Free FCP_FGT_AD-7.6 Exam Dumps

Question 6

Which three statements about SD-WAN performance SLAs are true? (Choose three.)

Correct Answer:ABE
SD-WAN SLAs monitor metrics like packet loss and jitter to evaluate link performance. SLA measurements can be performed using active probing or passive monitoring. Administrators can configure all SLA target parameters to define performance criteria.

Question 7

Refer to the exhibit.
FCP_FGT_AD-7.6 dumps exhibit
The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit.
For which two reasons are these web categories exempted? (Choose two.)

Correct Answer:AD
FortiGate's temporary SSL certificate may cause access denial to sites using HTTP Strict Transport Security (HSTS), so such sites are exempted from deep SSL inspection.
Legal regulations require exemption of certain categories to protect user privacy and sensitive information, so these web categories are excluded from SSL inspection.

Question 8

Refer to the exhibits.
FCP_FGT_AD-7.6 dumps exhibit
An administrator wants to add HQ-ISFW-2 in the Security Fabric. HQ-ISFW-2 is in the same subnet as HQ- ISFW. After configuring the Security Fabric settings on HQ-ISFW-2, the status staysPending.
What can be the two possible reasons? (Choose two.)

Correct Answer:AC
The Upstream FortiGate IP should match the IP address of the Fabric Root interface, which is 10.0.11.254, not 10.0.13.254.
The new device (HQ-ISFW-2) must be authorized on the Fabric Root (HQ-ISFW) before it can join the Security Fabric, otherwise the status remains pending.

Question 9

Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI.
FCP_FGT_AD-7.6 dumps exhibit
Based on the exhibit, which statement is true?

Correct Answer:A
The Underlay zone is the default SD-WAN zone, typically representing the physical interfaces in the SD- WAN configuration before overlay or virtual links are added.

Question 10

Refer to the exhibit.
FCP_FGT_AD-7.6 dumps exhibit
An administrator has created a new firewall address to use as the destination for a static route.
Why is the administrator not able to select the new address in theDestinationfield of the new static route?

Correct Answer:D
To use an FQDN-based address object as a destination in a static route, the "Routing configuration" option must be enabled in the firewall address settings. Without this, the address cannot be selected for routing.