[2025年03月] 最新のFCP_FGT_AD-7.4試験問題集には合格保証が付きます [Q45-Q67]

Share

[2025年03月] 最新のFCP_FGT_AD-7.4試験問題集には合格保証が付きます

信頼できるFCP in Network Security FCP_FGT_AD-7.4問題集PDFで2025年03月09日に更新された問題


Fortinet FCP_FGT_AD-7.4 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • VPN: In this section, the focus is on how to configure SSL VPNs for secure network access and implement meshed or redundant IPsec VPNs.
トピック 2
  • Routing: This section covers how to set up packet routing with static routes and configure SD-WAN for efficient traffic load balancing.
トピック 3
  • Firewall Policies and Authentication: This topic covers how to set firewall policies, configure SNAT
  • DNAT, implement authentication methods, and deploy FSSO.
トピック 4
  • Deployment and System Configuration: This section covers how to set up initial configurations, implement Fortinet Security Fabric, and configure an FGCP HA cluster; diagnose resources and connectivity.
トピック 5
  • Content Inspection: This section covers how to inspect encrypted traffic, configure inspection modes, apply web filtering, manage applications, set antivirus modes, and implement IPS for security.

 

質問 # 45
Which three statements about security associations (SA) in IPsec are correct? (Choose three.)

  • A. A phase 1 SA is bidirectional, while a phase 2 SA is directional.
  • B. Phase 2 SAs are used for encrypting and decrypting the data exchanged through the tunnel.
  • C. Both the phase 1 SA and phase 2 SA are bidirectional.
  • D. Phase 2 SA expiration can be time-based, volume-based, or both.
  • E. An SA never expires.

正解:A、B、D

解説:
The correct statements about security associations (SA) in IPsec are:
A. Phase 2 SAs are used for encrypting and decrypting the data exchanged through the tunnel.
C. A phase 1 SA is bidirectional, while a phase 2 SA is directional.
D. Phase 2 SA expiration can be time-based, volume-based, or both. Here's an explanation for the correct statements:
A. Phase 2 SAs (Security Associations) are established for the purpose of encrypting and decrypting the actual data that is exchanged through the IPsec tunnel. Phase 1 SAs, on the other hand, are primarily responsible for setting up the initial secure connection.
C. A phase 1 SA is bidirectional, meaning it covers both directions of communication between two peers.
However, a phase 2 SA is directional, and separate SAs are established for inbound and outbound traffic.
D. Phase 2 SAs can have expiration based on time, volume (data transferred), or a combination of both.
This allows for better control and security management in IPsec implementations.


質問 # 46
Refer to the exhibit showing a debug flow output.

What two conclusions can you make from the debug flow output? (Choose two.)

  • A. The default route is required to receive a reply.
  • B. The debug flow is for ICMP traffic.
  • C. A firewall policy allowed the connection.
  • D. A new traffic session was created.

正解:B、D

解説:
A - The debug flow is for ICMP traffic.
B . A firewall policy allowed the connection.
C . A new traffic session was created.
D . The default route is required to receive a reply.
The debug flow is for ICMP traffic.
The output shows "proto=1," which indicates that the protocol is ICMP (Internet Control Message Protocol).
A new traffic session was created.
The message "allocate a new session-00003dd5" confirms that a new session was created for this traffic.


質問 # 47
When configuring a firewall virtual wire pair policy, which following statement is true?

  • A. Only a single virtual wire pair can be included in each policy.
  • B. Any number of virtual wire pairs can be included, as long as the policy traffic direction is the same.
  • C. Any number of virtual wire pairs can be included in each policy, regardless of the policy traffic direction settings.
  • D. Exactly two virtual wire pairs need to be included in each policy.

正解:C

解説:
Any number of virtual wire pairs can be included in each policy, regardless of the policy traffic direction settings.
We tested to create a policy. We can use any number of virtual wire pairs. We can select 3 options in traffic direction: in/out/both.
Firewall virtual wire pair policies can include more than a single virtual wire pair. This capability can streamline the policy management process by eliminating the need to create multiple, similar policies for each virtual wire pair. When creating or modifying a policy, you can select the traffic direction for each VWP included in the policy.


質問 # 48
Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.)

  • A. Checksums of devices will be different from each other because some configuration items are not synced to other HA members.
  • B. Checksums of devices are compared against each other to ensure configurations are the same.
  • C. Incremental configuration synchronization can occur only from changes made on the primary FortiGate device.
  • D. Incremental configuration synchronization can occur from changes made on any FortiGate device within the HA cluster

正解:B、C

解説:
In FortiGate HA (High Availability) configuration, checksums of device configurations are compared to ensure they are synchronized and identical across the cluster. Incremental synchronization can only happen from changes made on the primary device to ensure consistency and integrity across the cluster members.
Changes made on non-primary devices do not initiate synchronization.
References:
* FortiOS 7.4.1 Administration Guide: HA Configuration Synchronization


質問 # 49
Refer to the exhibit to view the firewall policy.

Why would the firewall policy not block a well-known virus, for example eicar?

  • A. The action on the firewall policy is not set to deny.
  • B. Web filter is not enabled on the firewall policy to complement the antivirus profile.
  • C. The firewall policy is not configured in proxy-based inspection mode.
  • D. The firewall policy does not apply deep content inspection.

正解:C

解説:
The firewall policy shown in the exhibit is configured in flow-based inspection mode. In flow-based inspection, certain security features, such as deep content inspection, might not be as effective as in proxy- based mode. Proxy-based inspection is necessary for thorough content inspection, which includes identifying and blocking well-known viruses like EICAR.
References:
* FortiOS 7.4.1 Administration Guide: Inspection Modes


質問 # 50
Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)

  • A. If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.
  • B. If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.
  • C. If SD-WAN is disabled, you configure the load balancing algorithm in config system settings.
  • D. If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP

正解:B、C

解説:
When SD-WAN is enabled on FortiGate, the load balancing algorithm for Equal-Cost Multi-Path (ECMP) is configured using the load-balance-mode parameter under SD-WAN settings. However, if SD-WAN is disabled, the ECMP load balancing algorithm can be configured under config system settings. This flexibility allows FortiGate to control traffic routing behavior based on the network configuration and requirements.
Reference:
FortiOS 7.4.1 Administration Guide: ECMP Configuration


質問 # 51
Refer to the exhibit.

Which contains a network diagram and routing table output. The Student is unable to access Webserver.
What is the cause of the problem and what is the solution for the problem?

  • A. The first reply packet for Student failed the RPF check. This issue can be resolved by adding a static route to 203.0.114.24/32 through port3.
  • B. The first packet sent from Student failed the RPF check. This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.
  • C. The first packet sent from Student failed the RPF check. This issue can be resolved by adding a static route to 203.0.114.24/32 through port3.
  • D. The first reply packet for Student failed the RPF check. This issue can be resolved by adding a static route to 10.0.4.0/24 through wan1.

正解:A

解説:
The first reply packet for Student failed the RPF check. This issue can be resolved by adding a static route to 203.0.114.24/32 through port3.
Option C is the correct answer based on the provided information, let's analyze it:
Option C states: "The first reply packet for Student failed the RPF check. This issue can be resolved by adding a static route to 203.0.114.24/32 through port3." The issue is related to the first reply packet from the Student failing the Reverse Path Forwarding (RPF) check and that adding a static route to 203.0.114.24/32 through "port3" will resolve the problem, then you can go ahead with this solution.
In a typical RPF check scenario, it ensures that the incoming packet is arriving on the expected interface based on the routing table. Adding a static route to 203.0.114.24/32 through "port3" may indeed resolve the RPF issue if the routing is misconfigured.
Option C is the correct solution based on your network setup and further analysis, you can proceed with implementing that static route to see if it resolves the issue. Additionally, it's a good practice to monitor the network to ensure that the problem is indeed resolved after making the change.


質問 # 52
Refer to the exhibit.

Which two statements are true about the routing entries in this database table? (Choose two.)

  • A. Both default routes have different administrative distances.
  • B. The default route on porc2 is marked as the standby route.
  • C. All of the entries in the routing database table are installed in the FortiGate routing table.
  • D. The port2 interface is marked as inactive.

正解:A、B

解説:
The routing table in the exhibit shows two default routes (0.0.0.0/0) with different administrative distances:
* The default route through port2 has an administrative distance of 20.
* The default route through port1 has an administrative distance of 10.
Administrative distance determines the priority of the route; a lower value is preferred. Here, the route through port1 with an administrative distance of 10 is the preferred route. The route through port2 with an administrative distance of 20 acts as a standby or backup route. If the primary route (port1) fails or is unavailable, traffic will then be routed through port2.
Regarding the statement that the port2 interface is marked as inactive, there is no indication in the routing table that port2 is inactive. Similarly, all the routes displayed are not necessarily installed in the FortiGate routing table, as the table could include both active and backup routes.
References:
* FortiOS 7.4.1 Administration Guide: Default route configuration
* FortiOS 7.4.1 Administration Guide: Routing table explanation


質問 # 53
Refer to the exhibits.



The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2.
The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver.
Which two configuration changes can the administrator make to the policy to deny Webserver access for Remote-User2? (Choose two.)

  • A. Disable match-vip in the Deny policy.
  • B. Set the Destination address as Deny_IP in the Allow_access policy.
  • C. Set the Destination address as Webserver in the Deny policy.
  • D. Enable match-vip in the Deny policy.

正解:C、D

解説:
To deny access to the web server for Remote-User2 while allowing Remote-User1 to access the same web server, two configuration changes can be made:
Enable match-vip in the Deny policy:
By enabling the match-vip option in the Deny policy, the FortiGate will check for virtual IP (VIP) objects during policy matching. This setting allows the firewall policy to correctly identify and block traffic directed to a specific mapped IP address, such as the web server, when using a VIP configuration.
Set the Destination address as Webserver in the Deny policy:
Setting the Destination address to "Webserver" in the Deny policy ensures that the policy specifically targets traffic attempting to reach the web server. This configuration helps to precisely control which traffic should be blocked, focusing the Deny policy on the intended destination.
Reference:
FortiOS 7.4.1 Administration Guide: Deny matching with a policy with a virtual IP applied FortiOS 7.4.1 Administration Guide: Configuring Policies with VIPs


質問 # 54
Refer to the exhibit.

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?

  • A. The Service DNS is required in the firewall policy.
  • B. The user is using an incorrect user name.
  • C. The Remote-users group is not added to the Destination.
  • D. No matching user account exists for this user.

正解:A

解説:
Firewall authentication generally requires the DNS service to be enabled in the firewall policy to correctly resolve hostnames during the authentication process. If DNS is not allowed in the firewall policy, the FortiGate cannot resolve external domains, and as a result, the user may not be presented with the login prompt when attempting to access an external website.
References:
* FortiOS 7.4.1 Administration Guide: Firewall Authentication Configuration


質問 # 55
An administrator wants to block https://www.example.com/videos and allow all other URLs on the website.
What are two configuration changes that the administrator can make to satisfy the requirement? (Choose two.)

  • A. Configure a static URL filter entry for the URL and select Block as the action
  • B. Enable full SSL inspection
  • C. Configure a video filter profile to block the URL
  • D. Configure web override for the URL and select a blocked FortiGuard subcategory

正解:A、B

解説:
If the goal is to block the specific URL https://www.example.com/videos and allow all other URLs on the website, the correct configuration changes are:
B. Enable full SSL inspection.
Enabling full SSL inspection allows the FortiGate to inspect and filter HTTPS traffic, including the specific URL https://www.example.com/videos.
D. Configure a static URL filter entry for the URL and select Block as the action.
Create a static URL filter entry for the specific URL https://www.example.com/videos and set the action to Block. This will block access to the specified URL.
Enabling full SSL inspection is necessary to inspect and filter HTTPS traffic effectively, including the specific URL within the encrypted traffic.
So, the correct choices are B and D.


質問 # 56
Refer to the exhibit.


The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?

  • A. 10.200.1.49
  • B. 10.200.1.1
  • C. 10.200.1.149
  • D. 10.200.1.99

正解:D

解説:
It's D because of the protocol number.
Ping is ICMP protocol - protocol number = 1
=> SNAT policy ID 1 is policy that used.
=> Translated address is "SNAT-Remote1" that 10.200.1.99


質問 # 57
Which of the following statements is true regarding SSL VPN settings for an SSL VPN portal?

  • A. By default, split tunneling is enabled.
  • B. By default, the admin GUI and SSL VPN portal use the same HTTPS port.
  • C. By default, the SSL VPN portal requires the installation of a client's certificate.
  • D. By default, FortiGate uses WINS servers to resolve names.

正解:A

解説:
There is a Trap here... C and D have something right but the trick is the question...
Under SSL VPN settings you can see that port is 443 (same of https admin port) BUT the question is about a SSL VPN Setting FOR A VPN PORTAL... so if you go to SSL VPN Portals and hit "Create new" you will see Tunnel Mode and Split Tunnel enabled by default... so, the correct answer is C.
Split tunneling is a feature that allows a remote VPN user to tunnel only specific, protected traffic back to the corporate network, while other traffic (e.g., internet traffic) is sent directly to its destination. This can help optimize bandwidth usage and reduce the load on the corporate network.
In the context of SSL VPN settings for an SSL VPN portal on FortiGate, if split tunneling is enabled by default, it means that the remote user's internet-bound traffic will not be forced through the corporate network but will be sent directly to the internet. This can improve performance and reduce latency for non-corporate internet traffic.
Extra explanation:
https://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-
sslvpn/SSLVPN_Examples/Split_Tunnel.htm#:~:text=Split%20Tunnel,SSL%20VPN%20on%20FortiGate
%20units.


質問 # 58
Refer to the exhibit.

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.
An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)

  • A. Configure a static URL filter entry for download, com with Type and Action set to Wildcard and Block, respectively.
  • B. Set the Freeware and Software Downloads category Action to Warning
  • C. Configure a web override rating for download, com and select Malicious Websites as the subcategory.
  • D. Configure a separate firewall policy with action Deny and an FQDN address object for *. download, com as destination address.

正解:A、D

解説:
To block access specifically to download.com while allowing other sites in the "Freeware and Software Downloads" category, you can create a separate firewall policy with a deny action specifically for the FQDN
*.download.com. This approach allows blocking this particular site without affecting the other sites in the same category. Alternatively, configuring a static URL filter entry with the type set to Wildcard and action set to Block will also achieve the desired effect by directly blocking the specific URL without impacting other sites in the category.
References:
* FortiOS 7.4.1 Administration Guide: URL filter configuration


質問 # 59
An administrator configured a FortiGate to act as a collector for agentless polling mode.
What must the administrator add to the FortiGate device to retrieve AD user group information?

  • A. DHCP server
  • B. Windows server
  • C. RADIUS server
  • D. LDAP server

正解:B


質問 # 60
Which are two benefits of using SD-WAN? (Choose two.)

  • A. FortiGate performs per-packet distribution across multiple SD-WAN members.
  • B. WAN is used effectively.
  • C. Application steering is available.
  • D. Firewall policies are not required.

正解:B、C

解説:
The two benefits of using SD-WAN are:
B. WAN is used effectively.
SD-WAN optimizes the utilization of Wide Area Network (WAN) resources, improving efficiency and performance in the network.
C. Application steering is available.
SD-WAN provides the capability to steer and prioritize traffic based on the specific applications, ensuring better application performance and user experience.
The other options are not accurate:
A is incorrect because FortiGate typically performs per-session, not per-packet, distribution across multiple SD-WAN members.
D is incorrect because firewall policies may still be required, especially for security and traffic control purposes.
So, the correct choices are B and C.


質問 # 61
Refer to the exhibit.

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.
What is the most likely reason for this situation?

  • A. The Remote-users group is not added to the Destination.
  • B. No matching user account exists for this user.
  • C. The user is using an incorrect user name.
  • D. The Service DNS is required in the firewall policy.

正解:C


質問 # 62
Refer to the exhibit.

Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit.
What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. The signature setting includes a group of other signatures.
  • B. Traffic matching the signature will be silently dropped and logged.
  • C. The signature setting uses a custom rating threshold.
  • D. Traffic matching the signature will be allowed and logged.

正解:D

解説:
The exhibit shows that the "FTP.Login.Failed" IPS signature is set with the action "Pass" and packet logging enabled. This means that any traffic matching this signature will be allowed through the FortiGate, and the traffic details will be logged for monitoring and analysis purposes.
References:
* FortiOS 7.4.1 Administration Guide: IPS Signature Actions


質問 # 63
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile.
Which order must FortiGate use when the web filter profile has features such as safe search enabled?

  • A. Static URL filter, FortiGuard categoryfilter, and advanced filters
  • B. Static domain filter, SSL inspection filter, and external connectors filters
  • C. FortiGuard category filter and ratingfilter
  • D. DNS-based web filter and proxy-based web filter

正解:A


質問 # 64
Refer to the exhibit.

A user located behind the FortiGate device is trying to go to http://www.addictinggames.com (Addicting.Games). The exhibit shows the application detains and application control profile.
Based on this configuration, which statement is true?

  • A. Addicting.Games will be blocked, based on the Filter Overrides configuration.
  • B. Addicting.Games will be allowed, based on the Categories configuration.
  • C. Addicting.Games will be allowed, based on the Application Overrides configuration.
  • D. Addicting.Games will be allowed only if the Filter Overrides action is set to Learn.

正解:C

解説:
Addicting.Games will be allowed, based on the Application Overrides configuration.
Based on the Scan order. Application and Filter overrides>>Category.
Application and Filter overrides follows the same rules as firewall policy. Application override will be considered first.


質問 # 65
Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)

  • A. The client FortiGate requires a manually added route to remote subnets.
  • B. The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
  • C. The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
  • D. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.

正解:B、C

解説:
For SSL VPN to function correctly between two FortiGate devices, the following settings are required:
* B. The server FortiGate requires a CA certificate to verify the client FortiGate certificate: The server FortiGate must have a Certificate Authority (CA) certificate installed to authenticate and verify the certificate presented by the client FortiGate device.
* C. The client FortiGate requires a client certificate signed by the CA on the server FortiGate: The client FortiGate must have a client certificate that is signed by the same CA that the server FortiGate uses for verification. This ensures a secure SSL VPN connection between the two devices.
The other options are not directly necessary for establishing SSL VPN:
* A. The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN: This is incorrect as SSL VPN does not require a specific tunnel interface type; it typically uses an SSL VPN client profile.
* D. The client FortiGate requires a manually added route to remote subnets: While routing may be necessary, it is not specifically required for the SSL VPN functionality between two FortiGates.
References
* FortiOS 7.4.1 Administration Guide - Configuring SSL VPN, page 1203.
* FortiOS 7.4.1 Administration Guide - SSL VPN Authentication, page 1210.


質問 # 66
Refer to the exhibits.
Exhibit A.

Exhibit B.

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?

  • A. Change the csf setting on ISFW (downstream) to set fabric-object-unification default.
  • B. Change the csf setting on Local-FortiGate (root) to set configuration-sync local.
  • C. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
  • D. Change the csf setting on ISFW (downstream) to set configuration-sync local.

正解:C

解説:
Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
The CLI command set fabric-object-unification is only available on the root FortiGate. When set to local, global objects will not be synchronized to downstream devices in the Security Fabric. The default value is default.
Option A will not synchronise global fabric objects downstream.


質問 # 67
......

2025年最新の実際にある検証済みのFCP_FGT_AD-7.4問題集:https://www.passtest.jp/Fortinet/FCP_FGT_AD-7.4-shiken.html

必ず合格できるFortinet FCP_FGT_AD-7.4試験で正確な90問題と解答あります:https://drive.google.com/open?id=1Y-jz4V5k-tqboJo1CVKCR0RfdX6uyf3I