Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable
equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?Free FCSS_EFW_AD-7.4 Practice Test Questions and Answers (2026)
Last Update Check
Q: 1
Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an
overlapping network segment to the existing VPN IPsec connection between the hub and site 1.
Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable
equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?
Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable
equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Refer to the exhibit, which shows a partial troubleshooting command output.
An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to
the output shown in the exhibit.
What can the administrator conclude?
An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to
the output shown in the exhibit.
What can the administrator conclude?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
An administrator is setting up an ADVPN configuration and wants to ensure that peer IDs are not
exposed during VPN establishment.
Which protocol can the administrator use to enhance security?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
An administrator must standardize the deployment of FortiGate devices across branches with
consistent interface roles and policy packages using FortiManager.
What is the recommended best practice for interface assignment in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Refer to the exhibit, which contains a partial command output.
The administrator has configured BGP on FortiGate. The status of this new BGP configuration is
shown in the exhibit.
What configuration must the administrator consider next?
The administrator has configured BGP on FortiGate. The status of this new BGP configuration is
shown in the exhibit.
What configuration must the administrator consider next?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A company's guest internet policy, operating in proxy mode, blocks access to Artificial Intelligence
Technology sites using FortiGuard. However, a guest user accessed a page in this category using port
8443.
Which configuration changes are required for FortiGate to analyze HTTPS traffic on nonstandard
ports like 8443 when full SSL inspection is active in the guest policy?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Refer to the exhibit, which shows a corporate network and a new remote office network.
An administrator must integrate the new remote office network with the corporate enterprise
network.
What must the administrator do to allow routing between the two networks?
An administrator must integrate the new remote office network with the corporate enterprise
network.
What must the administrator do to allow routing between the two networks?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
An administrator needs to install an IPS profile without triggering false positives that can impact
applications and cause problems with the user's normal traffic flow.
Which action can the administrator take to prevent false positives on IPS analysis?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A company's users on an IPsec VPN between FortiGate A and B have experienced intermittent issues
since implementing VXLAN. The administrator suspects that packets exceeding the 1500-byte default
MTU are causing the problems.
In which situation would adjusting the interface’s maximum MTU value help resolve issues caused by
protocols that add extra headers to IP packets?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Refer to the exhibit, which shows an enterprise network connected to an internet service provider.
The administrator must configure the BGP section of FortiGate A to give internet access to the
enterprise network.
Which command must the administrator use to establish a connection with the internet service
provider?
The administrator must configure the BGP section of FortiGate A to give internet access to the
enterprise network.
Which command must the administrator use to establish a connection with the internet service
provider?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
The IT department discovered during the last network migration that all zero phase selectors in
phase 2 IPsec configurations impacted network operations.
What are two valid approaches to prevent this during future migrations? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Refer to the exhibit, which shows a revision history window in the FortiManager device layer.
The IT team is trying to identify the administrator responsible for the most recent update in the
FortiGate device database.
Which conclusion can you draw about this scenario?
The IT team is trying to identify the administrator responsible for the most recent update in the
FortiGate device database.
Which conclusion can you draw about this scenario?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
An administrator received a FortiAnalyzer alert that a 1 ТВ disk filled up in a day. Upon investigation,
they found thousands of unusual DNS log requests, such as JHCMQK.website.com, with no answers.
They later discovered that DNS exfiltration was occurring through both UDP and TLS.
How can the administrator prevent this data theft technique?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Refer to the exhibit, which contains the partial output of an OSPF command.
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in
the exhibit.
What two conclusions can the administrator draw? (Choose two.)
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in
the exhibit.
What two conclusions can the administrator draw? (Choose two.)Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
An administrator applied a block-all IPS profile for client and server targets to secure the server, but
the database team reported the application stopped working immediately after.
How can an administrator apply IPS in a way that ensures it does not disrupt existing applications in
the network?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20