Fortinet FCSS - Enterprise Firewall 7.6 Administrator - FCSS_EFW_AD-7.6 Exam Practice Test
Which parameter must be configured to modify the MED value?
Correct Answer: D
You must segment an enterprise network. Which two features could you use? (Choose two.)
Correct Answer: B,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit.

A partial enterprise network is shown.
What must you configure so that FortiGate A and other OSPF routers in the backbone learn about prefixes generated within the RIP domain?

A partial enterprise network is shown.
What must you configure so that FortiGate A and other OSPF routers in the backbone learn about prefixes generated within the RIP domain?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit, which shows an ADVPN network.

The client behind Spoke-1 generates traffic to the device located behind Spoke-2. What is the first message that the hub sends to Spoke-1 to bring up the dynamic tunnel?

The client behind Spoke-1 generates traffic to the device located behind Spoke-2. What is the first message that the hub sends to Spoke-1 to bring up the dynamic tunnel?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
What does the command set forward-domain <domain_ID> in a transparent VDOM interface do?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit, which shows a physical topology and a traffic log.

The administrator is checking on FortiAnalyzer traffic from the device with IP address 10.1.10.1, located behind the FortiGate ISFW device.
The firewall policy in on the ISFW device does not have UTM enabled and the administrator is surprised to see a log with the action Malware, as shown in the exhibit.
What are the two reasons FortiAnalyzer would display this log? (Choose two.)

The administrator is checking on FortiAnalyzer traffic from the device with IP address 10.1.10.1, located behind the FortiGate ISFW device.
The firewall policy in on the ISFW device does not have UTM enabled and the administrator is surprised to see a log with the action Malware, as shown in the exhibit.
What are the two reasons FortiAnalyzer would display this log? (Choose two.)
Correct Answer: A,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An administrator must improve the resiliency of a link by minimizing data loss within the enterprise network that has full path redundancy.
What should the administrator enable on the FortiGate devices that use BGP as dynamic routing protocol between two separate autonomous systems? (Choose two.)
What should the administrator enable on the FortiGate devices that use BGP as dynamic routing protocol between two separate autonomous systems? (Choose two.)
Correct Answer: A,C
An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode.
Which two actions must the administrator take? (Choose two.)
Which two actions must the administrator take? (Choose two.)
Correct Answer: A,D
Refer to the exhibit.

An ADVPN network is shown.
You must configure an ADVPN using IBGP for each local region and EBGP across regions to connect Overlay 1 with Overlay 2.
Which two options must you configure in the Hub2Hub BGP peering? (Choose two.)

An ADVPN network is shown.
You must configure an ADVPN using IBGP for each local region and EBGP across regions to connect Overlay 1 with Overlay 2.
Which two options must you configure in the Hub2Hub BGP peering? (Choose two.)
Correct Answer: A,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibits.


The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown.
When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials.
What is the next status for the user?


The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown.
When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials.
What is the next status for the user?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration.


Why is FortiGate unable to detect HTTPS attacks on firewall policy ID 3 targeting the Linux server?


Why is FortiGate unable to detect HTTPS attacks on firewall policy ID 3 targeting the Linux server?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
How will configuring set tcp-mss-sender and set tcp-mss-receiver in a firewall policy affect the size and handling of TCP packets in the network?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).