FCSS_EFW_AD-7.4: FCSS - Enterprise Firewall 7.4 Administrator Fortigate Practice Questions
The free FCSS_EFW_AD-7.4: FCSS - Enterprise Firewall 7.4 Administrator questions that deal with fortigate, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
Refer to the exhibit, which shows a command output. FortiGate_A and FortiGate_B are members of an FGSP cluster in an enterprise network. While testing the cluster using the ping command, the administrator monitors packet loss and found that the session output on FortiGate_B is as shown in the exhibit. What could be the cause of this output on FortiGate_B?

Correct answer: B
Explanation
TheFortinet FGSP (FortiGate Session Life Support Protocol) clusterallows session synchronization betweentwo FortiGate devicesto provide seamless failover. However, ICMP (ping) is a connectionless protocol, and by default, FortiGate does not synchronize connectionless sessions unless explicitly enabled. In the exhibit: The commandget system session list | grep icmponFortiGate_Breturnsno output, meaning that ICMP sessions arenot being synchronizedfrom FortiGate_A. Ifsession-pickup-connectionlessis disabled,FortiGate_B will not receive ICMP sessions, causingpacket lossduring failover.
Question #6
Refer to the exhibit, which shows a revision history window in the FortiManager device layer. The IT team is trying to identify the administrator responsible for the most recent update in the FortiGate device database. Which conclusion can you draw about this scenario?

Correct answer: D
Explanation
TheConfiguration Revision Historywindow inFortiManagershows that the most recent configuration change (ID 10) was created byscript_managerwith the actionRetrieved. Sincescript_manager is a system-level script execution user, the IT team needs to find who actually triggered this script. This can be done by: Checking theFortiManager system logsforscript execution events. Using thetype=scriptfilter to locate the administrator associated with the script execution.
Question #8
An administrator is extensively using VXLAN on FortiGate. Which specialized acceleration hardware does FortiGate need to improve its performance?
Correct answer: A
Explanation
VXLAN (Virtual Extensible LAN)is an overlay network technology that extends Layer 2 networks over Layer 3 infrastructure. When VXLAN is used extensively on FortiGate, hardware acceleration is crucial for maintaining performance. NP7 (Network Processor 7)is Fortinet's latest network processor designed to accelerate high-performance networking features, including: VXLAN encapsulation/decapsulation IPsec VPN offloading Firewall policy enforcement Advanced threat protection at wire speed NP7 significantlyreduces latency and improves throughputwhen handling VXLAN traffic, making it the best choice for large-scale VXLAN deployments.
Continue with FCSS_EFW_AD-7.4: FCSS - Enterprise Firewall 7.4 Administrator
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in FCSS_EFW_AD-7.4: FCSS - Enterprise Firewall 7.4 Administrator, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All FCSS_EFW_AD-7.4: FCSS - Enterprise Firewall 7.4 Administrator practice questions →
