Official Bank 0/89

FCP – FortiGate 7.4 Administrator (FCP_FGT_AD-7.4) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
89 Total Questions
1
Question
Which three statements explain a flow-based antivirus profile? (Choose three.)
Select 3
Options
A FortiGate buffers the whole file but transmits to the client at the same time.
B If a virus is detected, the last packet is delivered to the client.
C The IPS engine handles the process as a standalone.
D Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection
E Flow-based inspection optimizes performance compared to proxy-based inspection
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibits.

Exhibit

Security Fabric physical topology view Q Search Upstream Internet • Loca Fi Edit Address Net Add_1 Name Color • Change Type Subnet IP/Netmask 1.1.1.0255.255.255.0 Interface • any Fabric synchronization Static route configuration O Comments Write a comment 0/255

Exhibit

Security Fabric configuration on Local-FortiGate Local-Fortigate show full-configuration system csf config system est set status enable set upstream •• set upstream-port 8013 set group-name "fortinet" set group-password ENC Y9ynT+64RpCTpVdgSm0QH242mYSI2NN2LN 9hpctBsz7rgcHcA/gHrByxsXtPEeHC6 W6GypwDUb503VFgPbASFYYteQesmwoJtGe84BIga+hUcgunLD1z/97sBp+PLt set accept-auth-by-cert enable set log-unification enable set authorization-request-type serial set fabric-workers 2 set downstream-access disable set configuration-sync default :fabric-object-unification local set saml-configuration-sync default

Exhibit

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW). What must the administrator do to synchronize the address object?
Options
A Change the csf setting on ISFW (downstream) to sec auchorizacion-requesc-cype certificace.
B Change the csf setting on ISFW (downstream) to sec configuration-sync local.
C Change the csf setting on Local-FortiGate (root) to sec fabric-object-unification default.
D Change the csf setting on both devices to sec downscream-access enable.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A network administrator has configured an SSL/SSH inspection profile defined for full SSL inspection and set with a private CA certificate. The firewall policy that allows the traffic uses this profile for SSL inspection and performs web filtering. When visiting any HTTPS websites, the browser reports certificate warning errors.

What is the reason for the certificate warning errors?
Options
A The browser does not recognize the certificate in use as signed by a trusted CA.
B With full SSL inspection it is not possible to avoid certificate warning errors at the browser level.
C The SSL cipher compliance option is not enabled on the SSL inspection profile. This setting is required when the SSL inspection profile is defined with a private CA certificate.
D The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
What is the primary FortiGate election process when the HA override setting is disabled?
Options
A Connected monitored ports > HA uptime > Priority > FortiGate serial number
B Connected monitored ports > Priority > HA uptime > FortiGate serial number
C Connected monitored ports > Priority > System uptime > FortiGate serial number
D Connected monitored ports > System uptime > Priority > FortiGate serial number
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Name default

Exhibit

Edit Antivirus Profile Comments Scan files and block viruses Al: 29/255 AntiVirus scan 0 © Block Monitor Feature set Flow-based Proxy based Inspected Protocols HTTP C SMTP C POP3 C IMAP C FTP C CIFS O APT Protection Options Treat Windows executables in email attachments as viruses Send files to FortiSandbax for inspection O Send files to FortiNDR for Inspection O Include mobile malware protection Quarantine O Virus Outbreak Prevention O Use FortiGuard outbreak prevention database Use external maiware block list Use EMS threat feed O Why is the user unable to receive a block replacement message when downloading an infected file
for the first time?
Options
A The firewall policy performs a full content inspection on the file.
B Flow-based inspection is used, which resets the last packet to the user.
C The intrusion prevention security profile must be enabled when using flow-based inspection mode.
D The option to send files to FortiSandbox for inspection is enabled.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.