FCP - FortiGate 7.4 Administrator (FCP_FGT_AD) - Fortinet Actual Exam Questions
Last updated on May 02, 2026
Refer to the exhibit. Which statement about this firewall policy list is true?
The Implicit group can include more than one deny firewall policy.
The firewall policies are listed by ID sequence view.
The firewall policies are listed by ingress and egress interfaces pairing view.
LAN to WAN. WAN to LAN. and Implicit are sequence grouping view lists.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet. Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.)
o. l. 3 as an address object in the source field.
In the firewall policy configuration, add
In the IP pool configuration, set endig to 192.2.0.12.
Configure another firewall policy that matches only the address of PC3 as source, and then place the policy on top of the list.
In the IP pool configuration, set cype to overload.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover. Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)
Enable Dead Peer Detection
Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
Configure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable the service on the interface. In this scenario, what prevents the administrator from enabling DHCP service?
The role of the interface prevents setting a DHCP server.
The DHCP server setting is available only on the CLI.
Another interface is configured as the only DHCP server on FortiGate.
The FortiGate model does not support the DHCP server.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection? (Choose two.)
The issuer must be a public CA
The CA extension must be set to TRUE
The Authority Key Identifier must be of type SSL
The keyUsage extension must be set to keyCertSign
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.