FCSS-EFW-AD-7-4 Sample Questions

FCSS-EFW-AD-7-4 Sample Questions & Answers

Topics run from standing up the Security Fabric with hardware acceleration and high-availability modes, through FortiManager- and FortiAnalyzer-based central management, OSPF and BGP routing, SSL/SSH inspection and web-filtering profiles, to IPsec VPN with ADVPN.

Launch the full FCSS-EFW-AD-7-4 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    System and session troubleshooting · Diagnose and troubleshoot resource problems using built-in tools

    An administrator is configuring a new VDOM named 'Guest-WiFi' on a FortiGate 1800F, which is equipped with NP7 processors. To maximize performance for the guest traffic, the administrator wants to ensure it is offloaded by the NP7 processors. Which step is essential to achieve this?

    Show answer & explanation

    Correct answer: D

    On FortiGate models with multiple NP7 processors, you can dedicate specific processors to particular VDOMs. By using the config global and config system npu CLI commands to set vdom-npu-affinity, the administrator can bind the 'Guest-WiFi' VDOM to a specific NP7, ensuring its traffic is prioritized for hardware acceleration by that processor.

  2. Question 2Intermediate

    Central Management · Troubleshoot central management issues

    A junior administrator is using the FortiManager script console to apply a configuration change to a group of FortiGate devices. The script fails with a 'permission denied' error. The administrator's account has 'Super_User' privileges on the ADOM containing the devices. What is the most likely reason for the script failure?

    Show answer & explanation

    Correct answer: C

    In FortiManager, permissions are granular. Even with Super_User rights within an ADOM, the administrator's overall access profile must explicitly grant permissions for 'Script Management'. Without this specific permission, the administrator cannot create, edit, or run scripts, resulting in a 'permission denied' error.

  3. Question 3Intermediate

    VPN Configuration · Implement a meshed or partially redundant IPsec VPN

    A manufacturing company uses a site-to-site IPsec VPN between its headquarters and a factory. Users report that the VPN tunnel disconnects every evening and does not automatically reconnect. The administrator confirms that Phase 1 and Phase 2 lifetimes are standard, and DPD (Dead Peer Detection) is enabled on both ends. What is the most likely cause for the tunnel failing to re-establish?

    Show answer & explanation

    Correct answer: A

    When auto-negotiate is disabled, the FortiGate will not attempt to bring the tunnel up automatically after it goes down (for example, due to lifetime expiration). It will wait for interesting traffic to trigger the negotiation. Since the disconnection happens overnight when traffic is low, the tunnel remains down. Enabling auto-negotiate ensures the FortiGate proactively re-establishes the tunnel.

  4. Question 4Intermediate

    Content inspection · Troubleshoot the Intrusion Prevention System (IPS)

    An administrator is reviewing the logs on FortiAnalyzer and notices a large number of IPS events with the action pass from a signature designed to detect anomalous DNS queries. The security policy requires that these events are logged but not blocked, as they are part of a research project. However, the sheer volume of these logs is making it difficult to find other critical alerts. What is the best way to handle this situation without losing visibility?

    Show answer & explanation

    Correct answer: C

    The best approach is to use a FortiAnalyzer event handler. An event handler can be configured to automatically process incoming logs that match specific criteria (like the IPS signature ID). It can then perform an action, such as marking the event as acknowledged or changing its severity, which effectively hides it from the default alert views without deleting the log data. This preserves visibility for forensic purposes while cleaning up the active monitoring console.

  5. Question 5BeginnerSelect 2

    System Configuration · Implement Virtual Domains (VDOMs)

    A university has implemented multiple VDOMs on a single FortiGate to separate faculty, student, and administrative networks. The administrator needs to establish communication between the 'Faculty-VDOM' and the 'Admin-VDOM' for a specific application. Which two methods can be used to route traffic between these two VDOMs on the same FortiGate device? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    Traffic between VDOMs on the same device can be routed either virtually using an inter-VDOM link (a software or hardware-accelerated connection) or physically by connecting two ports with a cable and assigning each port to a different VDOM. The inter-VDOM link is the more common and efficient method.

  6. Question 6Beginner

    Central Management · Use metadata variables for dynamic configuration

    What is the primary function of metadata variables within FortiManager provisioning templates?

    Show answer & explanation

    Correct answer: A

    Metadata variables act as placeholders in a provisioning template. They allow you to create a single, generic configuration template that can be applied to many devices, while the variables are dynamically replaced with unique values (such as IP address, hostname, location) defined for each specific device in FortiManager.

  7. Question 7Intermediate

    VPN Configuration · Troubleshoot IPsec connectivity

    A network engineer is troubleshooting a new IPsec tunnel where IKEv2 is used. The diagnose vpn ike log filter is configured, and the debug output shows that the remote peer is not responding to the IKE_SA_INIT message sent by the local FortiGate. The engineer has verified that the public IP address of the remote peer is correct. What is the most common cause of this issue?

    Show answer & explanation

    Correct answer: C

    The IKE_SA_INIT message is the very first packet in the IKEv2 exchange, sent over UDP port 500. If the remote peer does not respond at all, it almost always indicates a connectivity issue. The most common cause is a firewall policy on the local or remote side, or an upstream network device (like an ISP router), blocking the IKE (UDP 500) or NAT-T (UDP 4500) ports.

  8. Question 8Beginner

    System Configuration · Implement the Fortinet Security Fabric

    An administrator needs to implement a Security Fabric between a root FortiGate in a data center and three downstream FortiGate devices in branch offices. What is a prerequisite for a downstream FortiGate to join the Security Fabric?

    Show answer & explanation

    Correct answer: C

    For a downstream FortiGate to join a Security Fabric, an interface on that device must be dedicated to this purpose. This is done by editing the interface and setting its role to 'Security Fabric Connection'. This allows the device to listen for and respond to authorization requests from the upstream (root) FortiGate.

  9. Question 9Intermediate

    Content inspection · Troubleshoot web filtering issues

    A company has a guest wireless network policy that uses a captive portal for authentication. The security team wants to apply web filtering to this traffic but is concerned about performance, as the FortiGate model in use has a low-end CPU. Which web filtering inspection mode should be used to provide URL filtering with the least impact on CPU resources?

    Show answer & explanation

    Correct answer: B

    For the lowest resource impact, flow-based inspection combined with a DNS filter profile is the most efficient choice. DNS filtering inspects only the DNS query itself to determine the category of the requested domain, blocking access before an HTTP session is even established. This is significantly less CPU-intensive than flow-based web filtering (which inspects HTTP headers) or proxy-based filtering (which buffers the entire content).

  10. Question 10Intermediate

    Central Management · Troubleshoot central management issues

    After a recent configuration change on FortiManager, an administrator notices that all managed FortiGate devices have gone into a 'modified' state. The administrator did not intentionally make any changes to the device-level settings. What is the most likely cause of this status change?

    Show answer & explanation

    Correct answer: B

    When an object (like an address or service) or a policy package that is assigned to a device is modified, FortiManager flags the device's configuration status as 'modified'. This indicates that the configuration stored on FortiManager for that device no longer matches the last installed configuration, even if the change was to a shared object rather than a direct device setting.

Ready for the real thing?

The full FCSS-EFW-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.