Pay attention to our Valid and Useful Exam Reviews and take our Exam Torrent as your Study Material. With little time and energy investment, you have a High Efficiency Study experience. Pass your Actual Test with the help of our Actual Reviews.

[Q49-Q70] Free Sample Questions to Practice FCP_FGT_AD-7.4 Certification Test Engine [Oct-2025]

Share

Free Sample Questions to Practice FCP_FGT_AD-7.4 Certification Test Engine [Oct-2025]

2025 Valid FCP_FGT_AD-7.4 Real Exam Questions, practice FCP in Network Security

NEW QUESTION # 49
Refer to the exhibits, which show the firewall policy and an antivirus profile configuration.

Why is the user unable to receive a block replacement message when downloading an infected file for the first time?

  • A. The firewall policy performs a full content inspection on the file.
  • B. The intrusion prevention security profile must be enabled when using flow-based inspection mode.
  • C. Flow-based inspection is used, which resets the last packet to the user.
  • D. The option to send files to FortiSandbox for inspection is enabled.

Answer: C

Explanation:
In flow-based inspection mode, FortiGate sends a reset (RST) packet to the client instead of providing a replacement message, which causes the block message not to be displayed.


NEW QUESTION # 50
An administrator wants to block https://www.example.com/videos and allow all other URLs on the website.
What are two configuration changes that the administrator can make to satisfy the requirement? (Choose two.)

  • A. Enable full SSL inspection
  • B. Configure a static URL filter entry for the URL and select Block as the action
  • C. Configure a video filter profile to block the URL
  • D. Configure web override for the URL and select a blocked FortiGuard subcategory

Answer: A,B

Explanation:
If the goal is to block the specific URL https://www.example.com/videos and allow all other URLs on the website, the correct configuration changes are:
B. Enable full SSL inspection.
Enabling full SSL inspection allows the FortiGate to inspect and filter HTTPS traffic, including the specific URL https://www.example.com/videos.
D. Configure a static URL filter entry for the URL and select Block as the action.
Create a static URL filter entry for the specific URL https://www.example.com/videos and set the action to Block. This will block access to the specified URL.
Enabling full SSL inspection is necessary to inspect and filter HTTPS traffic effectively, including the specific URL within the encrypted traffic.
So, the correct choices are B and D.


NEW QUESTION # 51
What is the common feature shared between IPv4 and SD-WAN ECMP algorithms?

  • A. Both can be enabled at the same time.
  • B. Both support volume algorithms.
  • C. Both control ECMP algorithms.
  • D. Both use the same physical interface load balancing settings.

Answer: C

Explanation:
The correct answer is: C. Both control ECMP algorithms.
In the context of SD-WAN (Software-Defined Wide Area Network), ECMP (Equal-Cost Multi-Path) algorithms are used to determine the path packets should take through the network. Both IPv4 and SD- WAN ECMP algorithms control how traffic is load-balanced across multiple paths to a destination. While IPv4 ECMP operates at the network layer (Layer 3) of the OSI model, SD-WAN ECMP operates at a higher level, typically involving application-aware routing and more advanced traffic steering capabilities.


NEW QUESTION # 52
Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)

  • A. On HQ-FortiGate, disable Diffie-Helman group 2.
  • B. On Remote-FortiGate, set port2 as Interface.
  • C. On both FortiGate devices, set Dead Peer Detection to On Demand.
  • D. On HQ-FortiGate, set IKE mode to Main (ID protection).

Answer: B,D


NEW QUESTION # 53
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

  • A. The host field in the HTTP header.
  • B. The subject field in the server certificate.
  • C. The serial number in the server certificate.
  • D. The subject alternative name (SAN) field in the server certificate.
  • E. The server name indication (SNI) extension in the client hello message.

Answer: B,D,E


NEW QUESTION # 54
Which statement is a characteristic of automation stitches?

  • A. They can run multiple actions at the same time.
  • B. They can be created only on downstream devices in the fabric.
  • C. They can have one or more triggers.
  • D. They can be run only on devices in the Security Fabric.

Answer: A


NEW QUESTION # 55
What devices form the core of the security fabric?

  • A. One FortiGate device and one FortiManager device
  • B. Two FortiGate devices and one FortiAnalyzer device
  • C. Two FortiGate devices and one FortiManager device
  • D. One FortiGate device and one FortiAnalyzer device

Answer: B

Explanation:
C: Two FortiGate devices and one FortiAnalyzer device.
These devices form the core of the Fortinet Security Fabric, providing firewall functionality, centralized management, logging, and reporting capabilities.
In certain scenarios, especially when emphasizing visibility and analysis, having multiple FortiGate devices and a FortiAnalyzer device can indeed form a core configuration within the Fortinet Security Fabric. FortiAnalyzer is used for centralized logging, reporting, and analysis of data from multiple FortiGate devices, enhancing the overall security posture.


NEW QUESTION # 56
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?

  • A. The internal IP address of the FortiGate device.
  • B. remote user's public IP address
  • C. The public IP address of the FortiGate device.
  • D. The remote user's virtual IP address.

Answer: A

Explanation:
The internal IP address of the FortiGate device.
The SSL VPN portal enables remote users to access internal network resources through a secure channel using a web browser. The portal, bookmarks are used as links to internal network resources.
Source IP seen by the remote resources is FortiGate's internal IP address and not the user's IP address.
Reference: https://kb.fortinet.com/kb/documentLink.do?externalID=FD36530


NEW QUESTION # 57
Which statement is correct regarding the inspection of some of the services available by web applications embedded in third-party websites?

  • A. FortiGate can inspect sub-application traffic regardless where it was originated.
  • B. FortiGuard maintains only one signature of each web application that is unique.
  • C. The application signature database inspects traffic only from the original web application server.
  • D. The security actions applied on the web applications will also be explicitly applied on the third-party websites.

Answer: A

Explanation:
D. FortiGate can inspect sub-application traffic regardless of where it originated.
FortiGate is capable of inspecting traffic from web applications embedded in third-party websites, regardless of where the traffic originated. This allows FortiGate to provide comprehensive security measures for web applications, including those embedded in third-party websites. FortiOS gives administrators all the tools they need to inspect sub-application traffic.
Reference: https://help.fortinet.com/fortiproxy/11/Content/Admin%20Guides/FPX- AdminGuide/300_System/303d_Fo rtiGuard.htm


NEW QUESTION # 58
When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate.
Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choose three.)

  • A. Trust & Allow
  • B. Block & Warning
  • C. Block
  • D. Allow & Warning
  • E. Allow

Answer: A,C,E

Explanation:
When a certificate fails for any of the reasons above, you can configure any of the following actions: * Keep untrusted & Allow: FortiGate allows the website and lets the browser decide the action to take. FortiGate takes the certificate as untrusted. * Block: FortiGate blocks the content of the site. * Trust & Allow: FortiGate allows the website and takes the certificate as trusted.


NEW QUESTION # 59
Refer to the exhibit.

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

  • A. Traffic is distributed based on the number of sessions through each interface.
  • B. Traffic is sent to the link with the lowest latency.
  • C. All traffic from a source IP is sent to the same interface
  • D. All traffic from a source IP to a destination IP is sent to the same interface.

Answer: D

Explanation:
For traffic that does not match any of the defined SD-WAN rules, the default implicit SD-WAN rule is applied. By default, the FortiGate uses a "source-destination IP-based" algorithm, which means all traffic from a specific source IP to a specific destination IP is sent through the same interface. This ensures that a consistent path is used for traffic between the same source and destination IP addresses. Options B, C, and D do not apply because the default algorithm does not prioritize by latency, session count, or source IP alone.
References:
* FortiOS 7.4.1 Administration Guide: SD-WAN Load Balancing Algorithms


NEW QUESTION # 60
Refer to the exhibit.

Which statement about the configuration settings is true?

  • A. When a remote user accesses https://10.200.1.1:443, the SSL-VPN login page opens.
  • B. When a remote user accesses http://10.200.1.1:443, the SSL-VPN login page opens.
  • C. When a remote user accesses https://10.200.1.1:443, the FortiGate login page opens.
  • D. The settings are invalid. The administrator settings and the SSL-VPN settings cannot use the same port.

Answer: A

Explanation:
B. When a remote user accesses https://10.200.1.1:443, the SSL-VPN login page opens.
In this scenario, the remote user is accessing the FortiGate device using HTTPS (port 443), which is typically used for SSL-VPN access. Therefore, when accessing the device at that address and port, the SSL-VPN login page should open for the user to authenticate and establish a VPN connection.


NEW QUESTION # 61
Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device.
Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet.
Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.)

  • A. Configure another firewall policy that matches only the address of PC3 as source, and then place the policy on top of the list.
  • B. In the IP pool configuration, set endig to 192.2.0.12.
  • C. In the IP pool configuration, set cype to overload.
  • D. In the firewall policy configuration, add 10. o. l. 3 as an address object in the source field.

Answer: B,C

Explanation:
To resolve the issue of PC3 not being able to access the internet, the administrator needs to adjust the IP pool configuration or the firewall policy. The following two options will fix the connectivity issue:
* B. In the IP pool configuration, set the ending IP to 192.2.0.12: The current IP pool range is
192.2.0.10-192.2.0.11, which only provides two IP addresses for network address translation (NAT). To allow PC3 to access the internet, the IP pool should be expanded to include an additional IP address by changing the end of the range to 192.2.0.12.
* D. In the IP pool configuration, set type to overload: Instead of using a one-to-one NAT, changing the type to overload will allow multiple internal addresses (such as PC1, PC2, and PC3) to share a single external IP address. This will solve the issue without needing additional public IP addresses.
The other options are not suitable:
* A. In the firewall policy configuration, add 10.0.1.3 as an address object in the source field: This option is unnecessary since the firewall policy already allows all addresses from the source (LAN port3).
* C. Configure another firewall policy that matches only the address of PC3 as the source, and then place the policy on top of the list: This option is redundant and would not resolve the underlying issue with the IP pool configuration.
References
* FortiOS 7.4.1 Administration Guide - Configuring Firewall Policies, page 512.
* FortiOS 7.4.1 Administration Guide - Configuring NAT with IP Pools, page 518.


NEW QUESTION # 62
Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)

  • A. No certificate is required on the remote peer when you set the certificate signature as the authentication method
  • B. Extended authentication (XAuth) for faster authentication because fewer packets are exchanged
  • C. Extended authentication (XAuth)to request the remote peer to provide a username and password
  • D. Pre-shared key and certificate signature as authentication methods

Answer: C,D


NEW QUESTION # 63
An administrator has configured the following settings:

What are the two results of this configuration? (Choose two.)

  • A. A session for denied traffic is created
  • B. Denied users are blocked for 30 minutes
  • C. The number of logs generated by denied traffic is reduced
  • D. Device detection on all interfaces is enforced for 30 minutes

Answer: A,C

Explanation:
C: A session for denied traffic is created.
D: The number of logs generated by denied traffic is reduced.
During the session, if a security profile detects a violation, FortiGate records the attack log immediately.
To reduce the number of log messages generated and improve performance, you can enable a session table entry of dropped traffic. This creates the denied session in the session table and, if the session is denied, all packets of that session are also denied. This ensures that FortiGate does not have to do a policy lookup for each new packet matching the denied session, which reduces CPU usage and log generation.
This option is in the CLI, and is called ses-denied-traffic. You can also set the duration for block sessions.
This determines how long a session will be kept in the session table by setting block-sessiontimer in the CLI. By default, it is set to 30 seconds.


NEW QUESTION # 64
Refer to the exhibits.
The exhibits show the SSL and authentication policy (Exhibit A) and the security policy (Exhibit B) for Facebook.
Users are given access to the Facebook web application. They can play video content hosted on Facebook, but they are unable to leave reactions on videos or other types of posts.


Which part of the policy configuration must you change to resolve the issue?

  • A. Force access to Facebook using the HTTP service.
  • B. Get the additional application signatures required to add to the security policy.
  • C. Make the SSL inspection a deep content inspection.
  • D. Add Facebook in the URL category in the security policy.

Answer: C

Explanation:
Needs SSL full inspection.
They can play video (tick) content hosted on Facebook, but they are unable to leave reactions on videos or other types of posts.
This indicate that the rule are partially working as they can watch video but can't react, i.e. liking the content. So, must be an issue with the SSL inspection rather then adding an app rule.
The lock logo behind Facebook_like.Button indicates that SSL Deep Inspection is Required. All other Application Signatures Facebook and Facebook_Video.Play does not require SSL inspection. Hence that the users can play video content. If you look up the Application Signature for Facebook_like.Button it will say "Requires SSL Deep Inspection".
FortiGate needs to perform full SSL inspection. Without full SSL inspection, FortiGate cannot inspect encrypted traffic.


NEW QUESTION # 65
Refer to the exhibit.

The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.
What must the administrator configure to answer this specific request from the NOC team?

  • A. Increase the offline value of the Override idle Timeout parameter in the NOC_Access admin profile
  • B. Increase the admintimeout value under config system accprofile super_admin.
  • C. Increase the admintimeout value under config system global
  • D. Enable the parameter Never Timeout in the admin profiles

Answer: C

Explanation:
To adjust the inactivity timeout for GUI sessions, the administrator should increase the admintimeout value in the global settings. This parameter controls how long an administrator's session can remain idle before it times out and disconnects. This is configured globally and affects all administrators, including those with the
"NOC_Access" profile.


NEW QUESTION # 66
Which three statements explain a flow-based antivirus profile? (Choose three.)

  • A. The IPS engine handles the process as a standalone.
  • B. If a virus is detected, the last packet is delivered to the client.
  • C. FortiGate buffers the whole file but transmits to the client at the same time.
  • D. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
  • E. Flow-based inspection optimizes performance compared to proxy-based inspection.

Answer: C,D,E

Explanation:
A: Flow-based inspection mode uses a hybrid of the scanning modes available in proxy-based inspection.
D: the IPS engine reads the payload of each packet, caches a local copy, and forwards the packet to the receiver at the same time. some operations can be offloaded to SPUs to improve performance (not C).
E: If performance is your top priority, then flow inspection mode is more appropriate. Extra explanation:
A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
Flow-based inspection combines aspects of both proxy-based and flow-based inspection methods to optimize performance and scanning effectiveness.
D. FortiGate buffers the whole file but transmits to the client at the same time.
In flow-based inspection, FortiGate buffers the entire file for scanning before transmitting it to the client.
This allows for comprehensive scanning without delaying the transmission to the client.
E. Flow-based inspection optimizes performance compared to proxy-based inspection.
Flow-based inspection is generally more efficient than proxy-based inspection, especially in high-traffic environments, as it does not require the buffering of entire files before delivery.


NEW QUESTION # 67
What is the primary FortiGate election process when the HA override setting is disabled?

  • A. Connected monitored ports > System uptime > Priority > FortiGate serial number
  • B. Connected monitored ports > Priority > HA uptime > FortiGate serial number
  • C. Connected monitored ports > Priority > System uptime > FortiGate serial number
  • D. Connected monitored ports > HA uptime > Priority > FortiGate serial number

Answer: B

Explanation:
When the HA override setting is disabled, FortiGate uses the primary election process based on the following criteria:
* Connected monitored ports: The unit with the most monitored ports up is preferred.
* Priority: The unit with the highest priority is preferred.
* System uptime: The unit with the longest uptime is preferred.
* FortiGate serial number: Used as the final criterion to break any remaining ties.
References:
* FortiOS 7.4.1 Administration Guide: HA election process


NEW QUESTION # 68
Which three methods are used by the collector agent for AD polling? (Choose three.)

  • A. FSSO REST API
  • B. WMI
  • C. WinSecLog
  • D. FortiGate polling
  • E. NetAPI

Answer: A,D,E


NEW QUESTION # 69
Refer to the exhibit, which shows the IPS sensor configuration.

If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will reset all connections that match these signatures.
  • B. The sensor will gather a packet log for all matched traffic.
  • C. The sensor will block all attacks aimed at Windows servers.
  • D. The sensor will allow attackers matching the Microsoft.Windows.iSCSl.Target.DoS signature.

Answer: C,D


NEW QUESTION # 70
......

Genuine FCP_FGT_AD-7.4 Exam Dumps Free Demo Valid QA's: https://www.examsreviews.com/FCP_FGT_AD-7.4-pass4sure-exam-review.html

Latest Success Metrics For Actual FCP_FGT_AD-7.4 Exam (Updated 91 Questions): https://drive.google.com/open?id=1hcJRGOmGBgeIehFgXLc7R9HktT9rlrsK