合格目指せFCSS_EFW_AD-7.4試験最新のFCSS_EFW_AD-7.4試験問題集PDF 2026年更新 [Q17-Q39]

Share

合格目指せFCSS_EFW_AD-7.4試験最新のFCSS_EFW_AD-7.4試験問題集PDF 2026年更新

FCSS_EFW_AD-7.4試験問題集、365日更新無料サンプル


Fortinet FCSS_EFW_AD-7.4 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • 集中管理:このセクションでは、セキュリティ管理者のスキルを評価し、フォーティネットのセキュリティソリューションの集中管理の実装に焦点を当てます。デバイスの構成と管理を一元的に行うことで、ネットワークセキュリティ運用を効率化します。受験者は、セキュリティポリシーの一貫性を維持し、導入を自動化することで、大規模なエンタープライズ環境を効率的に管理する方法を理解します。
トピック 2
  • システム構成:このセクションでは、ネットワークセキュリティエンジニアのスキルを評価し、セキュリティソリューション間のシームレスな統合を実現するフォーティネット セキュリティ ファブリックの実装について学習します。また、パフォーマンスを最適化するために、FortiGateデバイスのハードウェアアクセラレーションを構成することも学習します。受験者は、高可用性クラスタのさまざまな動作モードの設定方法と、VLANおよびVDOMを使用したエンタープライズネットワークの実装方法を習得します。さらに、フォーティネットソリューションが安全なネットワーク環境にどのように貢献するかを示す、様々なユースケースシナリオを網羅します。
トピック 3
  • VPN:このセクションでは、ネットワークセキュリティエンジニアのスキルを評価し、エンタープライズ環境における安全な通信トンネルの実装について解説します。受験者は、IKEバージョン2を使用したIPsec VPNの設定方法を習得し、暗号化された接続を確立します。また、異なるサイト間でオンデマンドVPNトンネルを構築し、安全で動的な接続を確保するためのADVPNの実装も学習します。
トピック 4
  • セキュリティプロファイル:このセクションでは、ネットワークセキュリティエンジニアのスキルを測定し、SSLおよびSSHインスペクションを含むセキュリティインスペクションプロファイルの管理に焦点を当てます。受験者は、Webフィルタリング、アプリケーション制御、インターネットサービスデータベース(ISDB)を組み合わせてネットワークセキュリティを強化する方法を習得します。また、侵入防止システム(IPS)を統合して、企業ネットワーク内の脅威を監視・軽減する方法についても学習します。
トピック 5
  • ルーティング:このセクションでは、セキュリティ管理者のスキルを評価し、エンタープライズトラフィックを効果的に管理するための高度なルーティングプロトコルの実装について学習します。受験者は、ダイナミックルーティングを実現するOpen Shortest Path First(OSPF)と、異なるネットワーク間の通信を容易にし、エンタープライズ環境全体で効率的なトラフィックフローを確保するためのBorder Gateway Protocol(BGP)の設定に関する専門知識を習得します。

 

質問 # 17
An administrator wants to capture encrypted phase 2 traffic between two FortiGate devices using the built-in sniffer.
If the administrator knows that there is no NAT device located between both FortiGate devices, which command should the administrator run?

  • A. diagnose sniffer packet any 'udp port 4500'
  • B. diagnose sniffer packet any 'ah'
  • C. diagnose sniffer packet any 'ip proto 50'
  • D. diagnose sniffer packet any 'udp port 500'

正解:C


質問 # 18
Refer to the exhibits.


The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown.
When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials.
What is the next status for the user?

  • A. The user is prompted to create an SSO administrator account for AdminSSO.
  • B. The user accesses the downstream FortiGate with super_admin privileges.
  • C. The user accesses the downstream FortiGate with super_admin_readonly privileges.
  • D. The user receives an authentication failure message.

正解:C

解説:
From the Root FortiGate - System Administrator Configuration exhibit:
The AdminSSO account has the super_admin_readonly role.
From the Downstream FortiGate - Security Fabric Settings exhibit:
The Security Fabric role is set to Join Existing Fabric, meaning it will authenticate with the root FortiGate.
SAML Single Sign-On (SSO) is enabled, and the default admin profile is set to super_admin_readonly.
When the AdminSSO user logs into the downstream FortiGate using SSO, the authentication request is sent to the root FortiGate, where AdminSSO has super_admin_readonly permissions.
Since the downstream FortiGate inherits this permission through the Security Fabric configuration, the user will be granted super_admin_readonly access.


質問 # 19
An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs the debug flow while attempting the connection using HTTP.
The output of the debug flow is shown in the exhibit.

Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)

  • A. Redirection of HTTP to HTTPS administrative access is disabled.
  • B. HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.
  • C. The packet is denied because of reverse path forwarding check.
  • D. HTTP administrative access is configured with a port number different than 80.

正解:B、D


質問 # 20
An administrator is setting up an ADVPN configuration and wants to ensure that peer IDs are not exposed during VPN establishment.
Which protocol can the administrator use to enhance security?

  • A. Stick with IKEv1 main mode because it offers better performance.
  • B. Opt for SSL VPN web mode because it does not use peer IDs at all.
  • C. Choose IKEv1 aggressive mode because it simplifies peer identification.
  • D. Use IKEv2, which encrypts peer IDs and prevents exposure.

正解:D

解説:
InADVPN (Auto-Discovery VPN) configurations, security concerns includeprotecting peer IDsduring VPN establishment. Peer IDs are exchanged in theIKE (Internet Key Exchange) negotiation phase, and their exposure could lead toprivacy risks or targeted attacks.
#IKEv2 encrypts peer IDs, making itmore securecompared to IKEv1, where peer IDs can beexposed in plaintextin aggressive mode.
#IKEv2 also provides better performance and flexibilitywhile supporting dynamic tunnel establishment in ADVPN.


質問 # 21
Refer to the exhibit, which shows the ADVPN network topology and partial BGP configuration.


Which two parameters must an administrator configure in the config neighbor range for spokes shown in the exhibit? (Choose two.)

  • A. set route-reflector-client enable
  • B. set prefix 172.16.1.0 255.255.255.0
  • C. set neighbor-group advpn
  • D. set max-neighbor-num 2

正解:B、C

解説:
In the given ADVPN (Auto-Discovery VPN) topology, BGP is being used to dynamically establish routes between spokes. The neighbor-range configuration is crucial for simplifying BGP peer setup by automatically assigning neighbors based on their IP range.
set neighbor-group advpn
The neighbor-group parameter is used to apply pre-defined settings (such as AS number) to dynamically discovered BGP neighbors.
The advpn neighbor-group is already defined in the configuration, and assigning it to the neighbor- range ensures consistent BGP settings for all spoke neighbors.
set prefix 172.16.1.0 255.255.255.0
This command allows dynamic BGP peer discovery by defining a range of potential neighbor IPs (172.16.1.1 - 172.16.1.255).
Since each spoke has a unique /32 IP within this subnet, this ensures that any spoke within the
172.16.1.0/24 range can automatically establish a BGP session with the hub.


質問 # 22
Refer to the exhibit, which shows an OSPF network.

Which configuration must the administrator apply to optimize the OSPF database?

  • A. Set an access list in the AS boundary FortiGate.
  • B. Set the area 0.0.0.1 to the type NSSA in the area border FortiGate.
  • C. Set the area 0.0.0.1 to the type STUB in the area border FortiGate.
  • D. Set a route map in the AS boundary FortiGate.

正解:C

解説:
TheOSPF database optimizationis necessary to reduce unnecessary routing information and improve network performance. In the given topology,Area 0.0.0.1is a non-backbone area connected toArea 0.0.0.0 (the backbone area)through anArea Border Router (ABR).
To optimize OSPF in this scenario, configuringArea 0.0.0.1 as a Stub Areawill:
#Reduce the size of the OSPF databaseby preventing external routes (from outside OSPF) from being injected into Area 0.0.0.1.
#Allow only intra-area and inter-area routes, meaning routers in Area 0.0.0.1 will rely on adefault route for external destinations.
#Improve convergence time and reduce router processing loadsince fewer LSAs (Link-State Advertisements) are exchanged.


質問 # 23
A user reports that their computer was infected with malware after accessing a secured HTTPS website.
However, when the administrator checks the FortiGate logs, they do not see that the website was detected as insecure despite having an SSL certificate and correct profiles applied on the policy.
How can an administrator ensure that FortiGate can analyze encrypted HTTPS traffic on a website?

  • A. The administrator must enable full SSL inspection in the SSL/SSH Inspection Profile to decrypt packets and ensure they are analyzed as expected.
  • B. The administrator must enable reputable websites to allow only SSL/TLS websites rated by FortiGuard web filter.
  • C. The administrator must enable DNS over TLS to protect against fake Server Name Indication (SNI) that cannot be analyzed in common DNS requests on HTTPS websites.
  • D. The administrator must enable URL extraction from SNI on the SSL certificate inspection to ensure the TLS three-way handshake is correctly analyzed by FortiGate.

正解:A

解説:
FortiGate, like other security appliances, cannot analyze encrypted HTTPS traffic unless itdecryptsit first. If only certificate inspectionis enabled, FortiGate can see the certificate details (such as the domain and issuer) butcannot inspect the actual web content.
To fully analyze the traffic and detect potential malware threats:
#Full SSL inspection (Deep Packet Inspection)must be enabled in theSSL/SSH Inspection Profile.
# This allows FortiGate todecrypt the HTTPS traffic, inspect the content, and then re-encrypt it before forwarding it to the user.
# Without full SSL inspection, threats embedded in encrypted traffic may go undetected.


質問 # 24
Why does the ISDB block layers 3 and 4 of the OSI model when applying content filtering? (Choose two.)

  • A. The ISDB limits access by URL and domain.
  • B. The ISDB works in proxy mode, allowing the analysis of packets in layers 3 and 4 of the OSI model.
  • C. The ISDB blocks the IP addresses and ports of an application predefined by FortiGuard.
  • D. FortiGate has a predefined list of all IPs and ports for specific applications downloaded from FortiGuard.

正解:C、D

解説:
TheInternet Service Database (ISDB)in FortiGate is used to enforce content filtering atLayer 3 (Network Layer) and Layer 4 (Transport Layer)of the OSI model by identifying applications based on their predefined IP addresses and ports.
FortiGate has a predefined list of all IPs and ports for specific applications downloaded from FortiGuard:
# FortiGate retrieves and updates apredefined listof IPs and ports for different internet services from FortiGuard.
# This allows FortiGate to block specific services atLayer 3 and Layer 4without requiring deep packet inspection.
The ISDB blocks the IP addresses and ports of an application predefined by FortiGuard:
# ISDB works by matching traffic to knownIP addresses and portsof categorized services.
# When an application or service is blocked, FortiGate prevents communication bydenying traffic based on its destination IP and port number.


質問 # 25
Refer to the exhibit, which shows a partial web filter profile configuration.


Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

  • A. FortiGate will block the connection, based on the FortiGuard category based filter configuration.
  • B. FortiGate will allow the connection, based onthe URL Filter configuration.
  • C. FortiGate will block the connection as an invalid URL.
  • D. FortiGate will exempt the connection, based on the Web Content Filter configuration.

正解:B


質問 # 26
View the central management configuration shown in the exhibit, and then answer the question below.

Which server will FortiGate choose for antivirus and IPS updates if 10.0.1.243 is experiencing an outage?

  • A. 10.0.1.242
  • B. 10.0.1.240
  • C. One of the public FortiGuard distribution servers
  • D. 0.0.1.244

正解:C


質問 # 27
Refer to the exhibit, which shows a hub and spokes deployment.

An administrator is deploying several spokes, including the BGP configuration for the spokes to connect to the hub.
Which two commands allow the administrator to minimize the configuration? (Choose two.)

  • A. route-reflector-client
  • B. ibgp-enforce-multihop
  • C. neighbor-range
  • D. neighbor-group

正解:C、D

解説:
neighbor-group:
# This command is used to group multipleBGP neighborswith the same configuration, reducing redundant configuration.
# Instead of defining individual BGP settings for each spoke, the administrator can create aneighbor-group and apply the same policies, reducing manual work.
neighbor-range:
# This command allows the configuration ofa range of neighbor IPs dynamically, reducing the need to manually define each spoke neighbor.
# It automatically addsBGP neighborsthat match a given prefix, simplifying deployment.


質問 # 28
View the global IPS configuration, and then answer the question below.

Which of the following statements is true regarding this configuration?

  • A. IPS will scan every byte in every session.
  • B. IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.
  • C. New packets will be passed through without inspection if the IPS socket buffer runs out of memory
  • D. FortiGate will spawn IPS engine instances based on the system load.

正解:A


質問 # 29
Which ADVPN configuration must be configured using a script on FortiManager, when using VPN Manager to manage FortiGate VPN tunnels?

  • A. Set protected network to all
  • B. Enable AD-VPN in IPsec phase 1
  • C. Disable add-route on hub
  • D. Configure IP addresses on IPsec virtual interfaces

正解:B


質問 # 30
Refer to the exhibit, which shows a LAN interface connected from FortiGate to two FortiSwitch devices.

What two conclusions can you draw from the corresponding LAN interface? (Choose two.)

  • A. You must enable STP or RSTP on FortiGate and FortiSwitch to avoid layer 2 loopbacks.
  • B. This connection is using a FortiLInk to manage VLANs on FortiGate.
  • C. FortiGate is using an SD-WAN-type interface to connect to a FortiSwitch device with MCLAG.
  • D. The LAN interface must use a 802.3ad type interface.

正解:B、D

解説:
The diagram shows a FortiGate connected to two FortiSwitches, which suggests the use ofFortiLink, Fortinet's protocol for managing switches directly from a FortiGate. Since multiple connections are being used, the LAN interface must be set to802.3ad (LAG)mode to aggregate the links for redundancy and load balancing.
This setup allows FortiGate to handle VLAN assignments dynamically, as seen withVLAN 10 (192.168.15.1
/24). FortiLink ensures seamless integration between FortiGate and FortiSwitches, making STP unnecessary because Fortinet'sMCLAGprevents loops at Layer 2. SD-WAN, on the other hand, is used for WAN interfaces and does not apply to switch connectivity in this scenario.


質問 # 31
Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)

  • A. Importing interface mappings from managed devices.
  • B. Installing configuration changes to managed devices.
  • C. Previewing pending configuration changes for managed devices.
  • D. Adding devices to FortiManager.

正解:B、C


質問 # 32
Refer to the exhibit, which shows partial outputs from two routing debug commands.

Which change must an administrator make on FortiGate to route web traffic from internal users to the internet, using ECMP?

  • A. Set the priority of the static default route using port1 to 10.
  • B. Set preserve-session-route to enable.
  • C. Set snat-route-change to enable.
  • D. Set the priority of the static default route using port2 to 1.

正解:A


質問 # 33
Refer to the exhibits.


The Administrators section of a root FortiGate device and the Security Fabric Settings section of a downstream FortiGate device are shown.
When prompted to sign in with Security Fabric in the downstream FortiGate device, a user enters the AdminSSO credentials.
What is the next status for the user?

  • A. The user is prompted to create an SSO administrator account for AdminSSO.
  • B. The user accesses the downstream FortiGate with super_admin privileges.
  • C. The user accesses the downstream FortiGate with super_admin_readonly privileges.
  • D. The user receives an authentication failure message.

正解:C

解説:
From theRoot FortiGate - System Administrator Configurationexhibit:
# TheAdminSSOaccount has thesuper_admin_readonlyrole.
From theDownstream FortiGate - Security Fabric Settingsexhibit:
# TheSecurity Fabric roleis set toJoin Existing Fabric, meaning it will authenticate with the root FortiGate.
#SAML Single Sign-On (SSO) is enabled, and thedefault admin profileis set tosuper_admin_readonly.
When theAdminSSOuser logs into the downstream FortiGate usingSSO, the authentication request is sent to the root FortiGate, where AdminSSO hassuper_admin_readonlypermissions. Since the downstream FortiGate inherits this permission through the Security Fabric configuration, the user will be granted super_admin_readonlyaccess.


質問 # 34
A FortiGate device has the following LDAP configuration:

The LDAP user student cannot authenticate.
The exhibit shows the output of the authentication real time debug while testing the student account:

Based on the above output, what FortiGate LDAP settings must the administer check? (Choose two.)

  • A. username.
  • B. password.
  • C. cnid.
  • D. dn.

正解:A、B


質問 # 35
A FortiGate device has the following LDAP configuration:

The administrator executed the 'dsquery' command in the Windows LDAp server 10.0.1.10, and got the following output:
>dsquery user -samid administrator
"CN-Administrator, CN-Users, DC=trainingAD, DC-training, DC-lab"
Based on the output, what FortiGate LDAP setting is configured incorrectly?

  • A. password.
  • B. username.
  • C. cnid.
  • D. dn.

正解:B


質問 # 36
An administrator must automate a weekly backup of all the FortiGate devices in an enterprise network.
Which two steps must the administrator follow to implement this? (Choose two.)

  • A. Create an automation stitch.
  • B. Create metadata variables for all the FortiGate devices.
  • C. Integrate all the FortiGate devices in a Security Fabric environment.
  • D. Create a script to be run in the device database.

正解:A、C


質問 # 37
Which two statements correctly describe the characteristics of the Fortinet Security Fabric? (Choose two.)

  • A. The core of the Security Fabric includes FortiMail, FortiWeb, and FortiSandbox.
  • B. It supports an open API, allowing third-party product integration.
  • C. It contains individual management platforms for each device to provide granular control.
  • D. It provides a single pane of glass for reporting for all devices in the Security Fabric.

正解:B、D


質問 # 38
Refer to the exhibit, which shows a command output.

FortiGate_A and FortiGate_B are members of an FGSP cluster in an enterprise network.
While testing the cluster using the ping command, the administrator monitors packet loss and found that the session output on FortiGate_B is as shown in the exhibit.
What could be the cause of this output on FortiGate_B?

  • A. FortiGate_B is configured in passive mode.
  • B. FortiGate_A and FortiGate_B have the same standalone-group-id value.
  • C. The session synchronization is encrypted.
  • D. session-pickup-connectionless is set to disable on FortiGate_B.

正解:D

解説:
TheFortinet FGSP (FortiGate Session Life Support Protocol) clusterallows session synchronization betweentwo FortiGate devicesto provide seamless failover. However,ICMP (ping) is a connectionless protocol, and by default, FortiGate does not synchronize connectionless sessions unless explicitly enabled.
In the exhibit:
# The commandget system session list | grep icmponFortiGate_Breturnsno output, meaning that ICMP sessions arenot being synchronizedfrom FortiGate_A.
# Ifsession-pickup-connectionlessis disabled,FortiGate_B will not receive ICMP sessions, causingpacket lossduring failover.


質問 # 39
......

FCSS_EFW_AD-7.4問題集、あなたを合格させる認証試験:https://www.goshiken.com/Fortinet/FCSS_EFW_AD-7.4-mondaishu.html

まもなくセール終了!リアルFCSS_EFW_AD-7.4のPDF解答を使おう:https://drive.google.com/open?id=1VF1D-75fyNe4za2E86-Zg4gT7tRfuFwQ