Big Black Friday Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

FortiGate 7.6 Administrator FCP_FGT_AD-7.6 Question and Answers

FortiGate 7.6 Administrator FCP_FGT_AD-7.6

Last Update Nov 22, 2025
Total Questions : 67

We are offering FREE FCP_FGT_AD-7.6 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare FCP_FGT_AD-7.6 free exam questions and then go for complete pool of FortiGate 7.6 Administrator FCP_FGT_AD-7.6 test questions that will help you more.

FCP_FGT_AD-7.6 pdf

FCP_FGT_AD-7.6 PDF

$36.75  $104.99
FCP_FGT_AD-7.6 Engine

FCP_FGT_AD-7.6 Testing Engine

$43.75  $124.99
FCP_FGT_AD-7.6 PDF + Engine

FCP_FGT_AD-7.6 PDF + Testing Engine

$57.75  $164.99
Questions 1

Which two statements are correct when FortiGate enters conserve mode? (Choose two.)

Options:

A.  

FortiGate continues to run critical security actions, such as quarantine.

B.  

FortiGate refuses to accept configuration changes.

C.  

FortiGate halts complete system operation and requires a reboot to regain available resources.

D.  

FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled.

Discussion 0
Questions 2

Refer to the exhibit.

As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.

What could be the possible reason of the diagnose output shown in the exhibit?

Options:

A.  

There is a no firewall policy configured with an IPS security profile.

B.  

FortiGate entered into IPS fail open state.

C.  

Administrator entered the command diagnose test application ipsmonitor 5.

D.  

Administrator entered the command diagnose test application ipsmonitor 99.

Discussion 0
Questions 3

What are three key routing principles in SD-WAN? (Choose three.)

Options:

A.  

By default. SD-WAN rules are skipped if the included SD-WAN members do not have a valid route to the destination.

B.  

SD-WAN rules have precedence over any other type of routes.

C.  

Regular policy routes have precedence over SD-WAN rules.

D.  

By default. SD-WAN rules are skipped if only one route to the destination is available.

E.  

By default. SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

Discussion 0
Questions 4

You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic.

In which two ways can you effectively resolve the problem? (Choose two.)

Options:

A.  

You should use the protocol IKEv2.

B.  

You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 or 4500).

C.  

You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP ports.

D.  

You can turn on fragmentation to fix large certificate negotiation problems.

Discussion 0
Questions 5

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

Options:

A.  

Enabled

B.  

On Idle

C.  

Disabled

D.  

On Demand

Discussion 0
Questions 6

Refer to the exhibits.

An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access Facebook.com, they are redirected to a FortiGuard web filtering block page.

Based on the exhibits, which configuration change must the administrator make to allow Facebook while blocking all other social networking sites?

Options:

A.  

Change the Feature set of Web Filter Profile as Proxy-based.

B.  

Set the Action as Exempt for www.facebook.com

in the Static URL Filter.

C.  

Change the type as Simple in the Static URL Filter section.

D.  

Set the Social Networking action as warning in the FortiGuard Category Based Filter.

Discussion 0
Questions 7

You have configured the below commands on a FortiGate.

What would be the impact of this configuration on FortiGate?

Options:

A.  

FortiGate will enable strict RPF on ail its interfaces and port1 will be enable for asymmetric routing.

B.  

FortiGate will enable strict RPF on all its interfaces and port1 will be exempted from RPF checks.

C.  

Port1 will be enabled with flexible RPF, and all other interfaces will be enabled for strict RPF

D.  

The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces.

Discussion 0
Questions 8

Refer to the exhibit.

The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.

What must the administrator configure to answer this specific request from the NOC team?

Options:

A.  

Move NOC_Access to the top of the list to ensure all profile settings take effect.

B.  

Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.

C.  

Ensure that all NOC_Access users are assigned the super_admin role to guarantee access

D.  

Increase the admintimeout value under config system accprofile NOC_Access.

Discussion 0
Questions 9

A remote user reports slow SSL VPN performance and frequent disconnections. The user is located in an area with poor internet connectivity.

What setting should the administrator adjust to improve the user's experience?

Options:

A.  

Enable split tunneling to reduce VPN traffic.

B.  

Change the SSL VPN port to a non-standard port.

C.  

Increase the session timeout for inactive sessions.

D.  

Configure the DTLS timeout to accommodate high-latency connections.

Discussion 0
Questions 10

Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)

Options:

A.  

If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.

B.  

If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.

C.  

If SD-WAN is disabled, you configure the load balancing algorithm in config system settings.

D.  

If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.

Discussion 0
Questions 11

An administrator notices that some users are unable to establish SSL VPN connections, while others can connect without any issues.

What should the administrator check first?

Options:

A.  

Ensure that the affected users are using the correct port number.

B.  

Ensure that user traffic is hitting the firewall policy.

C.  

Ensure that forced tunneling is enabled to reroute all traffic through the SSL VPN

D.  

Ensure that the HTTPS service is enabled on SSL VPN tunnel interface

Discussion 0
Questions 12

What is the primary FortiGate election process when the HA override setting is enabled?

Options:

A.  

Connected monitored ports > Priority > HA uptime > FortiGate serial number

B.  

Connected monitored ports > Priority > System uptime > FortiGate serial number

C.  

Connected monitored ports > HA uptime > Priority > FortiGate serial number

D.  

Connected monitored ports > System uptime > Priority > FortiGate serial number

Discussion 0
Questions 13

Refer to the exhibit.

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.

An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.

What are two solutions for satisfying the requirement? (Choose two.)

Options:

A.  

Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.

B.  

Configure a web override rating for download.com and select Malicious Websites as the subcategory.

C.  

Configure a separate firewall policy with action Deny and an FQDN address object for*.download.com as destination address.

D.  

Set the Freeware and Software Downloads category Action to Warning.

Discussion 0
Questions 14

Refer to the exhibit.

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit.

For which two reasons are these web categories exempted? (Choose two.)

Options:

A.  

The FortiGate temporary certificate denies the browser’s access to websites that use HTTP Strict Transport Security.

B.  

These websites are in an allowlist of reputable domain names maintained by FortiGuard.

C.  

The resources utilization is optimized because these websites are in the trusted domain list on FortiGate.

D.  

The legal regulation aims to prioritize user privacy and protect sensitive information for these websites.

Discussion 0