Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Fortinet FCSS_EFW_AD-7.6 Practice Exam with Questions & Answers

Questions 1

Which two statements about IKEv2 are true if an administrator decides to implement IKEv2 in the VPN topology? (Choose two.)

Options:
A.

It includes stronger Diffie-Hellman (DH) groups, such as Elliptic Curve (ECP) groups.

B.

It supports interoperability with devices using IKEv1.

C.

It exchanges a minimum of two messages to establish a secure tunnel.

D.

It supports the extensible authentication protocol (EAP).

Fortinet FCSS_EFW_AD-7.6 Premium Access
Questions 2

What happens when an SSO user logs into a downstream FortiGate?

Options:
A.

Denied

B.

Readonly admin

C.

Super admin

D.

No account

Questions 3

Which specialized acceleration hardware must you use for VXLAN?

Options:
A.

CPU

B.

NTurbo

C.

CP10

D.

NPU7

Questions 4

Why is the prerun CLI template not assigned after installation?

Options:
A.

Manual removal

B.

Auto-unassigned

C.

Permanent

D.

Postrun needed

Questions 5

Refer to the exhibit, which shows the ADVPN network topology and partial BGP configuration.

FCSS_EFW_AD-7.6 Question 5

FCSS_EFW_AD-7.6 Question 5

Which two parameters must an administrator configure in the config neighbor range for spokes shown in the exhibit? (Choose two.)

Options:
A.

set max-neighbor-num 2

B.

set neighbor-group advpn

C.

set route-reflector-client enable

D.

set prefix 172.16.1.0 255.255.255.0

Questions 6

Which technology should you use to facilitate dynamic direct tunnels and automatic link optimization in a hub-and-spoke VPN topology?

Options:
A.

Use static IPsec tunnels

B.

Use ADVPN 2.0

C.

Use GRE over IPsec

D.

Use IP-in-IP tunneling

Questions 7

Why is the web filter database version not shown in the FortiGuard Security Services dashboard?

Options:
A.

The database failed to update

B.

The web filter database is cloud hosted

C.

Flow mode disables the database

D.

FortiGate does not support web filtering

Questions 8

How does configuring tcp-mss-sender and tcp-mss-receiver affect TCP packets?

Options:
A.

Header

B.

Payload

C.

Allow

D.

Fragment

Questions 9

An administrator configured the FortiGate devices in an enterprise network to join the Fortinet Security Fabric. The administrator has a list of IP addresses that must be blocked by the data center firewall. This list is updated daily.

How can the administrator automate a firewall policy with the daily updated list?

Options:
A.

With FortiNAC

B.

With FortiAnalyzer

C.

With a Security Fabric automation

D.

With an external connector from Threat Feeds

Questions 10

A company ' s users on an IPsec VPN between FortiGate A and B have experienced intermittent issues since implementing VXLAN. The administrator suspects that packets exceeding the 1500-byte default MTU are causing the problems.

In which situation would adjusting the interface’s maximum MTU value help resolve issues caused by protocols that add extra headers to IP packets?

Options:
A.

Adjust the MTU on interfaces only if FortiGate has the FortiGuard enterprise bundle, which allows MTU modification.

B.

Adjust the MTU on interfaces in all FortiGate devices that support the latest family of Fortinet SPUs: NP7, CP9 and SP5.

C.

Adjust the MTU on interfaces in controlled environments where all devices along the path allow MTU interface changes.

D.

Adjust the MTU on interfaces only in wired connections like PPPoE, optic fiber, and ethernet cable.

Exam Code: FCSS_EFW_AD-7.6
Certification Provider: Fortinet
Exam Name: Fortinet NSE 7 - Enterprise Firewall 7.6 Administrator
Last Update: Apr 13, 2026
Questions: 113