Pre-Summer Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

FCSS_EFW_AD-7.6 Fortinet NSE 7 - Enterprise Firewall 7.6 Administrator Questions and Answers

Questions 4

Refer to the exhibit, which shows a partial troubleshooting command output.

An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit.

What can the administrator conclude?

Options:

A.

IPsec SAs cannot be offloaded.

B.

The two IPsec SAs, inbound and outbound, are copied to the NPU.

C.

Only the outbound IPsec SA is copied to the NPU.

D.

Only the inbound IPsec SA is copied to the NPU.

Buy Now
Questions 5

What does the command set forward-domain < domain_ID > in a transparent VDOM interface do?

Options:

A.

It configures the interface to prioritize traffic based on the domain ID, enhancing quality of service for specified VLANs.

B.

It isolates traffic within a specific VLAN by assigning a broadcast domain to an interface based on the VLAN ID.

C.

It restricts the interface to managing traffic only from the specified VLAN, effectively segregating network traffic.

D.

It assigns a unique domain ID to the interface, allowing it to operate across multiple VLANs within the same VDOM.

Buy Now
Questions 6

The IT department discovered during the last network migration that all zero phase selectors in phase 2 IPsec configurations impacted network operations.

What are two valid approaches to prevent this during future migrations? (Choose two.)

Options:

A.

Use routing protocols to specify allowed subnets over the tunnel.

B.

Configure an IPsec-aggregate to create redundancy between each firewall peer.

C.

Clearly indicate to the VPN which segments will be encrypted in the phase two selectors.

D.

Configure an IP address on the IPsec interface of each firewall to establish unique peer connections and avoid impacting network operations.

Buy Now
Questions 7

Which hardware improves VXLAN performance?

Options:

A.

CPU

B.

NTurbo

C.

CP10

D.

NPU7

Buy Now
Questions 8

To secure your enterprise network traffic, which step does FortiGate perform first, when handling the first packets of a session? (Choose one answer)

Options:

A.

Installation of the session key in the network processor (NP)

B.

Decryption

C.

A reverse path forwarding (RPF) check

D.

IP integrity header checking

Buy Now
Questions 9

What is the effect of configuring tcp-mss-sender and tcp-mss-receiver?

Options:

A.

Header change

B.

Largest payload

C.

Allow/Deny

D.

Fragment only

Buy Now
Questions 10

Which two statements about IKEv2 are true if an administrator decides to implement IKEv2 in the VPN topology? (Choose two.)

Options:

A.

It includes stronger Diffie-Hellman (DH) groups, such as Elliptic Curve (ECP) groups.

B.

It supports interoperability with devices using IKEv1.

C.

It exchanges a minimum of two messages to establish a secure tunnel.

D.

It supports the extensible authentication protocol (EAP).

Buy Now
Questions 11

A user reports that their computer was infected with malware after accessing a secured HTTPS website. However, when you check the FortiGate logs, you see that FortiGate did not detect the website as insecure, despite having an SSL certificate and the correct profiles applied on the policy.

How can you ensure that FortiGate can analyze encrypted HTTPS traffic on a website?

Options:

A.

Enable full SSL inspection in the SSL/SSH inspection profile to decrypt packets

B.

Set min-allowed-ssl-version to tls-1.2.

C.

Enable server certificate SNI check to protect against unsecured HTTPS websites.

D.

Set inspection-mode to proxy.

Buy Now
Questions 12

Refer to the exhibit, which shows an enterprise network connected to an internet service provider.

The administrator must configure the BGP section of FortiGate A to give internet access to the enterprise network.

Which command must the administrator use to establish a connection with the internet service provider?

Options:

A.

config neighbor

B.

config redistribute bgp

C.

config router route-map

D.

config redistribute ospf

Buy Now
Questions 13

Based on the TLS handshake shown, what can be inferred about the client?

Options:

A.

Supports TLS 1.0 only

B.

Supports TLS 1.2 and TLS 1.3

C.

Supports SSLv3

D.

Supports DTLS

Buy Now
Questions 14

How can FortiGate analyze HTTPS traffic on non-standard port 8443?

Options:

A.

Proxy mode

B.

TLS 1.2

C.

Add 443 and 8443 mapping

D.

Enable IPS

Buy Now
Questions 15

Refer to the exhibits.

The firewall policy ID 1 of the DCFW policy package and the reinstall preview window for the DCFW policy package installation are shown.

Why is FortiManager installing set srcaddr " SSLVPN_tunnel_addr1 " on firewall policy ID 1 when the policy package DCFW has the source address 10.0.5 on the firewall policy ID 1?

Options:

A.

The reinstall policy package ignores recent changes to the policy layer. The administrator must run the Install Wizard.

B.

FortiManager is installing the global policy package, which has higher priority than the ADOM policy package.

C.

FortiManager has assigned firewall HQ-DCFW a CLI template that can overwrite configurations at the policy layer.

D.

The firewall policy and reinstall preview use the same addresses, but they have different names because of per-device mapping.

Buy Now
Questions 16

Refer to the exhibit.

FCSS_EFW_AD-7.6 Question 16

The partial output of an OSPF command is shown. You are checking the OSPF status of a FortiGate device when you receive the output shown in the exhibit. Based on the output, which two statements about FortiGate are correct? (Choose two answers)

Options:

A.

FortiGate is a backup designated router.

B.

FortiGate supports OSPF ECMP.

C.

FortiGate is in the area 0.0.0.5.

D.

FortiGate can inject external routing information.

Buy Now
Questions 17

Refer to the exhibit, which shows an ADVPN network.

FCSS_EFW_AD-7.6 Question 17

The client behind Spoke-1 generates traffic to the device located behind Spoke-2.

What is the first message that the hub sends to Spoke-1 to bring up the dynamic tunnel?

Options:

A.

Shortcut query

B.

Shortcut offer

C.

Shortcut reply

D.

Shortcut forward

Buy Now
Questions 18

Refer to the exhibit.

A physical topology along with a traffic log is shown. You are using FortiAnalyzer to monitor traffic from the device with IP address 10.0.2.51, which is located behind the FortiGate internal segmentation firewall (ISFW) device. Unified threat management (UTM) is not enabled in the firewall policy on the HQ-ISFW device, and you are surprised to see a log with the action Malware, as shown in the exhibit. What are two reasons why FortiAnalyzer would display this log? (Choose two answers)

Options:

A.

HQ-ISFW is not connected to FortiAnalyzer and traffic must go through HQ-NGFW-1.

B.

UTM is enabled in the firewall policy in HQ-NGFW-1.

C.

HQ-ISFW is in a Security Fabric environment.

D.

Security rating is enabled in HQ-ISFW.

Buy Now
Questions 19

A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server.

What can the firewall administrator do to block all outdated SSL/TLS versions on any HTTPS web server to prevent possible attacks on user traffic?

Options:

A.

Configure the unsupported SSL version and set the minimum allowed SSL version in the HTTPS settings of the SSL/SSH inspection profile.

B.

Enable auto-detection of outdated SSL/TLS versions in the SSL/SSH inspection profile to block vulnerable websites.

C.

Install the required certificate in the client ' s browser or use Active Directory policies to block specific websites as defined in the SSL/SSH inspection profile.

D.

Use the latest certificate, Fortinet_SSL_ECDSA256, and replace the CA certificate in the SSL/SSH inspection profile.

Buy Now
Questions 20

Which two approaches facilitate efficient ADVPN deployment?

Options:

A.

VPN Manager enable

B.

Best link only

C.

Loopback

D.

IPsec templates

Buy Now
Questions 21

An administrator is extensively using VXLAN on FortiGate.

Which specialized acceleration hardware does FortiGate need to improve its performance?

Options:

A.

NP7

B.

SP5

C.

СР9

D.

NTurbo

Buy Now
Questions 22

Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and site 1.

FCSS_EFW_AD-7.6 Question 22

Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?

Options:

A.

Set route-overlap to either use-new or use-old

B.

Set net-device to ecmp

C.

Set single-source to enable

D.

Set route-overlap to allow

Buy Now
Questions 23

How does configuring tcp-mss-sender and tcp-mss-receiver affect TCP packets?

Options:

A.

Header

B.

Payload

C.

Allow

D.

Fragment

Buy Now
Questions 24

Refer to the exhibits.

FCSS_EFW_AD-7.6 Question 24

FCSS_EFW_AD-7.6 Question 24

The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown.

When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials.

What is the next status for the user?

Options:

A.

The user is prompted to create an SSO administrator account for AdminSSO.

B.

The user receives an authentication failure message.

C.

The user accesses the downstream FortiGate with super_admin_readonly privileges.

D.

The user accesses the downstream FortiGate with super_admin privileges.

Buy Now
Questions 25

What can be inferred from the OSPF status output shown?

Options:

A.

Is ASBR

B.

Is BDR

C.

Supports ECMP

D.

Is in area 0.0.0.5

Buy Now
Questions 26

Refer to the exhibit, which shows a hub and spokes deployment.

FCSS_EFW_AD-7.6 Question 26

An administrator is deploying several spokes, including the BGP configuration for the spokes to connect to the hub.

Which two commands allow the administrator to minimize the configuration? (Choose two.)

Options:

A.

neighbor-group

B.

route-reflector-client

C.

neighbor-range

D.

ibgp-enforce-multihop

Buy Now
Questions 27

Refer to the exhibit.

An HA configuration of an active-active (A-A) cluster with the same HA uptime is shown. You want HQ-NGFW-2 to handle the Core2 VDOM traffic. Which modification must you make to achieve this outcome? (Choose one answer)

Options:

A.

Reboot HQ-NGFW-2.

B.

Change the priority from 100 to 160 for HQ-NGFW-2.

C.

Change the priority from 120 to 200 for HQ-NGFW-2.

D.

Enable override in virtual cluster 2 for HQ-NGFW-2.

Buy Now
Questions 28

An administrator is designing an ADVPN network for a large enterprise with spokes that have varying numbers of internet links. They want to avoid a high number of routes and peer connections at the hub.

Which method should be used to simplify routing and peer management?

Options:

A.

Deploy a full-mesh VPN topology to eliminate hub dependency.

B.

Implement static routing over IPsec interfaces for each spoke.

C.

Use a dynamic routing protocol using loopback interfaces to streamline peers and routes.

D.

Establish a traditional hub-and-spoke VPN topology with policy routes.

Buy Now
Questions 29

Refer to the exhibit, which shows the FortiGuard Distribution Network of a FortiGate device.

FortiGuard Distribution Network on FortiGate

FCSS_EFW_AD-7.6 Question 29

An administrator is trying to find the web filter database signature on FortiGate to resolve issues with websites not being filtered correctly in a flow-mode web filter profile.

Why is the web filter database version not visible on the GUI, such as with IPS definitions?

Options:

A.

The web filter database is stored locally, but the administrator must run over CLI diagnose autoupdate versions.

B.

The web filter database is stored locally on FortiGate, but it is hidden behind the GUI. It requires enabling debug mode to make it visible.

C.

The web filter database is not hosted on FortiGate: FortiGate queries FortiGuard or FortiManager for web filter ratings on demand.

D.

The web filter database is only accessible after manual syncing with a valid FDS server using diagnose test update info.

Buy Now
Questions 30

Refer to the exhibit, which shows a partial enterprise network.

FCSS_EFW_AD-7.6 Question 30

An administrator would like the area 0.0.0.0 to detect the external network.

What must the administrator configure?

Options:

A.

Enable RIP redistribution on FortiGate B.

B.

Configure a distribute-route-map-in on FortiGate B.

C.

Configure a virtual link between FortiGate A and B.

D.

Set the area 0.0.0.l type to stub on FortiGate A and B.

Buy Now
Questions 31

Why is the web filter database version not shown in the FortiGuard Security Services dashboard?

Options:

A.

The database failed to update

B.

The web filter database is cloud hosted

C.

Flow mode disables the database

D.

FortiGate does not support web filtering

Buy Now
Questions 32

Refer to the exhibit.

An administrator is deploying a hub and spokes network and using OSPF as dynamic protocol.

Which configuration is mandatory for neighbor adjacency?

Options:

A.

Set bfd enable in the router configuration

B.

Set network-type point-to-multipoint in the hub interface

C.

Set rfc1583-compatible enable in the router configuration

D.

Set virtual-link enable in the hub interface

Buy Now
Questions 33

How should you adjust MTU values to resolve encapsulation issues?

Options:

A.

All interfaces

B.

Wired only

C.

FortiGate only

D.

Controlled environment

Buy Now
Exam Code: FCSS_EFW_AD-7.6
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.6 Administrator
Last Update: Apr 18, 2026
Questions: 113

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now FCSS_EFW_AD-7.6 testing engine

PDF (Q&A)

$31.5  $104.99
buy now FCSS_EFW_AD-7.6 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 18 Apr 2026