Free FCSS_EFW_AD-7-6 Practice Test Questions and Answers (2026)
Q: 1
How will configuring set tcp-mss-sender and set tcp-mss-receiver in a firewall policy affect the size
and handling of TCP packets in the network?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Refer to the exhibit.
A pre-run CLI template that is used in zero-touch provisioning (ZTP) and low-touch provisioning (LTP)
with FortiManager is shown.
The template is not assigned even though the configuration has already been installed on FortiGate.
What is true about this scenario?
The template is not assigned even though the configuration has already been installed on FortiGate.
What is true about this scenario?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Refer to the exhibit, which shows an ADVPN network
An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with
2.
What two options must the administrator configure in BGP? (Choose two.)
An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with
2.
What two options must the administrator configure in BGP? (Choose two.)Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Refer to the exhibit, which contains a partial command output.
The administrator has configured BGP on FortiGate. The status of this new BGP configuration is
shown in the exhibit.
What configuration must the administrator consider next?
The administrator has configured BGP on FortiGate. The status of this new BGP configuration is
shown in the exhibit.
What configuration must the administrator consider next?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
An administrator is checking an enterprise network and sees a suspicious packet with the MAC
address e0:23:ff:fc:00:86.
What two conclusions can the administrator draw? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
An administrator must minimize CPU and RAM use on a FortiGate firewall while also enabling
essential security features, such as web filtering and application control for HTTPS traffic.
Which SSL inspection setting helps reduce system load while also enabling security features, such as
web filtering and application control for encrypted HTTPS traffic?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Refer to the exhibit.
An administrator is deploying a hub and spokes network and using OSPF as dynamic protocol.
Which configuration is mandatory for neighbor adjacency?
An administrator is deploying a hub and spokes network and using OSPF as dynamic protocol.
Which configuration is mandatory for neighbor adjacency?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
An administrator must standardize the deployment of FortiGate devices across branches with
consistent interface roles and policy packages using FortiManager.
What is the recommended best practice for interface assignment in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
An administrator needs to install an IPS profile without triggering false positives that can impact
applications and cause problems with the user's normal traffic flow.
Which action can the administrator take to prevent false positives on IPS analysis?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Refer to the exhibit, which shows a network diagram.
An administrator would like to modify the MED value advertised from FortiGate_1 to a BGP neighbor
in the autonomous system 30.
What must the administrator configure on FortiGate_1 to implement this?
An administrator would like to modify the MED value advertised from FortiGate_1 to a BGP neighbor
in the autonomous system 30.
What must the administrator configure on FortiGate_1 to implement this?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on
network transmission patterns and application signatures?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Refer to the exhibit, which contains the partial output of an OSPF command.
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in
the exhibit.
What two conclusions can the administrator draw? (Choose two.)
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in
the exhibit.
What two conclusions can the administrator draw? (Choose two.)Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Why does the ISDB block layers 3 and 4 of the OSI model when applying content filtering? (Choose
two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Refer to the exhibit, which shows an enterprise network connected to an internet service provider.
An administrator must configure a loopback as a BGP source to connect to the ISP.
Which two commands are required to establish the connection? (Choose two.)
An administrator must configure a loopback as a BGP source to connect to the ISP.
Which two commands are required to establish the connection? (Choose two.)Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20
What two conclusions can you draw from the corresponding LAN interface? (Choose two.)