Fortinet FCP_FGT_AD-7.6 Exam
FCP - FortiGate 7.6 Administrator (Page 3 )

Updated On: 7-Feb-2026

Refer to the exhibit.



The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity.

What must the administrator configure to answer this specific request from the NOC team?

  1. Move NOC_Access to the top of the list to ensure all profile settings take effect.
  2. Increase the offline value of the Override Idle Timeout parameter in the NOC_Access admin profile.
  3. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access
  4. Increase the admintimeout value under config system accprofile NOC_Access.

Answer(s): B



Refer to the exhibit.



Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.)

  1. Administrators cannot change the configuration.
  2. FortiGate skips quarantine actions.
  3. Administrators must restart FortiGate to allow new session.
  4. FortiGate drops new sessions requiring inspection.

Answer(s): A,B



What is the primary FortiGate election process when the HA override setting is enabled?

  1. Connected monitored ports > Priority > HA uptime > FortiGate serial number
  2. Connected monitored ports > Priority > System uptime > FortiGate serial number
  3. Connected monitored ports > HA uptime > Priority > FortiGate serial number
  4. Connected monitored ports > System uptime > Priority > FortiGate serial number

Answer(s): A

Explanation:

When HA override is enabled, FortiGate uses the following election order: number of connected monitored ports, then device priority, followed by HA uptime, and finally FortiGate serial number as a tiebreaker.



An administrator wanted to configure an IPS sensor to block traffic that triggers a signature set number of times during a specific time period.

How can the administrator achieve the objective?

  1. Use IPS group signatures, set rate-mode 60.
  2. Use IPS packet logging option with periodical filter option.
  3. Use IPS filter, rate-mode periodical option.
  4. Use IPS signatures, rate-mode periodical option.

Answer(s): D

Explanation:

To block traffic that triggers a signature a specific number of times within a time period, the administrator must configure the IPS signature with the rate-mode periodical option.
This allows the IPS to count the number of times a signature is matched in a defined interval and take action (e.g., block) if the threshold is exceeded.



A FortiGate firewall policy is configured with active authentication, however, the user cannot authenticate when accessing a website.

Which protocol must FortiGate allow even though the user cannot authenticate?

  1. LDAP
  2. TACASC+
  3. Kerberos
  4. DNS

Answer(s): D

Explanation:

DNS traffic must be allowed so the user can resolve domain names and reach the authentication server or web resources, even if authentication initially fails.



Viewing page 3 of 27
Viewing questions 11 - 15 out of 128 questions



Post your Comments and Discuss Fortinet FCP_FGT_AD-7.6 exam prep with other Community members:

Join the FCP_FGT_AD-7.6 Discussion