UPDATED [Nov 28, 2025] Pass FCP - FortiGate 7.6 Administrator Exam with Latest Questions
FCP_FGT_AD-7.6 Exam Practice Questions prepared by Fortinet Professionals
Fortinet FCP_FGT_AD-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 12
You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked.
What FortiGate settings should you check to resolve this issue?
- A. Replacement Messages for UDP-based Applications
- B. Network Protocol Enforcement
- C. FortiGuard category ratings
- D. Application and Filter Overrides
Answer: B
Explanation:
Network Protocol Enforcement settings control how FortiGate inspects and enforces protocols on traffic, including peer-to-peer applications on known ports. If not properly enabled, peer-to-peer traffic may bypass blocking despite the application control profile.
NEW QUESTION # 13
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode.
Which step is NOT part of the expected process?
- A. The DC agent sends login event data directly to FortiGate.
- B. The user logs into the windows domain.
- C. The collector agent forwards login event data to FortiGate.
- D. FortiGate determines user identity based on the IP address in the FSSO list.
Answer: C
Explanation:
In DC Agent Mode, the DC agent sends login event data directly to FortiGate without involving a collector agent.
NEW QUESTION # 14
Refer to the exhibit.
Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
- A. FortiGate skips quarantine actions.
- B. Administrators must restart FortiGate to allow new session.
- C. FortiGate drops new sessions requiring inspection.
- D. Administrators cannot change the configuration.
Answer: A,C
Explanation:
In fail-open mode, FortiGate skips quarantine actions to maintain traffic flow despite IPS or antivirus failures.
FortiGate drops new sessions that require inspection when in conserve mode and fail-open is enabled, to protect the network from potentially harmful traffic.
NEW QUESTION # 15
You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied.
What should the administrator check first?
- A. The windows event viewer for failed login attempts.
- B. Whether the user is assigned to the correct AD group.
- C. The FortiGate FSSO active users list for user's IP address.
- D. The FortiGate firewall policy settings for SSL decryption.
Answer: C
Explanation:
Checking the active users list verifies if FortiGate correctly associates the user with their IP address, ensuring proper policy enforcement for internet access.
NEW QUESTION # 16
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.
Which DPD mode on FortiGate meets this requirement?
- A. Disabled
- B. On Idle
- C. Enabled
- D. On Demand
Answer: C
Explanation:
The "On Idle" DPD mode configures FortiGate to send DPD probes only when no inbound traffic is detected, meeting the requirement to send probes only when the tunnel is idle.
NEW QUESTION # 17
Refer to the exhibits.
The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2.
The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver.
Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver?
- A. Configure a One-to-One IP Pool object in a new policy.
- B. Disable match-vip in the Allow_access policy
- C. Set the Destination address as Deny_IP in the Allow_access policy.
- D. Set the Destination address as Webserver in the Deny policy.
Answer: D
Explanation:
To block Remote-User2's access to the Webserver, the deny policy must explicitly specify the Webserver as the destination address; otherwise, it denies traffic to all destinations, which is not the desired behavior.
NEW QUESTION # 18
You have configured the below commands on a FortiGate.
What would be the impact of this configuration on FortiGate?
- A. Port1 will be enabled with flexible RPF, and all other interfaces will be enabled for strict RPF
- B. The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces.
- C. FortiGate will enable strict RPF on all its interfaces and port1 will be exempted from RPF checks.
- D. FortiGate will enable strict RPF on ail its interfaces and port1 will be enable for asymmetric routing.
Answer: C
Explanation:
The global setting enables strict source checking (RPF) on all interfaces by default. The per-interface setting disables the source check on port1, exempting it from strict RPF enforcement.
NEW QUESTION # 19
Refer to the exhibit.
The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit.
For which two reasons are these web categories exempted? (Choose two.)
- A. The FortiGate temporary certificate denies the browser's access to websites that use HTTP Strict Transport Security.
- B. These websites are in an allowlist of reputable domain names maintained by FortiGuard.
- C. The resources utilization is optimized because these websites are in the trusted domain list on FortiGate.
- D. The legal regulation aims to prioritize user privacy and protect sensitive information for these websites.
Answer: A,D
Explanation:
FortiGate's temporary SSL certificate may cause access denial to sites using HTTP Strict Transport Security (HSTS), so such sites are exempted from deep SSL inspection.
Legal regulations require exemption of certain categories to protect user privacy and sensitive information, so these web categories are excluded from SSL inspection.
NEW QUESTION # 20
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI.
Based on the exhibit, which statement is true?
- A. The virtual-wan-link and overlay zones can be deleted.
- B. The Underlay zone contains no member.
- C. port2 and port3 are not assigned to a zone.
- D. The Underlay zone is the zone by default.
Answer: D
Explanation:
The Underlay zone is the default SD-WAN zone, typically representing the physical interfaces in the SD-WAN configuration before overlay or virtual links are added.
NEW QUESTION # 21
Refer to the exhibits.
Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibit.
What would be the expected outcome in the HA cluster?
- A. HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2.
- B. HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority.
- C. HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1.
- D. The HA cluster will become out of sync because the override setting must match on all HA members.
Answer: C
Explanation:
With override enabled on HQ-NGFW-2 and its higher priority (110 vs. 90), HQ-NGFW-2 will become the primary device, preempting HQ-NGFW-1 despite the current primary status.
NEW QUESTION # 22
A remote user reports slow SSL VPN performance and frequent disconnections. The user is located in an area with poor internet connectivity.
What setting should the administrator adjust to improve the user's experience?
- A. Enable split tunneling to reduce VPN traffic.
- B. Change the SSL VPN port to a non-standard port.
- C. Increase the session timeout for inactive sessions.
- D. Configure the DTLS timeout to accommodate high-latency connections.
Answer: D
Explanation:
Adjusting the DTLS timeout helps maintain SSL VPN stability and performance in environments with poor or high-latency internet connectivity by allowing more time for packet retransmissions before dropping the connection.
NEW QUESTION # 23
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
- A. The NetSessionEnum function is used to track user logouts.
- B. NetAPI polling can increase bandwidth usage in large networks.
- C. The collector agent must search Windows application event logs.
- D. The collector agent uses a Windows API to query DCs for user logins.
Answer: B
Explanation:
NetAPI polling mode involves frequent queries to domain controllers, which can cause increased bandwidth usage, especially in large networks with many login events.
NEW QUESTION # 24
Refer to the exhibits.
The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects.
The WAN (port2) interface has the IP address 100.65.0.101/24.
The LAN (port4) interface has the IP address 10.0.11.254/24.
Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)
- A. 100.65.0.149
- B. 100.65.0.99
- C. 100.65.0.101
- D. 100.65.0.49
Answer: B
Explanation:
The ping traffic policy uses the IP pool named SNAT-Remote1, which has the external IP range 100.65.0.99. Therefore, traffic matching this policy (ping from HQ-PC-1 to BR1-FGT) will use 100.65.0.99 for source NAT.
NEW QUESTION # 25
Refer to the exhibit, which shows a partial configuration from the remote authentication server.
Why does the FortiGate administrator need this configuration?
- A. To set up a RADIUS server Secret.
- B. To authenticate and match the Training OU on the RADIUS server.
- C. To authenticate only the Training user group.
- D. To authenticate Any FortiGate user groups.
Answer: C
Explanation:
The Fortinet-Group-Name attribute is used to restrict authentication to users who belong specifically to the "Training" user group on the RADIUS server.
NEW QUESTION # 26
When configuring a FortiGate in a multi-WAN setup, why would an administrator enable session preservation on an interface?
- A. To allow the FortiGate to dynamically change interfaces for all active sessions when a WAN link fails
- B. To improve security by forcing users to authenticate again when the WAN link changes
- C. To ensure that existing SSL VPN connections remain on the same interface even if route changes occur
- D. To make sure all sessions without source NAT enabled always use the primary WAN link
Answer: C
Explanation:
Session preservation keeps active sessions, such as SSL VPNs, tied to the original interface to prevent disruption when WAN routes change.
NEW QUESTION # 27
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)
- A. Both interfaces must have directly connected routes on the routing table.
- B. Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.
- C. Both interfaces must have the interface role assigned.
- D. Both interfaces must have IP addresses assigned.
Answer: A,D
Explanation:
Interfaces must have directly connected routes in the routing table to forward traffic correctly.
Interfaces must have IP addresses assigned to communicate within their respective networks.
NEW QUESTION # 28
An administrator wants to analyze and manage digital certificates to prevent browser warnings when users connect to the SSL VPN portal.
Which two statements describe how to correctly do this? (Choose two.)
- A. The administrator can rely on the default FortiGate self-signed certificate to prevent all security warnings in the browser.
- B. The administrator can use a publicly trusted certificate from a known certificate authority (CA) to stop browser warnings.
- C. The administrator can import the FortiGate self-signed certificate into each user's browser as a trusted certificate.
- D. The administrator must disable HTTPS administrative access entirely to avoid certificate warnings.
Answer: B,C
Explanation:
Using a publicly trusted certificate from a known CA prevents browser warnings without additional user action.
Importing the FortiGate self-signed certificate into users' browsers as trusted eliminates warnings caused by untrusted certificates.
NEW QUESTION # 29
You have created a web filter profile named restrict_media-profile with a daily category usage quota.
When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.
What could be the reason?
- A. The naming convention used in the web filter profile is restricting it in the firewall policy.
- B. The inspection mode in the firewall policy is not matching with web filter profile feature set.
- C. The firewall policy is in no-inspection mode instead of deep-inspection.
- D. The web filter profile is already referenced in another firewall policy.
Answer: B
Explanation:
Web filter profiles with category usage quotas require the firewall policy to be in proxy-based (deep) inspection mode; if the inspection mode does not match this requirement, the profile will not appear in the drop-down list.
NEW QUESTION # 30
......
FCP_FGT_AD-7.6 Exam Practice Materials Collection: https://www.practicematerial.com/FCP_FGT_AD-7.6-exam-materials.html
Use Valid New FCP_FGT_AD-7.6 Questions - Top choice Help You Gain Success: https://drive.google.com/open?id=1510PaJ83PfWzh_lRABHaZHDqfn9W2Nmr

