● FCSS - Enterprise Firewall 7.4 Administrator Exam Materials

Please note that the exam "FCSS - Enterprise Firewall 7.4 Administrator Exam" is no longer offered by Fortinet and is not available for booking through Pearson VUE, so we opened it on free view,
It has been replaced by the exam "NSE 7 - Enterprise Firewall 7.6 Administrator"

The new exam version is available on Brave-Dumps and can be purchased.




Question #61
Comment Image Comment Image Comment Image

efer to the exhibits, which show policy package conflict status and import device wizard information in the Core1 VDOM.

When the FortiManager administrator imports the policy package, the following message appears for the Web_restrictions web filter profile and the deep-inspection SSL-SSH profile, as shown in the exhibit.

The following objects were found having conflicts.
Please confirm your settings, then continue.

Which step should the administrator take to resolve the issue if Web_restrictions and deep-inspection are already being used by other FortiGate devices within FortiManager? (Choose one answer)

  • A. Create uniquely named objects on FortiGate and reimport them into the policy package.
  • B. Use non-default object values because FortiManager is unable to alter default values.
  • C. Select the FortiManager configuration that accepts changes in FortiManager and preserves existing configurations on FortiGate devices.
  • D. Retrieve the FortiGate configuration to automatically export correct objects and policies.

Question #62
Comment Image Comment Image Comment Image

Refer to the exhibit,

which shows a network diagram showing the addition of site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and site 1.

Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets? (Choose one answer)

  • A. Set route-overlap to either use-new or use-old
  • B. Set net-device to ecmp
  • C. Set single-source to enable
  • D. Set route-overlap to allow

Question #63
Comment Image Comment Image Comment Image

Refer to the exhibit, which shows a normalized interface LAN on FortiManager.

What two conclusions can you draw from this interface configuration? (Choose two answers)

  • A. The normalized interface LAN will be used as the port2 interface for NGFW-1 [Core2].
  • B. The normalized interface LAN will be used as the Human_Resources interface for any FortiGate-40F model devices.
  • C. The normalized interface LAN will be used as the private interface for FortiGate-VM64 model devices.
  • D. The normalized interface LAN will be used as the wireless interface for FortiGate-81E model devices.

Question #64
Comment Image Comment Image Comment Image

Refer to the exhibit, which shows the Administrators section of a root FortiGate and the Security Fabric Settings section of a downstream FortiGate.

When prompted to sign in with Security Fabric on the downstream FortiGate, a user enters the AdminSSO credentials.

What is the result? (Choose one answer)

  • A. The downstream FortiGate creates an SSO administrator account for AdminSSO with the super_admin_readonly profile.
  • B. The downstream FortiGate creates an SSO administrator account for AdminSSO with the super_admin profile.
  • C. The downstream FortiGate relies on the root FortiGate and does not create an administrator account.
  • D. The user is prompted to create an administrator account for AdminSSO with the correct profile