Fortinet FCP_FGT_AD-7.4 Exam Practice Questions (P. 2)
- Full Access (89 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device.
Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet.
Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.)



The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device.
Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet.
Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.)
- AIn the firewall policy configuration, add 10.0.1.3 as an address object in the source field.
- BIn the IP pool configuration, set endip to 192.2.0.12.
- CConfigure another firewall policy that matches only the address of PC3 as source, and then place the policy on top of the list.
- DIn the IP pool configuration, set type to overload.
send
light_mode
delete
Question #7
Which method allows management access to the FortiGate CLI without network connectivity?
send
light_mode
delete
Question #8
Refer to the exhibit.

In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output shown in the exhibit.
What should the administrator do next, to troubleshoot the problem?

In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output shown in the exhibit.
What should the administrator do next, to troubleshoot the problem?
- AExecute a debug flow.
- BCapture the traffic using an external sniffer connected to port1.
- CExecute another sniffer on FortiGate, this time with the filter "host 10.0.1.10".
- DRun a sniffer on the web server.
send
light_mode
delete
Question #9
Refer to the exhibit.

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.
An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.
An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)
- AConfigure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.
- BSet the Freeware and Software Downloads category Action to Warning.
- CConfigure a web override rating for download.com and select Malicious Websites as the subcategory.
- DConfigure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
send
light_mode
delete
Question #10
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.
All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)
All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover.
Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)
- AEnable Dead Peer Detection.
- BEnable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
- CConfigure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
- DConfigure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
send
light_mode
delete
All Pages