FCP_FGT_AD-7.4 Exam Details

  • Exam Code
    :FCP_FGT_AD-7.4
  • Exam Name
    :FCP - FortiGate 7.4 Administrator
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :89 Q&As
  • Last Updated
    :May 31, 2026

Fortinet FCP_FGT_AD-7.4 Online Questions & Answers

  • Question 71:

    An administrator has configured a strict RPF check on FortiGate. How does strict RPF check work?

    A. Strict RPF checks the best route back to the source using the incoming interface.
    B. Strict RPF allows packets back to sources with all active routes.
    C. Strict RPF checks only for the existence of at least one active route back to the source using the incoming interface.
    D. Strict RPF check is run on the first sent and reply packet of any new session.

  • Question 72:

    Which two statements describe how the RPF check is used? (Choose two.)

    A. The RPF check is run on the first sent packet of any new session.
    B. The RPF check is run on the first reply packet of any new session.
    C. The RPF check is run on the first sent and reply packet of any new session.
    D. The RPF check is a mechanism that protects FortiGate and the network from IP spoofing attacks.

  • Question 73:

    Refer to exhibit.

    An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to accesstwitter.com, they are redirected to a FortiGuard web filtering block page. Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?

    A. On the Static URL Filter configuration set Type to Simple
    B. On the FortiGuard Category Based Filter configuration set Action to Warning for Social Networking
    C. On the Static URL Filter configuration set Action to Monitor
    D. On the Static URL Filter configuration set Action to Exempt

  • Question 74:

    Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?

    A. Internet Service Database (ISDB) engine
    B. Intrusion prevention system engine
    C. Antivirus engine
    D. Application control engine

  • Question 75:

    Refer to the exhibit.

    Which two statements are true about the routing entries in this database table? (Choose two.)

    A. All of the entries in the routing database table are installed in the FortiGate routing table.
    B. The port2 interface is marked as inactive.
    C. Both default routes have different administrative distances.
    D. The default route on port2 is marked as the standby route.

  • Question 76:

    Refer to the exhibit.

    Which statement about this firewall policy list is true?

    A. The Implicit group can include more than one deny firewall policy.
    B. The firewall policies are listed by ID sequence view.
    C. The firewall policies are listed by ingress and egress interfaces pairing view.
    D. LAN to WAN. WAN to LAN. and Implicit are sequence grouping view lists.

  • Question 77:

    Refer to the exhibit showing a debug flow output.

    What two conclusions can you make from the debug flow output? (Choose two.)

    A. The debug flow is for ICMP traffic.
    B. A firewall policy allowed the connection.
    C. A new traffic session was created.
    D. The default route is required to receive a reply.

  • Question 78:

    Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)

    A. Pre-shared key and certificate signature as authentication methods
    B. Extended authentication (XAuth)to request the remote peer to provide a username and password
    C. Extended authentication (XAuth) for faster authentication because fewer packets are exchanged
    D. No certificate is required on the remote peer when you set the certificate signature as the authentication method

  • Question 79:

    An organization requires remote users to send external application data running on their PCs and access FTP resources through an SSUTLS connection. Which FortiGate configuration can achieve this goal?

    A. SSL VPN quick connection
    B. SSL VPN tunnel
    C. SSL VPN bookmark
    D. Zero trust network access

  • Question 80:

    Which three CLI commands, can you use to troubleshoot Layer 3 issues if the issue is in neither the physical layer nor the link layer? (Choose three.)

    A. execute ping
    B. execute traceroute
    C. diagnose sys top
    D. get system arp
    E. diagnose sniffer packet any

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your FCP_FGT_AD-7.4 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.