Fortinet FCSS_EFW_AD-7.4 Practice Exams
Last updated on Oct 01,2026- Exam Code: FCSS_EFW_AD-7.4
- Exam Name: FCSS - Enterprise Firewall 7.4 Administrator
- Certification Provider: Fortinet
- Latest update: Oct 01,2026
Examine the partial output from the IKE real time debug shown in the exhibit; then answer the question below.


Why didn’t the tunnel come up?
- A . IKE mode configuration is not enabled in the remote IPsec gateway.
- B . The remote gateway’s Phase-2 configuration does not match the local gateway’s phase-2 configuration.
- C . The remote gateway’s Phase-1 configuration does not match the local gateway’s phase-1 configuration.
- D . One IPsec gateway is using main mode, while the other IPsec gateway is using aggressive mode.
Refer to the exhibit, which shows a network diagram.

An administrator would like to modify the MED value advertised from FortiGate_1 to a BGP neighbor in the autonomous system 30.
What must the administrator configure on FortiGate_1 to implement this?
- A . route-map-out
- B . network-import-check
- C . prefix-list-out
- D . distribute-list-out
A
Explanation:
TheMulti-Exit Discriminator (MED)is aBGP attributeused to influence the preferred path for incoming traffic from an external autonomous system (AS). The diagram shows that FortiGate_1 advertisesMED 200, while FortiGate_2 advertisesMED 300, meaningthe ISP will prefer the route through FortiGate_1because alower MED is preferredin BGP.
To modify theMED valueon FortiGate_1 for routes advertised to AS 30, the administrator must configure a route-map-out. A route map canmatch specific routesandset the MED valuebefore sending them to the BGP neighbor.
An administrator applied a block-all IPS profile for client and server targets to secure the server, but the database team reported the application stopped working immediately after.
How can an administrator apply IPS in a way that ensures it does not disrupt existing applications in the network?
- A . Use an IPS profile with all signatures in monitor mode and verify patterns before blocking.
- B . Limit the IPS profile to server targets only to avoid blocking connections from the server to clients.
- C . Select flow mode in the IPS profile to accurately analyze application patterns.
- D . Set the IPS profile signature action to default to discard all possible false positives.
A
Explanation:
Applying anaggressive IPS profilewithout prior testing candisrupt legitimate applicationsby incorrectly identifying normal traffic as malicious.
To prevent disruptions while still monitoring for threats:
#Enable IPS in "Monitor Mode" first:
# This allows FortiGate tolog and analyzepotential threatswithout actively blockingtraffic.
# Administrators can review logs and fine-tune IPS signatures to minimize false positives before switching to blocking mode.
#Verify and adjust signature patterns:
# Some signatures might trigger unnecessary blocks for legitimate application traffic.
# By analyzing logs, administrators candisable or modifyspecific rules causing false positives.
An administrator is running the following sniffer in a FortiGate:
diagnose sniffer packet any “host 10.0.2.10” 2
What information is included in the output of the sniffer? (Choose two.)
- A . Ethernet headers.
- B . IP payload.
- C . IP headers.
- D . Port names.
Refer to the exhibits.


The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown.
When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the Admin SSO credentials.
What is the next status for the user?
- A . The user is prompted to create an SSO administrator account for AdminSSO.
- B . The user receives an authentication failure message.
- C . The user accesses the downstream FortiGate with super_admin_readonly privileges.
- D . The user accesses the downstream FortiGate with super_admin privileges.
C
Explanation:
From theRoot FortiGate – System Administrator Configurationexhibit:
# TheAdminSSOaccount has thesuper_admin_readonlyrole.
From theDownstream FortiGate – Security Fabric Settingsexhibit:
# TheSecurity Fabric roleis set toJoin Existing Fabric, meaning it will authenticate with the root FortiGate.
#SAML Single Sign-On (SSO) is enabled, and thedefault admin profileis set tosuper_admin_readonly.
When theAdminSSOuser logs into the downstream FortiGate usingSSO, the authentication request is sent to the root FortiGate, where AdminSSO hassuper_admin_readonlypermissions. Since the downstream FortiGate inherits this permission through the Security Fabric configuration, the user will be granted super_admin_readonlyaccess.
Which statement about protocol options is true?
- A . Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.
- B . Protocol options allows administrators the ability to configure the Any setting for all enabled protocols which provides the most efficient use of system resources.
- C . Protocol options allows administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.
- D . Protocol options allows administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.
An administrator has enabled HA session synchronization in a HA cluster with two members.
Which flag is added to a primary unit’s session to indicate that it has been synchronized to the secondary unit?
- A . redir.
- B . dirty.
- C . synced
- D . nds.
An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23: ff:fc:00:86.
What two conclusions can the administrator draw? (Choose two.)
- A . The suspicious packet is related to a cluster that has VDOMs enabled.
- B . The network includes FortiGate devices configured with the FGSP protocol.
- C . The suspicious packet is related to a cluster with a group-id value lower than 255.
- D . The suspicious packet corresponds to port 7 on a FortiGate device.
A C
Explanation:
The MAC addresse0:23:ff:fc:00:86follows the format used inFortiGate High Availability (HA) clusters. When FortiGate devices are in an HA configuration, they usevirtual MAC addresses for failover and redundancy purposes.
The suspicious packet is related to a cluster that has VDOMs enabled:FortiGate devices withVirtual Domains (VDOMs)enabled use specific MAC address ranges to differentiate HA-related traffic. This MAC address is likely part of that mechanism.
The suspicious packet is related to a cluster with a group-id value lower than 255: FortiGate HA clusters assign virtual MAC addresses based on the group ID. The last octet (00:86) corresponds to agroup IDthat is below 255, confirming this option.
View the exhibit, which contains the sniffer output for a passive mode FTP request, and then answer the question below.

An administrator has created the following custom IPS signature to block all FTP requests for passive mode:
F-SBID (–attack_id 1002; –name "Block.FTP "; –protocol tcp; –flow from_client; –pattern "PASV"; –no_case;)
Soon after the signature is enabled in an active IPS sensor, some false positive detections are generated.
Which of the following option and value pairs will allow more specific detection?
- A . –attack_id 1001
- B . –protocol ftp
- C . –name "Block.FTP.PASV
- D . –service ftp
In which two ways does FortiManager function when it is deployed as a local FDS? (Choose two.)
- A . It provides VM license validation services.
- B . It supports rating requests from non-FortiGate devices.
- C . It caches available firmware updates for unmanaged devices.
- D . It can be configured as an update server, a rating server, or both.