Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

FCSS_EFW_AD-7.6 Fortinet NSE 7 - Enterprise Firewall 7.6 Administrator Questions and Answers

Questions 4

An administrator wants to scale the IBGP sessions and optimize the routing table in an IBGP network.

Which parameter should the administrator configure?

Options:

A.

network-import-check

B.

ibgp-enforce-multihop

C.

neighbor-group

D.

route-reflector-client

Buy Now
Questions 5

Which two parameters must you configure in neighbor-range for ADVPN iBGP deployment?

Options:

A.

route-reflector-client

B.

neighbor-group

C.

remote-as

D.

update-source

Buy Now
Questions 6

An administrator is extensively using VXLAN on FortiGate.

Which specialized acceleration hardware does FortiGate need to improve its performance?

Options:

A.

NP7

B.

SP5

C.

СР9

D.

NTurbo

Buy Now
Questions 7

Refer to the exhibit.

An HA configuration of an active-active (A-A) cluster with the same HA uptime is shown. You want HQ-NGFW-2 to handle the Core2 VDOM traffic. Which modification must you make to achieve this outcome? (Choose one answer)

Options:

A.

Reboot HQ-NGFW-2.

B.

Change the priority from 100 to 160 for HQ-NGFW-2.

C.

Change the priority from 120 to 200 for HQ-NGFW-2.

D.

Enable override in virtual cluster 2 for HQ-NGFW-2.

Buy Now
Questions 8

You are using Virtual eXtensible LAN (VXLAN) extensively on FortiGate. Which specialized acceleration hardware must you use to improve FortiGate performance? (Choose one answer)

Options:

A.

NP7

B.

SP5

C.

СР9

D.

NTurbo

Buy Now
Questions 9

What can be inferred from the OSPF status output shown?

Options:

A.

Is ASBR

B.

Is BDR

C.

Supports ECMP

D.

Is in area 0.0.0.5

Buy Now
Questions 10

Which two statements about the LAN interface connection are correct?

Options:

A.

802.3ad

B.

SD-WAN

C.

FortiLink

D.

Enable STP

Buy Now
Questions 11

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this VPN IPsec phase 1 configuration?

Options:

A.

This configuration is the best for networks with regular traffic intervals, providing a balance between connectivity assurance and resource utilization.

B.

Peer IDs are unencrypted and exposed, creating a security risk.

C.

FortiGate will not add a route to its routing or forwarding information base when the dynamic tunnel is negotiated.

D.

A separate interface is created for each dial-up tunnel, which can be slower and more resource intensive, especially in large networks.

Buy Now
Questions 12

The IT department discovered during the last network migration that all zero phase selectors in phase 2 IPsec configurations impacted network operations.

What are two valid approaches to prevent this during future migrations? (Choose two.)

Options:

A.

Use routing protocols to specify allowed subnets over the tunnel.

B.

Configure an IPsec-aggregate to create redundancy between each firewall peer.

C.

Clearly indicate to the VPN which segments will be encrypted in the phase two selectors.

D.

Configure an IP address on the IPsec interface of each firewall to establish unique peer connections and avoid impacting network operations.

Buy Now
Questions 13

Refer to the exhibit, which shows the FortiGuard Distribution Network of a FortiGate device.

FortiGuard Distribution Network on FortiGate

An administrator is trying to find the web filter database signature on FortiGate to resolve issues with websites not being filtered correctly in a flow-mode web filter profile.

Why is the web filter database version not visible on the GUI, such as with IPS definitions?

Options:

A.

The web filter database is stored locally, but the administrator must run over CLI diagnose autoupdate versions.

B.

The web filter database is stored locally on FortiGate, but it is hidden behind the GUI. It requires enabling debug mode to make it visible.

C.

The web filter database is not hosted on FortiGate: FortiGate queries FortiGuard or FortiManager for web filter ratings on demand.

D.

The web filter database is only accessible after manual syncing with a valid FDS server using diagnose test update info.

Buy Now
Questions 14

How can you ensure the corporate FortiGate learns the 192.168.1.0/24 network?

Options:

A.

Add static route

B.

Enable RIP

C.

Implement OSPF over IPsec

D.

Add network locally

Buy Now
Questions 15

Which parameter must be configured to modify the MED value?

Options:

A.

route-overlap

B.

distribute-list-out

C.

prefix-list-out

D.

route-map-out

Buy Now
Questions 16

An administrator is designing an ADVPN network for a large enterprise with spokes that have varying numbers of internet links. They want to avoid a high number of routes and peer connections at the hub.

Which method should be used to simplify routing and peer management?

Options:

A.

Deploy a full-mesh VPN topology to eliminate hub dependency.

B.

Implement static routing over IPsec interfaces for each spoke.

C.

Use a dynamic routing protocol using loopback interfaces to streamline peers and routes.

D.

Establish a traditional hub-and-spoke VPN topology with policy routes.

Buy Now
Questions 17

Refer to the exhibits.

The firewall policy ID 1 of the DCFW policy package and the reinstall preview window for the DCFW policy package installation are shown.

Why is FortiManager installing set srcaddr " SSLVPN_tunnel_addr1 " on firewall policy ID 1 when the policy package DCFW has the source address 10.0.5 on the firewall policy ID 1?

Options:

A.

The reinstall policy package ignores recent changes to the policy layer. The administrator must run the Install Wizard.

B.

FortiManager is installing the global policy package, which has higher priority than the ADOM policy package.

C.

FortiManager has assigned firewall HQ-DCFW a CLI template that can overwrite configurations at the policy layer.

D.

The firewall policy and reinstall preview use the same addresses, but they have different names because of per-device mapping.

Buy Now
Questions 18

Refer to the exhibit, which shows a partial troubleshooting command output.

An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit.

What can the administrator conclude?

Options:

A.

IPsec SAs cannot be offloaded.

B.

The two IPsec SAs, inbound and outbound, are copied to the NPU.

C.

Only the outbound IPsec SA is copied to the NPU.

D.

Only the inbound IPsec SA is copied to the NPU.

Buy Now
Questions 19

Refer to the exhibit, which shows an OSPF network.

Which configuration must the administrator apply to optimize the OSPF database?

Options:

A.

Set a route map in the AS boundary FortiGate.

B.

Set the area 0.0.0.1 to the type STUB in the area border FortiGate.

C.

Set an access list in the AS boundary FortiGate.

D.

Set the area 0.0.0.1 to the type NSSA in the area border FortiGate.

Buy Now
Questions 20

How do you resolve object conflicts when importing a policy package?

Options:

A.

Rename

B.

FortiManager accept

C.

Non-default

D.

Retrieve config

Buy Now
Questions 21

Based on the TLS handshake shown, what can be inferred about the client?

Options:

A.

Supports TLS 1.0 only

B.

Supports TLS 1.2 and TLS 1.3

C.

Supports SSLv3

D.

Supports DTLS

Buy Now
Questions 22

Refer to the exhibit, which shows the HA status of an active-passive cluster.

An administrator wants FortiGate_B to handle the Core2 VDOM traffic.

Which modification must the administrator apply to achieve this?

Options:

A.

The administrator must disable override on FortiGate_A.

B.

The administrator must change the priority from 100 to 160 for FortiGate_B.

C.

The administrator must change the load balancing method on FortiGate_B.

D.

The administrator must change the priority from 128 to 200 for FortiGate_B.

Buy Now
Questions 23

Refer to the exhibit.

The partial output of an OSPF command is shown. You are checking the OSPF status of a FortiGate device when you receive the output shown in the exhibit. Based on the output, which two statements about FortiGate are correct? (Choose two answers)

Options:

A.

FortiGate is a backup designated router.

B.

FortiGate supports OSPF ECMP.

C.

FortiGate is in the area 0.0.0.5.

D.

FortiGate can inject external routing information.

Buy Now
Questions 24

How can you ensure FortiGate can analyze encrypted HTTPS traffic?

Options:

A.

Enable SNI

B.

Enable full SSL inspection

C.

Set TLS 1.2

D.

Enable proxy

Buy Now
Questions 25

Refer to the exhibit, which shows an enterprise network connected to an internet service provider.

An administrator must configure a loopback as a BGP source to connect to the ISP.

Which two commands are required to establish the connection? (Choose two.)

Options:

A.

ebgp-enforce-multihop

B.

update-source

C.

ibgp-enforce-multihop

D.

recursive-next-hop

Buy Now
Questions 26

What is the initial step performed by FortiGate when handling the first packets of a session?

Options:

A.

Installation of the session key in the network processor (NP)

B.

Data encryption and decryption

C.

Security inspections such as ACL, HPE, and IP integrity header checking

D.

Offloading the packets directly to the content processor (CP)

Buy Now
Questions 27

What is the effect of configuring tcp-mss-sender and tcp-mss-receiver?

Options:

A.

Header change

B.

Largest payload

C.

Allow/Deny

D.

Fragment only

Buy Now
Questions 28

Refer to the exhibit.

A pre-run CLI template that is used in zero-touch provisioning (ZTP) and low-touch provisioning (LTP) with FortiManager is shown.

The template is not assigned even though the configuration has already been installed on FortiGate.

What is true about this scenario?

Options:

A.

The administrator did not assign the template correctly when adding the model device because pre-CLI templates remain permanently assigned to the firewall

B.

Pre-run CLI templates are automatically unassigned after their initial installation

C.

Pre-run CLI templates for ZTP and LTP must be unassigned manually after the first installation to avoid conflicting error objects when importing a policy package

D.

The administrator must use post-run CLI templates that are designed for ZTP and LTP

Buy Now
Questions 29

Which two options should you consider to scale performance using an additional FortiGate?

Options:

A.

FGSP

B.

FGCP Active-Active

C.

VRRP

D.

FGCP Active-Passive

Buy Now
Questions 30

Which specialized acceleration hardware must you use for VXLAN?

Options:

A.

CPU

B.

NTurbo

C.

CP10

D.

NPU7

Buy Now
Questions 31

You applied a block-all intrusion prevention system (IPS) profile for client and server targets to secure the server but the database team reported that applications stopped working immediately after.

How can you apply IPS in a way that ensures it does not disrupt existing applications in the network?

Options:

A.

Set the IPS profile signature action to default and verify patterns

B.

Use an IPS profile with all signatures in monitor mode and verify patterns before blocking.

C.

Select flow mode in the IPS profile and monitor the application patterns.

D.

Limit the IPS profile to server targets only and set the action to default.

Buy Now
Questions 32

An administrator applied a block-all IPS profile for client and server targets to secure the server, but the database team reported the application stopped working immediately after.

How can an administrator apply IPS in a way that ensures it does not disrupt existing applications in the network?

Options:

A.

Use an IPS profile with all signatures in monitor mode and verify patterns before blocking.

B.

Limit the IPS profile to server targets only to avoid blocking connections from the server to clients.

C.

Select flow mode in the IPS profile to accurately analyze application patterns.

D.

Set the IPS profile signature action to default to discard all possible false positives.

Buy Now
Questions 33

Which parameter should be configured to scale iBGP sessions?

Options:

A.

neighbor-group

B.

recursive-next-hop

C.

route-reflector-client

D.

neighbor-range

Buy Now
Exam Code: FCSS_EFW_AD-7.6
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.6 Administrator
Last Update: Apr 12, 2026
Questions: 113
FCSS_EFW_AD-7.6 pdf

FCSS_EFW_AD-7.6 PDF

$25.5  $84.99
FCSS_EFW_AD-7.6 Engine

FCSS_EFW_AD-7.6 Testing Engine

$30  $99.99
FCSS_EFW_AD-7.6 PDF + Engine

FCSS_EFW_AD-7.6 PDF + Testing Engine

$40.5  $134.99