Fortinet FCP_FGT_AD-7.6 Exam (page: 1)
Fortinet FCP - FortiGate 7.6 Administrator
Updated on: 19-Feb-2026

Viewing Page 1 of 12

An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic.

Which DPD mode on FortiGate meets this requirement?

  1. Enabled
  2. On Idle
  3. Disabled
  4. On Demand

Answer(s): B

Explanation:

The "On Idle" DPD mode configures FortiGate to send DPD probes only when no inbound traffic is detected, meeting the requirement to send probes only when the tunnel is idle.



Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)

  1. If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.
  2. If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.
  3. If SD-WAN is disabled, you configure the load balancing algorithm in config system settings.
  4. If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.

Answer(s): A,D

Explanation:

When SD-WAN is disabled, FortiGate supports volume-based ECMP mode via the v4-ecmp-mode parameter.
When SD-WAN is enabled, the load balancing algorithm is controlled by the load-balance-mode parameter within the SD-WAN configuration.



You have created a web filter profile named restrict_media-profile with a daily category usage quota.

When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down.

What could be the reason?

  1. The firewall policy is in no-inspection mode instead of deep-inspection.
  2. The inspection mode in the firewall policy is not matching with web filter profile feature set.
  3. The web filter profile is already referenced in another firewall policy.
  4. The naming convention used in the web filter profile is restricting it in the firewall policy.

Answer(s): B

Explanation:

Web filter profiles with category usage quotas require the firewall policy to be in proxy-based (deep) inspection mode; if the inspection mode does not match this requirement, the profile will not appear in the drop-down list.



Refer to the exhibit.



As an administrator you have created an IPS profile, but it is not performing as expected.
While testing you got the output as shown in the exhibit.

What could be the possible reason of the diagnose output shown in the exhibit?

  1. There is a no firewall policy configured with an IPS security profile.
  2. FortiGate entered into IPS fail open state.
  3. Administrator entered the command diagnose test application ipsmonitor 5.
  4. Administrator entered the command diagnose test application ipsmonitor 99.

Answer(s): A

Explanation:

The output shows the IPS engine count as 0, indicating no active IPS engines are running. This typically means no firewall policy is referencing the IPS security profile, so the IPS profile is not being applied or triggered.



Refer to the exhibit.



The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL

inspection, as shown in the exhibit.

For which two reasons are these web categories exempted? (Choose two.)

  1. The FortiGate temporary certificate denies the browser's access to websites that use HTTP Strict Transport Security.
  2. These websites are in an allowlist of reputable domain names maintained by FortiGuard.
  3. The resources utilization is optimized because these websites are in the trusted domain list on FortiGate.
  4. The legal regulation aims to prioritize user privacy and protect sensitive information for these websites.

Answer(s): A,D

Explanation:

FortiGate's temporary SSL certificate may cause access denial to sites using HTTP Strict Transport Security (HSTS), so such sites are exempted from deep SSL inspection.
Legal regulations require exemption of certain categories to protect user privacy and sensitive information, so these web categories are excluded from SSL inspection.



Refer to the exhibit.



The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.

What must the administrator configure to answer this specific request from the NOC team?

  1. Move NOC_Access to the top of the list to ensure all profile settings take effect.
  2. Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.
  3. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access
  4. Increase the admintimeout value under config system accprofile NOC_Access.

Answer(s): D

Explanation:

The admintimeout setting in the admin access profile controls the inactivity timeout for GUI sessions.
Increasing this value will extend the session duration before automatic disconnection.



Refer to the exhibit.



Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)

  1. Administrators cannot change the configuration.
  2. FortiGate skips quarantine actions.
  3. Administrators must restart FortiGate to allow new session.
  4. FortiGate drops new sessions requiring inspection.

Answer(s): B,D

Explanation:

In fail-open mode, FortiGate skips quarantine actions to maintain traffic flow despite IPS or antivirus failures.
FortiGate drops new sessions that require inspection when in conserve mode and fail-open is enabled, to protect the network from potentially harmful traffic.



What is the primary FortiGate election process when the HA override setting is enabled?

  1. Connected monitored ports > Priority > HA uptime > FortiGate serial number
  2. Connected monitored ports > Priority > System uptime > FortiGate serial number
  3. Connected monitored ports > HA uptime > Priority > FortiGate serial number
  4. Connected monitored ports > System uptime > Priority > FortiGate serial number

Answer(s): A

Explanation:

When HA override is enabled, FortiGate uses the following election order: number of connected monitored ports, then device priority, followed by HA uptime, and finally FortiGate serial number as a tiebreaker.



Viewing Page 1 of 12



Share your comments for Fortinet FCP_FGT_AD-7.6 exam with other users:

Albin 10/13/2023 12:37:00 AM

good ................
EUROPEAN UNION


Passed 1/16/2022 9:40:00 AM

passed
GERMANY


Harsh 6/12/2023 1:43:00 PM

yes going good
Anonymous


Salesforce consultant 1/2/2024 1:32:00 PM

good questions for practice
FRANCE


Ridima 9/12/2023 4:18:00 AM

need dump and sap notes for c_s4cpr_2308 - sap certified application associate - sap s/4hana cloud, public edition - sourcing and procurement
Anonymous


Tanvi Rajput 10/6/2023 6:50:00 AM

question 11: d i personally feel some answers are wrong.
UNITED KINGDOM


Anil 7/18/2023 9:38:00 AM

nice questions
Anonymous


Chris 8/26/2023 1:10:00 AM

looking for c1000-158: ibm cloud technical advocate v4 questions
Anonymous


sachin 6/27/2023 1:22:00 PM

can you share the pdf
Anonymous


Blessious Phiri 8/13/2023 10:26:00 AM

admin ii is real technical stuff
Anonymous


Luis Manuel 7/13/2023 9:30:00 PM

could you post the link
UNITED STATES


vijendra 8/18/2023 7:54:00 AM

hello send me dumps
Anonymous


Simeneh 7/9/2023 8:46:00 AM

it is very nice
Anonymous


john 11/16/2023 5:13:00 PM

i gave the amazon dva-c02 tests today and passed. very helpful.
Anonymous


Tao 11/20/2023 8:53:00 AM

there is an incorrect word in the problem statement. for example, in question 1, there is the word "speci c". this is "specific. in the other question, there is the word "noti cation". this is "notification. these mistakes make this site difficult for me to use.
Anonymous


patricks 10/24/2023 6:02:00 AM

passed my az-120 certification exam today with 90% marks. studied using the dumps highly recommended to all.
Anonymous


Ananya 9/14/2023 5:17:00 AM

i need it, plz make it available
UNITED STATES


JM 12/19/2023 2:41:00 PM

q47: intrusion prevention system is the correct answer, not patch management. by definition, there are no patches available for a zero-day vulnerability. the way to prevent an attacker from exploiting a zero-day vulnerability is to use an ips.
UNITED STATES


Ronke 8/18/2023 10:39:00 AM

this is simple but tiugh as well
Anonymous


CesarPA 7/12/2023 10:36:00 PM

questão 4, segundo meu compilador local e o site https://www.jdoodle.com/online-java-compiler/, a resposta correta é "c" !
UNITED STATES


Jeya 9/13/2023 7:50:00 AM

its very useful
INDIA


Tracy 10/24/2023 6:28:00 AM

i mastered my skills and aced the comptia 220-1102 exam with a score of 920/1000. i give the credit to for my success.
Anonymous


James 8/17/2023 4:33:00 PM

real questions
UNITED STATES


Aderonke 10/23/2023 1:07:00 PM

very helpful assessments
UNITED KINGDOM


Simmi 8/24/2023 7:25:00 AM

hi there, i would like to get dumps for this exam
AUSTRALIA


johnson 10/24/2023 5:47:00 AM

i studied for the microsoft azure az-204 exam through it has 100% real questions available for practice along with various mock tests. i scored 900/1000.
GERMANY


Manas 9/9/2023 1:48:00 AM

please upload 1z0-1072-23 exam dups
UNITED STATES


SB 9/12/2023 5:15:00 AM

i was hoping if you could please share the pdf as i’m currently preparing to give the exam.
Anonymous


Jagjit 8/26/2023 5:01:00 PM

i am looking for oracle 1z0-116 exam
UNITED STATES


S Mallik 11/27/2023 12:32:00 AM

where we can get the answer to the questions
Anonymous


PiPi Li 12/12/2023 8:32:00 PM

nice questions
NETHERLANDS


Dan 8/10/2023 4:19:00 PM

question 129 is completely wrong.
UNITED STATES


gayathiri 7/6/2023 12:10:00 AM

i need dump
UNITED STATES


Deb 8/15/2023 8:28:00 PM

love the site.
UNITED STATES