New FCSS_EFW_AD-7.4 Dumps For Preparing Fortinet Certified Solution Specialist Certified Fortinet Exam Well
Updated FCSS_EFW_AD-7.4 Dumps Questions Are Available [2026] For Passing Fortinet Exam
NEW QUESTION # 28
Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)
- A. Previewing pending configuration changes for managed devices.
- B. Importing interface mappings from managed devices.
- C. Installing configuration changes to managed devices.
- D. Adding devices to FortiManager.
Answer: A,C
NEW QUESTION # 29
Refer to the exhibit, which contains the partial output of an IKE real-time debug.

The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?
- A. Change phase 1 encryption to 3DES and authentication to SHA256.
- B. Change phase 1 encryption to AES128 and authentication to SHA512.
- C. Change phase 1 encryption to 3DES and authentication to CBC.
- D. Change phase 1 encryption to AESCBC and authentication to SHA128.
Answer: A
NEW QUESTION # 30
An administrator is extensively using VXLAN on FortiGate. Which specialized acceleration hardware does FortiGate need to improve its performance?
- A. 0
- B. NP7
- C. SP5
- D. NTurbo
Answer: B
Explanation:
VXLAN (Virtual Extensible LAN) is an overlay network technology that extends Layer 2 networks over Layer 3 infrastructure. When VXLAN is used extensively on FortiGate, hardware acceleration is crucial for maintaining performance.
NP7 (Network Processor 7) is Fortinet's latest network processor designed to accelerate high- performance networking features, including:
- VXLAN encapsulation/decapsulation
- IPsec VPN offloading
- Firewall policy enforcement
- Advanced threat protection at wire speed
NP7 significantly reduces latency and improves throughput when handling VXLAN traffic, making it the best choice for large-scale VXLAN deployments.
NEW QUESTION # 31
View the exhibit, which contains the output of a diagnose command, and then answer the question below.
Which statements are true regarding the output in the exhibit? (Choose two.)
- A. Servers with a negative TZ value are experiencing a service outage.
- B. Servers with the D flag are considered to be down.
- C. FortiGate used 209.222.147.36 as the initial server to validate its contract.
- D. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
Answer: C,D
NEW QUESTION # 32
Which of the following conditions must be met for a static route to be active in the routing table?
(Choose three.)
- A. The next-hop IP address is up.
- B. The link health monitor (if configured) is up.
- C. There is no other route, to the same destination, with a higher distance.
- D. The outgoing interface is up.
- E. The next-hop IP address belongs to one of the outgoing interface subnets.
Answer: B,D,E
NEW QUESTION # 33
The logs in a FSSO collector agent (CA) are showing the following error:
failed to connect to registry: PIKA1026 (192.168.12.232)
What can be the reason for this error?
- A. The remote registry service is not running in the workstation 192.168.12.232.
- B. The CA cannot reach the FortiGate with the IP address 192.168.12.232.
- C. The FortiGate cannot resolve the name of the workstation.
- D. The CA cannot resolve the name of the workstation.
Answer: A
NEW QUESTION # 34
Refer to the exhibit, which shows a partial troubleshooting command output.
An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit.
What can the administrator conclude?
- A. IPsec SAs cannot be offloaded.
- B. The two IPsec SAs, inbound and outbound, are copied to the NPU.
- C. Only the outbound IPsec SA is copied to the NPU.
- D. Only the inbound IPsec SA is copied to the NPU.
Answer: B
Explanation:
The diagnose vpn tunnel list name Hub2Spoke1 command output provides key information about the offloading status of an IPsec VPN tunnel to the Network Processing Unit (NPU).
# npu_flag=20:
# This flag indicates that both inbound and outbound IPsec Security Associations (SAs) have been offloaded to the NPU, meaning the VPN traffic is processed in hardware instead of the CPU.
# npu_rgwy=10.10.2.2 and npu_lgwy=10.10.1.1:
# These IPs represent the remote gateway (rgwy) and local gateway (lgwy), confirming that the tunnel is successfully offloaded.
# npu_selid=1:
# This value means the session selector for the NPU offloaded SA is active.
Since both inbound and outbound SAs are offloaded, the administrator can conclude that the FortiGate NPU is handling IPsec encryption and decryption efficiently, reducing CPU load and improving VPN performance.
NEW QUESTION # 35
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration.

Why is FortiGate unable to detect HTTPS attacks on firewall policy ID 3 targeting the Linux server?
- A. The administrator must enable SSL inspection of the SSL server and upload the certificate of the Linux server website to the SSL/SSH inspection profile.
- B. The administrator must set the policy to inspection mode to analyze the HTTPS packets as expected.
- C. The administrator must enable cipher suites in the SSL/SSH inspection profile to decrypt the message.
- D. The administrator must enable HTTPS in the protocol port mapping of the deep- inspection SSL/SSH inspection profile.
Answer: A
Explanation:
The FortiGate SSL/SSH inspection profile is configured for Full SSL Inspection, which is necessary to analyze encrypted HTTPS traffic. However, the firewall policy is protecting an SSL server (the Linux server hosting the website), and currently, the SSL/SSH profile only applies to client-side SSL inspection.
To detect HTTPS-based attacks targeting the Linux server:
FortiGate must act as an SSL intermediary to inspect encrypted traffic destined for the web server. The administrator must upload the SSL certificate of the Linux web server to FortiGate so that the server-side SSL inspection can decrypt incoming HTTPS traffic before analyzing it.
NEW QUESTION # 36
View the exhibit, which contains the sniffer output for a passive mode FTP request, and then answer the question below.
An administrator has created the following custom IPS signature to block all FTP requests for passive mode:
F-SBID (--attack_id 1002; --name "Block.FTP "; --protocol tcp; --flow from_client; --pattern "PASV"; -- no_case;) Soon after the signature is enabled in an active IPS sensor, some false positive detections are generated.
Which of the following option and value pairs will allow more specific detection?
- A. --attack_id 1001
- B. --protocol ftp
- C. --name "Block.FTP.PASV
- D. --service ftp
Answer: D
NEW QUESTION # 37
Refer to the exhibit, which shows a revision history window in the FortiManager device layer.
The IT team is trying to identify the administrator responsible for the most recent update in the FortiGate device database.
Which conclusion can you draw about this scenario?
- A. This retrieved process was automatically triggered by a Remote FortiGate Directly (via CLI) script.
- B. Find the user in the FortiManager system logs and use the type=script command to find the administrator user in the user field.
- C. To identify the user who created the event, check it on the Configuration and Installation widget on FortiGate within the FortiManager device layer.
- D. The user script_manager is an API user from the Fortinet Developer Network (FDN) retrieving a configuration.
Answer: B
Explanation:
TheConfiguration Revision Historywindow inFortiManagershows that the most recent configuration change (ID 10) was created byscript_managerwith the actionRetrieved.
Sincescript_manageris a system-level script execution user, the IT team needs to findwho actually triggered this script. This can be done by:
# Checking theFortiManager system logsforscript execution events.
# Using thetype=scriptfilter to locate the administrator associated with the script execution.
NEW QUESTION # 38
Refer to the exhibit, which contains the partial output of an OSPF command.
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in the exhibit.
What two conclusions can the administrator draw? (Choose two.)
- A. The FortiGate device injects external routing information
- B. The FortiGate device is a backup designated router
- C. The FortiGate device is connected to multiple areas
- D. The FortiGate device has OSPF ECMP enabled
Answer: A,C
Explanation:
The output of the get router info ospf status command provides key information about the OSPF (Open Shortest Path First) configuration on the FortiGate device.
The FortiGate device is connected to multiple areas
The output states: "This router is an ABR"
ABR (Area Border Router) means the device is connected to multiple OSPF areas and maintains routing information between them.
This confirms that the FortiGate is not just in one area, but at least one backbone area (Area 0) and another OSPF area.
The FortiGate device injects external routing information
The output states: "Supports opaque LSA"
Opaque LSAs (Type 9, 10, and 11) are used in OSPF extensions, including those that support external route injection.
Typically, ABRs or ASBRs (Autonomous System Boundary Routers) inject external routes, allowing routes from other routing protocols (such as BGP or static routes) to be advertised into OSPF.
NEW QUESTION # 39
Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy.
What must the administrator change to fix the issue?
- A. The administrator must change protocol to TCP.
- B. The administrator must increase webfilter-timeout.
- C. The administrator must disable webfilter-force-off.
- D. The administrator must enable fortiguard-anycast.
Answer: C
NEW QUESTION # 40
You want to know which content processor (CP) model FortiGate contains.
Which command should you enter?
- A. diagnose hardware lspci | grep 4e36
- B. get hardware cp
- C. get hardware status
- D. diagnose hardware deviceinfo
Answer: C
NEW QUESTION # 41
Refer to the exhibit, which shows a command output.
FortiGate_A and FortiGate_B are members of an FGSP cluster in an enterprise network.
While testing the cluster using the ping command, the administrator monitors packet loss and found that the session output on FortiGate_B is as shown in the exhibit.
What could be the cause of this output on FortiGate_B?
- A. FortiGate_A and FortiGate_B have the same standalone-group-id value.
- B. FortiGate_B is configured in passive mode.
- C. session-pickup-connectionless is set to disable on FortiGate_B.
- D. The session synchronization is encrypted.
Answer: C
Explanation:
TheFortinet FGSP (FortiGate Session Life Support Protocol) clusterallows session synchronization betweentwo FortiGate devicesto provide seamless failover. However,ICMP (ping) is a connectionless protocol, and by default, FortiGate does not synchronize connectionless sessions unless explicitly enabled.
In the exhibit:
# The commandget system session list | grep icmponFortiGate_Breturnsno output, meaning that ICMP sessions arenot being synchronizedfrom FortiGate_A.
# Ifsession-pickup-connectionlessis disabled,FortiGate_B will not receive ICMP sessions, causingpacket lossduring failover.
NEW QUESTION # 42
Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud.
What two conclusions can you draw from the exhibit? (Choose two.)
- A. FortiGate is connecting to the same IP server and will receive an independent certificate for its connection between FortiGate and FortiManager Cloud.
- B. FortiGate will receive a certificate that supports multiple domains because FortiManager operates in a cloud computing environment.
- C. The wildcard for the domain *.fortinet-ca2.support.fortinet.com must be supported by FortiManager Cloud.
- D. If the TLS handshake contains 17 cipher suites it means the TLS version must be 1.0 on this three- way handshake.
Answer: C
Explanation:
The packet capture output displays a TLS Client Hello message from FortiGate to FortiManager Cloud. This message contains Server Name Indication (SNI), which is used to indicate the domain name that FortiGate is trying to connect to.
FortiGate will receive a certificate that supports multiple domains because FortiManager operates in a cloud computing environment.
FortiManager Cloud hosts multiple customers and domains under a shared infrastructure. The TLS handshake includes SNI (Server Name Indication), which allows FortiManager Cloud to serve multiple certificates based on the requested domain. This means FortiGate will likely receive a multi-domain or wildcard certificate that can be used for multiple customers under FortiManager Cloud.
The wildcard for the domain .fortinet-ca2.support.fortinet.com must be supported by FortiManager Cloud.
The SNI extension contains the domain 9398.support.fortinet-ca2.fortinet.com. FortiManager Cloud must support wildcard certificates such as *.fortinet-ca2.support.fortinet.com to securely manage multiple subdomains and customers. This ensures that FortiGate can validate the server certificate without any TLS errors.
NEW QUESTION # 43
Which step can be taken to ensure that only FortiAP devices receive IP addresses from a DHCP server on FortiGate?
- A. Change the interface addressing mode to FortiAP devices
- B. Configure a VCI string value of FortiAP in the DHCP server settings
- C. Create a reservation list in the DHCP server settings
- D. Use DHCP option 138 to assign IPs to FortiAP devices
Answer: B
NEW QUESTION # 44
Refer to the exhibit.
An administrator wants to expand the network by adding two additional FortiGate devices into AS
6500.
Which configuration is the most effective way to improve BGP convergence in this scenario?
- A. Neighbor group
- B. BFD
- C. Prefix list
- D. Route reflector
Answer: D
NEW QUESTION # 45
An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23:
ff:fc:00:86.
What two conclusions can the administrator draw? (Choose two.)
- A. The suspicious packet is related to a cluster that has VDOMs enabled.
- B. The network includes FortiGate devices configured with the FGSP protocol.
- C. The suspicious packet is related to a cluster with a group-id value lower than 255.
- D. The suspicious packet corresponds to port 7 on a FortiGate device.
Answer: A,C
Explanation:
The MAC addresse0:23:ff:fc:00:86follows the format used inFortiGate High Availability (HA) clusters.
When FortiGate devices are in an HA configuration, they usevirtual MAC addressesfor failover and redundancy purposes.
The suspicious packet is related to a cluster that has VDOMs enabled:FortiGate devices withVirtual Domains (VDOMs)enabled use specific MAC address ranges to differentiate HA-related traffic. This MAC address is likely part of that mechanism.
The suspicious packet is related to a cluster with a group-id value lower than 255:FortiGate HA clusters assign virtual MAC addresses based on thegroup ID. The last octet (00:86) corresponds to agroup IDthat is below 255, confirming this option.
NEW QUESTION # 46
Which of the following statements are true regarding the SIP session helper and the SIP application layer gateway (ALG)? (Choose three)
- A. SIP helper supports SIP over TCP and UDP; SIP ALG supports only SIP over UDP.
- B. SIP ALG supports SIP HA failover; SIR helper does not
- C. SIP ALG can create expected sessions for media traffic; SIP helper does not.
- D. SIP ALG supports SIP over IPv6; SIR helper does not.
- E. SIP session helper runs in the kernel; SIP ALG runs as a user space process.
Answer: B,D,E
NEW QUESTION # 47
Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week.

Which two statements about the output are true? (Choose two.)
- A. If no action is taken, the primary FortiGate will leave the cluster due to the current sync status.
- B. If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.
- C. If FGVM...649 is rebooted, FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.
- D. If port7 becomes disconnected on the secondary, both FortiGate devices will elect itself the primary.
Answer: C,D
NEW QUESTION # 48
......
Fortinet Exam 2026 FCSS_EFW_AD-7.4 Dumps Updated Questions: https://examcollection.actualcollection.com/FCSS_EFW_AD-7.4-exam-questions.html