Free FCP - FortiGate 7.6 Administrator practice — 6 questions on Deployment and System Configuration, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Deployment and System Configuration
A network engineer deploys a FortiGate in Transparent mode between two access switches that carry multiple VLANs. After deployment, broadcast storms occur because Layer 2 traffic from one VLAN segment is being forwarded to interfaces that should be logically isolated. Which configuration change on the affected interfaces BEST resolves this without changing the physical topology or operation mode?
In Transparent mode, the forward-domain setting on an interface creates a distinct Layer 2 broadcast/forwarding domain within the same bridge instance, preventing L2 traffic (including broadcasts) from being forwarded between interfaces assigned different forward-domain IDs, which stops the storm without changing topology.
Question 2 of 6 · Deployment and System Configuration
An administrator must create an account that can manage firewall policies and objects only within the 'Branch-VDOM' virtual domain, and must not be able to view or modify System > Global settings that affect other VDOMs. Which configuration approach satisfies this requirement?
A custom administrator profile with permissions scoped to VDOM-level objects, combined with limiting the administrator account's assigned VDOM(s) to only Branch-VDOM, restricts the account to managing policies/objects in that VDOM and blocks access to global system settings.
Question 3 of 6 · Deployment and System Configuration
By default, which TCP port does a FortiGate running FortiOS 7.6 use to retrieve antivirus and IPS signature package updates from the FortiGuard Distribution Network (FDN)?
FortiOS uses HTTPS over TCP 443 as the default port for contacting the FortiGuard Distribution Network to download AV and IPS signature updates in current FortiOS releases.
Question 4 of 6 · Deployment and System Configuration
A FortiGate has three interfaces (port1, port2, port3) all assigned to the same zone named 'Internal'. No firewall policies exist between port1 and port2, yet traffic currently flows freely between hosts on those two interfaces. What must the administrator configure so that traffic between port1 and port2 requires an explicit firewall policy, while keeping all three interfaces in the same zone?
By default, interfaces within the same zone can pass traffic to each other without an explicit policy. Enabling 'Block intra-zone traffic' forces the FortiGate to require an explicit firewall policy for traffic between member interfaces of that same zone.
Question 5 of 6 · Deployment and System Configuration
What is the default administrative GUI/CLI idle timeout on a FortiGate, and what is the maximum value it can be set to under 'config system global'?
The FortiOS admintimeout setting defaults to 5 minutes and can be configured up to a maximum of 480 minutes (8 hours) under config system global.
Question 6 of 6 · Deployment and System Configuration
A company wants to insert a FortiGate transparently into an existing network segment to apply security profiles without changing IP addressing, and also wants the FortiGate to participate in a dynamic routing protocol to influence traffic paths for transit traffic on that segment. Which statement is correct for FortiOS 7.6?
A FortiGate in Transparent mode operates as a Layer 2 bridge; it only supports static routing for its own management traffic and does not make Layer 3 forwarding decisions for transit traffic, so dynamic routing protocols cannot influence transit traffic paths in this mode. NAT/Route mode is required for that.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.