2026 Updated FCP_FGT_AD-7.6 PDF for the FCP_FGT_AD-7.6 Tests Free Updated Today!
Fully Updated Dumps PDF - Latest FCP_FGT_AD-7.6 Exam Questions and Answers
Fortinet FCP_FGT_AD-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 44
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
- A. The subject alternative name (SAN) field in the server certificate.
- B. The subject field in the server certificate.
- C. The host field in the HTTP header.
- D. The serial number in the server certificate.
- E. The server name indication (SNI) extension in the client hello message.
Answer: A,B,E
Explanation:
When using SSL certificate inspection, FortiGate is not decrypting the traffic. During the exchange of hello messages at the beginning of an SSL handshake, FortiGate parses the server name indication (SNI) from client Hello, which is an extension of the TLS protocol. The SNI tells FortiGate the hostname of the SSL server, which is validated against the DNS name before receipt of the server certificate. If there is no SNI exchanged, then FortiGate identifies the server by the value in the server by the value in the Subject field or SAN (Subject Alternative Name) field in the server certificate.
NEW QUESTION # 45
Refer to the exhibits.

You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.
You cannot access any of the Google applications, but you are able to access www.fortinet.com.
What would you do to resolve this issue?
- A. Add *Google*.com to the URL category in the security profile.
- B. Set SSL inspection to deep-content-inspection.
- C. Change the Inspection mode to Proxy-based.
- D. Move up Google in the Application and Filter Overrides section to set its priority to 1.
Answer: B
NEW QUESTION # 46
Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.)
- A. Manual with load balancing
- B. Lowest Quality (SLA) with load balancing
- C. Lowest Cost (SLA) with load balancing
- D. Lowest Cost (SLA) without load balancing
- E. Best Quality with load balancing
Answer: A,C,D
NEW QUESTION # 47
What is the primary FortiGate election process when the HA override setting is enabled?
- A. Connected monitored ports > HA uptime > Priority > FortiGate serial number
- B. Connected monitored ports > Priority > HA uptime > FortiGate serial number
- C. Connected monitored ports > Priority > System uptime > FortiGate serial number
- D. Connected monitored ports > System uptime > Priority > FortiGate serial number
Answer: B
Explanation:
If Override DISABLED then: ports > HA Uptime > Priority > SN.
If Overrrid ENABLED then: ports > Priority > HA Uptime > SN.
NEW QUESTION # 48
FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively.
Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.)
- A. Both interfaces must have the interface role assigned.
- B. Both interfaces must have directly connected routes on the routing table.
- C. Both interfaces must have DHCP enabled and interfaces set to LAN and DMZ roles assigned.
- D. Both interfaces must have IP addresses assigned.
Answer: B,D
Explanation:
Interfaces must have directly connected routes in the routing table to forward traffic correctly.
Interfaces must have IP addresses assigned to communicate within their respective networks.
NEW QUESTION # 49
Which two statements describe characteristics of automation stitches? (Choose two.)
- A. Multiple actions can run in parallel.
- B. An automation stitch can have multiple triggers.
- C. Actions involve only devices included in the Security Fabric.
- D. Triggers can involve external connectors.
Answer: A,D
Explanation:
Automation stitches can execute multiple actions concurrently (in parallel). Triggers for automation stitches can come from external connectors beyond just Fortinet devices.
NEW QUESTION # 50
Refer to the exhibit.
As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?
- A. FortiGate entered into IPS fail open state.
- B. Administrator entered the command diagnose test application ipsmonitor 99.
- C. Administrator entered the command diagnose test application ipsmonitor 5.
- D. There is a no firewall policy configured with an IPS security profile.
Answer: D
Explanation:
The output shows the IPS engine count as 0, indicating no active IPS engines are running. This typically means no firewall policy is referencing the IPS security profile, so the IPS profile is not being applied or triggered.
NEW QUESTION # 51
What are two features of FortiGate FSSO agentless polling mode? (Choose two.)
- A. FortiGate directs the collector agent to use a remote LDAP server.
- B. FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
- C. FortiGate uses the AD server as the collector agent.
- D. FortiGate does not support workstation check.
Answer: B,D
NEW QUESTION # 52 
Refer to the exhibits.
You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits.
Which two factors can you observe from these configurations? (Choose two.)
- A. YouTube search is allowed based on the Google Application and Filter override settings.
- B. YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings.
- C. Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings.
- D. Facebook access is blocked based on the category filter settings.
Answer: B,D
NEW QUESTION # 53
Refer to the exhibit.
FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?
- A. The user is using an incorrect user name.
- B. No matching user account exists for this user.
- C. The Remote-users group is not added to the Destination.
- D. The Service DNS is required in the firewall policy.
Answer: D
Explanation:
In FortiGate firewall authentication, users are prompted for login credentials only when their initial request matches a policy requiring authentication.
In this configuration, the firewall policy permits HTTP, HTTPS, and ICMP traffic, but DNS service is missing.
Since browsers first need DNS resolution before sending HTTP/HTTPS requests, the user cannot reach the FortiGate for authentication.
Adding DNS to the Service field (Option A) enables the user to resolve hostnames and trigger the firewall authentication prompt.
NEW QUESTION # 54
Refer to the exhibit, which contains a RADIUS server configuration.
An administrator added a configuration for a new RADIUS server. While configuring, the administrator enabled Include in every user group.
What is the impact of enabling Include in every user group in a RADIUS configuration?
- A. This option places all FortiGate users and groups required to authenticate into the RADIUS server, which, in this case, is FortiAuthenticator.
- B. This option places the RADIUS server, and all users who can authenticate against that server, into every FortiGate user group.
- C. This option places all users into every RADIUS user group, including groups that are used for the LDAP server on FortiGate.
- D. This option places the RADIUS server, and all users who can authenticate against that server, into every RADIUS group.
Answer: B
Explanation:
Enabling Include in every user group in the RADIUS configuration means the RADIUS server is automatically added to all FortiGate user groups. As a result, any user who can authenticate successfully against that RADIUS server becomes a member of every FortiGate user group, without needing to be manually assigned. This can inadvertently grant excessive access if not carefully controlled.
NEW QUESTION # 55
Refer to the exhibit. Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)
- A. FortiGate drops new sessions requiring inspection.
- B. Administrators must restart FortiGate to allow new session.
- C. Administrators cannot change the configuration.
- D. FortiGate skips quarantine actions.
Answer: C,D
Explanation:
System configuration cannot be changed because of the IPS Global configuration "fail-open enabled" FortiGate skips quarantine actions - again because of the IPS Global configuration "fail-open enabled"
NEW QUESTION # 56
Refer to the exhibit. The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.
An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)
- A. Set the Freeware and Software Downloads category Action to Warning.
- B. Configure a web override rating for download.com and select Malicious Websites as the subcategory.
- C. Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
- D. Configure a separate firewall policy with action Deny and an FQDN address object for*.download.com as destination address.
Answer: C,D
Explanation:
Creating a static URL filter to block download.com specifically allows blocking that site without affecting the entire category.
Using a separate firewall policy with a Deny action for an FQDN address object matching download.com can also block the site while allowing others in the same category.
NEW QUESTION # 57
Refer to the exhibit. FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles.
Which action must the administrator perform to consolidate the two policies into one?
- A. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy.
- B. Select port1 and port2 subnets in a single firewall policy.
- C. Create an Aggregate interface that includes port1 and port2 to create a single firewall policy.
- D. Replace port1 and port2 with the any interface in a single firewall policy.
Answer: A
Explanation:
Enabling Multiple Interface Policies allows you to select multiple interfaces (like port1 and port2) in a single firewall policy, consolidating access rules for both Sales and Engineering to the web server.
NEW QUESTION # 58
Refer to the exhibits.
The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device.
Based on the system performance output, what are the two possible outcomes? (Choose two.)
- A. Administrators can change the configuration.
- B. FortiGate drops new sessions.
- C. FortiGate has entered conserve mode.
- D. Administrators can access FortiGate only through the console port.
Answer: A,B
Explanation:
Since memory usage is at 90%, exceeding the red threshold (88%), FortiGate enters a state where configuration changes are still allowed.
In this state, FortiGate drops new sessions to preserve resources and maintain stability.
NEW QUESTION # 59
......
Free FCP_FGT_AD-7.6 Exam Questions FCP_FGT_AD-7.6 Actual Free Exam Questions: https://simplilearn.actual4labs.com/Fortinet/FCP_FGT_AD-7.6-actual-exam-dumps.html