Fortinet FCP_FGT_AD-7.6 Exam Practice Questions (P. 1)
- Full Access (128 questions)
- One Year of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?
Which DPD mode on FortiGate meets this requirement?
send
light_mode
delete
Question #2
Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)
- AIf SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.
- BIf SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.
- CIf SD-WAN is disabled, you configure the load balancing algorithm in config system settings.
- DIf SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.
send
light_mode
delete
Question #3
You have created a web filter profile named restrict_media-profile with a daily category usage quota.
When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.
What could be the reason?
When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.
What could be the reason?
- AThe firewall policy is in no-inspection mode instead of deep-inspection.
- BThe inspection mode in the firewall policy is not matching with web filter profile feature set.
- CThe web filter profile is already referenced in another firewall policy.
- DThe naming convention used in the web filter profile is restricting it in the firewall policy.
send
light_mode
delete
Question #4
Refer to the exhibit.

As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?

As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?
- AThere is a no firewall policy configured with an IPS security profile.
- BFortiGate entered into IPS fail open state.
- CAdministrator entered the command diagnose test application ipsmonitor 5.
- DAdministrator entered the command diagnose test application ipsmonitor 99.
send
light_mode
delete
Question #5
Refer to the exhibit.

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit.
For which two reasons are these web categories exempted? (Choose two.)

The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit.
For which two reasons are these web categories exempted? (Choose two.)
- AThe FortiGate temporary certificate denies the browser’s access to websites that use HTTP Strict Transport Security.
- BThese websites are in an allowlist of reputable domain names maintained by FortiGuard.
- CThe resources utilization is optimized because these websites are in the trusted domain list on FortiGate.
- DThe legal regulation aims to prioritize user privacy and protect sensitive information for these websites.
send
light_mode
delete
All Pages
