentless polling mode to retrieve AD user group information?
  • Why might an address object not be available on the downstream FortiGate after synchronization?
  • What should be enabled to enhance security measures while inspecting SSL traffic on FortiGate?
  • What command would show the active firewall policies configured on a FortiGate?
  • In order to conduct SSL inspection effectively, how must the firewall's SSL inspection profile be configured?
  • What is a firewall VIP (Virtual IP) used for in FortiGate?
  • How does FortiGate categorize network traffic?
  • How can RPF checking be disabled on a FortiGate device?
  • What configuration changes can help bring an IPsec tunnel phase 1 up between two FortiGate devices? (Choose two)
  • What type of VPN does FortiGate primarily use for secure remote access?
  • What must an administrator configure to prevent GUI sessions from disconnecting too early due to inactivity?
  • How does FortiGate support user authentication for VPN access?
  • How do you enable VDOMs on a FortiGate device?
  • What is a likely reason for certificate warning errors during SSL inspection when visiting HTTPS websites?
  • In a network where an administrator enables SSL inspection and antivirus, what is a potential limitation when inspecting HTTPS?
  • What configuration change must the administrator make if connectivity to a web server times out?
  • For detecting dead tunnels on an IPsec VPN, which DPD mode sends probes only when there’s outbound traffic but no response?
  • Why does the FortiGate administrator require a specific configuration to authenticate only the Training user group?
  • What are two features of collector agent advanced mode on FortiGate?
  • Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
  • What is a common feature of FortiGate's HA setup?
  • Why would a firewall policy not block a known virus like eicar?
  • Which FortiGate feature allows for application control?
  • What does the NetSessionEnum function achieve in the context of NetAPI polling?
  • What are two features of FortiGate FSSO agentless polling mode?
  • What information does FortiGate use to identify the hostname of the SSL server during SSL certificate inspection?
  • What feature does FortiGate use to provide web filtering capabilities?
  • What could be the reason for SD-WAN specific columns not showing in traffic logs?
  • What configuration change can an administrator make to allow access to Twitter while blocking all other social networking sites?
  • Which FortiGate feature is primarily used to manage applications on the network?
  • Which NAT mode does FortiGate use by default?
  • What command is used to configure an interface in FortiGate?
  • What is FortiOS?
  • Which command would you use to view active sessions on a FortiGate device?
  • What is the correct order followed during the HTTP inspection process in web filtering when multiple features are enabled?
  • Which method does FortiGate utilize for agentless FSSO polling mode?
  • What does the term "sandboxing" refer to regarding FortiGate's security features?
  • Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection?
  • What is the significance of the command "get sys session" on a FortiGate device?
  • What does FortiGate's "Traffic Shaping" functionality allow?
  • What is the impact of using the "Include in every user group" option in a RADIUS configuration?
  • What is the result of enabling the DPD feature in an IPsec VPN configuration?
  • When a TCP SYN packet is sent from host 10.200.3.1 to destination 10.200.1.10 on port 8080, what will be the source address, destination address, and port forwarded by FortiGate?
  • What are two results of a specific configuration on a FortiGate device?
  • Which inspection mode does FortiGate use for application profiles in a profile-based NGFW?
  • What are the two authentication methods supported by FortiGate for IPsec IKEv1?
  • What is preventing the administrator from enabling DHCP service on FortiGate's GUI?
  • Which CLI command is used to check the system status of a FortiGate device?
  • Why does the browser report certificate warning errors when using full SSL inspection on FortiGate?
  • Which two statements are true about the routing entries in a FortiGate routing database?
  • Which statement about the deployment of the Security Fabric in a multi-VDOM environment is true?
  • In FortiGate, what does the term "interface" refer to?
  • Which IPsec Wizard template is applicable for configuring a VPN tunnel for a traveling employee?
  • What does IPS stand for in the context of FortiGate?
  • What does a successful SSL VPN connection require from the client-side configuration?
  • What action must the administrator perform to consolidate two firewall policies into one for accessing the same web server?
  • How does NTurbo enhance performance for flow-based inspection in FortiGate devices?
  • Which Fortinet product is specifically designed for web application security?
  • What is the function of "Security Profiles" in FortiGate?
  • Which SSL timer can be used to mitigate a denial of service (DoS) attack on the SSL VPN portal?
  • What is the primary purpose of FortiGate's Antivirus feature?
  • What is required to create a site-to-site IPsec VPN on FortiGate?
  • Which engine handles application control traffic on the next-generation firewall FortiGate?
  • Which feature allows FortiGate to control application usage on the network?
  • Which component of FortiGate can block unwanted traffic based on signature analysis?
  • What is the main difference between Inspection Mode and Flow Mode in FortiGate?
  • What is a security zone in FortiGate?
  • Which FortiGate feature helps mitigate DDoS attacks?
  • What is the primary benefit of using Security Profiles in FortiGate?
  • What does UTM stand for in the context of Fortinet?
  • What must an administrator do to synchronize a newly created address object in FortiGate?
  • How can you test the connectivity and routing on a FortiGate device?
  • What is the importance of using the lowest cost (SLA) strategy in SD-WAN?
  • Which statement correctly describes the use of application control in inspecting web applications?
  • Which two syntaxes are correct to configure a web rating override for a homepage?
  • What element of FortiGate enables secure communication between remote sales offices and the main branch?
  • What is the most likely reason why a user is not presented with a login prompt when accessing an external website through FortiGate?
  • What action does FortiGate take when it detects a packet that does not meet any defined firewall rules?
  • Which VPN type is most commonly configured for remote access?
  • How can you configure an interface with a static IP address on a FortiGate device?
  • How can FortiGate's logging features improve network security?
  • Which command is used to clear the current configuration in FortiGate?
  • In which situation would a full file buffer be necessary during antivirus scanning?
  • Which protocol is commonly used for FortiGate's web management interface?
  • What is a prerequisite for configuring SSL VPN on FortiGate?
  • Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true?
  • What is a threat feed in FortiGuard?
  • Why did FortiGate drop a particular packet?
  • Which algorithm does SD-WAN use for traffic distribution that doesn't match any established rules?
  • What does FortiGate use to determine the best path for packet forwarding?
  • Which FortiGate setting helps prevent the risk of unauthorized device access?
  • What command would you use to view the running configuration on a FortiGate unit?
  • What is the recommended next step for an administrator troubleshooting HTTP connectivity issues using a built-in sniffer?
  • Which CLI commands can be utilized to troubleshoot Layer 3 networking issues? (Select three)
  • What is the purpose of fabric-object-unification in FortiGate's security fabric?
  • What is a "link aggregation" in FortiGate?
  • What action must be taken to allow features of FortiGuard to update regularly?
  • Which method in FortiGate determines the source of traffic to enforce policies?
  • What is the maximum number of Virtual Domains (VDOMs) you can configure on a FortiGate unit?
  • Which of the following best describes the primary function of a FortiGate firewall?
  • What feature does FortiOS use to perform SSL inspection?
  • What does the term "Session Aging" refer to?
  • Which two pieces of information are synchronized between FortiGate HA members?
  • What can be two possible outcomes if a FortiGate device has entered conserve mode?
  • Which protocol is used for secure DNS communication in FortiGate configurations?
  • What type of encryption is used in IPsec VPN configurations on FortiGate?
  • What is the default behavior of FortiGate if RPF checking is enabled?
  • Which of the following statements about SD-WAN zones is true? (Choose three)
  • In FortiGate, what is used to redirect traffic from one IP to another?
  • How can administrators limit access to the FortiGate management interface?
  • What adjustment can be made to enable better interaction with Facebook content while using a FortiGate device?
  • Which IP address will be used for source NAT when a user on Local-Client pings the IP address of Remote-FortiGate?
  • In FortiGate, which statement about routing distance is true?
  • When a FortiGate firewall policy is configured with active authentication, which protocol must be allowed for user access even if authentication fails?
  • What primary function does the intrusion prevention system provide on a FortiGate device?
  • Which two statements explain antivirus scanning modes?
  • If an IPS diagnostic command outcome shows a decrease in CPU usage after using option 5, what does this imply?
  • What does the term "implicit firewall policy" refer to in FortiGate?
  • What command would you use to restart the FortiGate unit?
  • What role does the WAN interface usually play in FortiGate configurations?
  • What must the administrator configure for the local quick mode selector for site B in an IPsec VPN?
  • What is the default management IP address of a FortiGate unit?
  • What are two key configuration changes necessary for setting up redundant IPsec VPN tunnels?
  • In FortiGate, what type of policies could impact the routing table aside from the default routes?
  • How would you configure log retention settings in FortiGate?
  • What configuration adjustment can enhance access control in FortiGate?
  • What role does HA (High Availability) play in FortiGate deployments?
  • What is the primary function of a firewall in a FortiGate device?
  • What is the primary advantage of implementing traffic shaping in a FortiGate firewall?
  • Which protocol is commonly used for secure remote access to FortiGate?
  • Which technology does FortiGate utilize to offer VPN services?
  • In a FortiGate firewall, which feature is essential for network traffic monitoring and management?
  • How does a FortiGate unit typically categorize incoming traffic?
  • What is "Deep Packet Inspection" (DPI) used for in FortiGate?
  • What feature allows FortiGate to inspect and block malware?
  • What does a FortiGate device typically use for deploying security policies?
  • What action does a "deny" policy take in FortiGate?
  • Which two statements are true about the FGCP protocol?
  • What happens when FortiGate enters conserve mode? (Select two)
  • How does FortiGate compare checksums during HA configuration synchronization?
  • What are three key routing principles in SD-WAN? (Choose three)
  • What are two features of the NGFW profile-based mode?
  • What configuration options can an administrator use to resolve connectivity issues for a newly added PC in a FortiGate network?
  • Which configuration changes can deny Webserver access for Remote-User2 while allowing access for Remote-User1?
  • In FortiGate, which mode is optimal for performance but less thorough in threat inspection?
  • What configuration must be ensuring for SSL inspection to function properly on FortiGate?
  • Which two statements are true about the requirements of connected physical interfaces on FortiGate operating in NAT mode? (Choose two)
  • What two conclusions can you make from a debug flow output showing traffic data?
  • What configuration should be made on FortiGate to allow remote users to send external application data and access FTP resources through an SSUTLS connection?
  • What is a major benefit of utilizing Virtual Domains (VDOMs) in a FortiGate firewall?
  • What is the purpose of the FortiClient software?
  • What does "DSRI" stand for in Fortinet troubleshooting?
  • When configuring a firewall policy to deny access to certain users, what is one essential element to include?
  • Which three methods are used by the collector agent for Active Directory polling?
  • What type of information does a FortiGate firewall use to determine the direction of traffic?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy