最新版を今すぐ試そう![2024年12月] 試験準備には欠かさない!FCP_FCT_AD-7.2問題集
有能な受験者がシミュレーション済みのFCP_FCT_AD-7.2試験PDF問題を試そう
Fortinet FCP_FCT_AD-7.2 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
質問 # 20
Refer to the exhibit, which shows FortiClient EMS deployment, profiles.
When an administrator creates a deployment profile on FortiClient EMS. which statement about the deployment profile is true?
- A. Deployment-2 will install FortiClient on both the AD group and workgroup.
- B. Deployment-2 will upgrade FortiClient on both the AD group and workgroup.
- C. Deployment-1 will upgrade FortiClient only on the workgroup.
- D. Deployment-1 will install FortiClient on new AO group endpoints.
正解:B
解説:
Deployment Profiles Analysis:
Deployment-1 has the "First-Time-Installation" package and is assigned to "All Groups" with a priority of 1 but is not enabled.
Deployment-2 has the "To-Upgrade" package, is assigned to both "All Groups" and "trainingAD.training.lab," with a priority of 2 and is enabled.
Evaluating Deployment-2:
Deployment-2 will upgrade FortiClient on both "All Groups" and "trainingAD.training.lab" since it is enabled and assigned to these groups. This includes both AD (Active Directory) groups and workgroups.
Conclusion:
Since Deployment-2 is set to upgrade FortiClient on all the assigned groups and workgroups, the correct answer is A.
Reference:
FortiClient EMS deployment and profile documentation from the study guides.
質問 # 21
FortiClient EMS endpoint policies
Refer to the exhibit, which shows multiple endpoint policies on FortiClient EMS. Which policy is applied to the endpoint in the AD group trainingAD
- A. The sales policy
- B. Both the Sales and Training policies because their priority is higher than the Default policy
- C. The Default policy because it has the highest priority
- D. The Training policy
正解:D
解説:
Observation of Endpoint Policies:
The exhibit shows multiple endpoint policies with their assigned groups, priority levels, and enabled status.
Evaluating Policy Assignment:
The Training policy is specifically assigned to the "trainingAD.training.lab" group, with a higher priority than the Default policy.
Conclusion:
The correct policy applied to the endpoint in the AD group "trainingAD" is the Training policy (A).
Reference:
FortiClient EMS policy configuration and priority management documentation from the study guides.
質問 # 22
Exhibit.
Refer to the exhibits, which show the Zero Trust Tag Monitor and the FortiClient GUI status.
Remote-Client is tagged as Remote-User* on the FortiClient EMS Zero Trust Tag Monitor.
What must an administrator do to show the tag on the FortiClient GUI?
- A. Change the FortiClient system settings to enable lag visibility.
- B. Update tagging rule logic to enable tag visibility.
- C. Change the FortiClient EMS shared settings to enable tag visibility.
- D. Change the endpoint alerts configuration to enable tag visibility.
正解:D
解説:
* Observation of Exhibits:
* The exhibits show the Zero Trust Tag Monitor on FortiClient EMS and the FortiClient GUI status.
* Remote-Client is tagged as "Remote-Endpoints" on the FortiClient EMS Zero Trust Tag Monitor.
* Enabling Tag Visibility:
* To show the tag on the FortiClient GUI, the endpoint alerts configuration must be adjusted to enable tag visibility.
* Verification:
* The correct action is to change the endpoint alerts configuration to enable tag visibility, ensuring that the tag appears in the FortiClient GUI.
References:
* FortiClient EMS and FortiClient configuration documentation from the study guides.
質問 # 23
What action does FortiClient anti-exploit detection take when it detects exploits?
- A. Blocks memory allocation to the compromised application process
- B. Deletes the compromised application process
- C. Patches the compromised application process
- D. Terminates the compromised application process
正解:C
解説:
The anti-exploit detection protects vulnerable endpoints from unknown exploit attacks. FortiClient monitors the behavior of popular applications, such as web browsers (Internet Explorer, Chrome, Firefox, Opera), Java
/Flash plug-ins, Microsoft Office applications, and PDF readers, to detect exploits that use zero-day or unpatched vulnerabilities to infect the endpoint. Once detected, FortiClient terminates the compromised application process.
質問 # 24
Refer to the exhibit, which shows the endpoint summary information on FortiClient EMS.
What two conclusions can you make based on the Remote-Client status shown above? (Choose two.)
- A. The endpoint is classified as at risk.
- B. The endpoint is configured to support FortiSandbox.
- C. The endpoint is currently off-net.
- D. The endpoint has been assigned the Default endpoint policy.
正解:C、D
解説:
Based on the Remote-Client status shown in the exhibit:
Endpoint Policy: The "Policy" field shows "Default," indicating that the endpoint has been assigned the Default endpoint policy.
Connection Status: The "Location" field shows "Off-Fabric," meaning that the endpoint is currently off the corporate network (off-net).
Therefore, the two conclusions that can be made are:
The endpoint has been assigned the Default endpoint policy.
The endpoint is currently off-net.
Reference
FortiClient EMS 7.2 Study Guide, Endpoint Summary Information Section
Fortinet Documentation on Endpoint Policies and Status Indicators
質問 # 25
Refer to the exhibit.
An administrator has restored the modified XML configuration file to FortiClient and sees the error shown in the exhibit.
Based on the XML settings shown in the exhibit, what must the administrator do to resolve the issue with the XML configuration file?
- A. The administrator must change the file size
- B. The administrator must save the file as FortiClient-config conf.
- C. The administrator must resolve the XML syntax error.
- D. The administrator must use a password to decrypt the file
正解:C
解説:
Based on the error message and the XML configuration file shown in the exhibit:
The error "Failed to process the file" typically indicates an issue with the XML syntax.
Upon reviewing the XML content, it is crucial to ensure that all tags are correctly formatted, properly opened and closed, and that there are no syntax errors.
Resolving any XML syntax errors will allow FortiClient to successfully process and restore the configuration file.
Therefore, the administrator must resolve the XML syntax error to fix the issue.
Reference
FortiClient EMS 7.2 Study Guide, Configuration File Management Section
General XML Syntax Guidelines and Best Practices
質問 # 26
An administrator wants to simplify remote accesswithout asking users to provideuser credentials Which access control method provides this solution?
- A. ZTNA IP/MAC littering mode
- B. ZTNA full mode
- C. L2TP
- D. SSL VPN
正解:B
解説:
* Simplifying Remote Access:
* The administrator wants to simplify remote access without asking users to provide user credentials.
* Evaluating Access Control Methods:
* ZTNA full mode can provide seamless access by leveraging device identity and posture, eliminating the need for user credentials for each access request.
* Other methods like SSL VPN and L2TP typically require user credentials.
* Conclusion:
* The correct access control method that provides this solution is ZTNA full mode.
References:
* ZTNA section in the FortiGate Infrastructure 7.2 Study Guide.
質問 # 27
Refer to the exhibit.
Based on the settings shown in the exhibit, which two actions must the administrator take to make the endpoint compliant? (Choose two.)
- A. Integrate FortiSandbox tor infected file analysis
- B. Patch applications that have vulnerability rated as high or above.
- C. Enable the web filter profile.
- D. Run Calculator application on the endpoint.
正解:B、D
解説:
* Observation of Compliance Profile:
* The compliance profile shown in the exhibit includes rules for vulnerability severity level and running process (Calculator.exe).
* Evaluating Actions for Compliance:
* To make the endpoint compliant, the administrator needs to ensure that the vulnerability severity level is medium or higher is patched (D).
* Additionally, the Calculator.exe application must be running on the endpoint (B).
* Eliminating Incorrect Options:
* Enabling the web filter profile (A) is not related to the compliance rules shown.
* Integrating FortiSandbox (C) is not a requirement in the given compliance profile.
* Conclusion:
* The correct actions are to run the Calculator application on the endpoint (B) and patch applications with vulnerabilities rated as high or above (D).
References:
* FortiClient EMS compliance profile configuration documentation from the study guides.
質問 # 28
Which statement about FortiClient comprehensive endpoint protection is true?
- A. It helps to safeguard systems from DDoS.
- B. It helps to safeguard systems from email spam
- C. It helps to safeguard systems from data loss.
- D. lt helps to safeguard systems from advanced security threats, such as malware.
正解:D
解説:
FortiClient provides comprehensive endpoint protection for your Windows-based, Mac-based, and Linuxbased desktops, laptops, file servers, and mobile devices such as iOS and Android. It helps you to safeguard your systems with advanced security technologies, all of which you can manage from a single management console.
質問 # 29
Which two statements about ZTNA destinations are true? (Choose two.)
- A. FortiClient ZTNA destination encryption is disabled by default.
- B. FottiClient ZTNA destinations use an existing VPN tunnel to create a secure connection.
- C. FortiClient ZTNA destinations do not support a wildcard FQDN.
- D. FortiCIient ZTNA destination authentication is enabled by default.
- E. FortiClient ZTNA destinations provides access through TCP forwarding.
正解:A、C
質問 # 30
An administrator has a requirement to add user authentication to the ZTNA access for remote or off-fabric users Which FortiGate feature is required m addition to ZTNA?
- A. FortiGate FSSO
- B. FortiGate certificates
- C. FortiGate endpoint control
- D. C. FortiGate explicit proxy
正解:D
解説:
For adding user authentication to the ZTNA access for remote or off-fabric users, the following FortiGate feature is required in addition to ZTNA:
* FortiGate explicit proxyallows FortiGate to intercept web traffic for authentication purposes.
* ZTNA integrates with various FortiGate features to provide secure access and ensure that users are authenticated before accessing resources.
* By using an explicit proxy, FortiGate can handle web traffic and enforce authentication policies for remote users who are not directly on the corporate network (off-fabric).
Thus, the correct feature to use for this requirement is the FortiGate explicit proxy.
References
* FortiGate Security 7.2 Study Guide, ZTNA and Proxy Configuration Sections
* Fortinet Documentation on FortiGate Explicit Proxy and ZTNA Integration
質問 # 31
Which component or device shares ZTNA tag information through Security Fabric integration?
- A. FortiGate Access Proxy
- B. FortiGate
- C. FortiClient
正解:B
解説:
FortiClient EMS is the component that shares ZTNA tag information through Security Fabric integration.
ZTNA tags are synchronized from FortiClient EMS as inputs for the FortiGate application gateway. They can be used in ZTNA policies as security posturechecks to ensure certain security criteria are met. FortiClient EMS can share ZTNA tags across multiple devices in the Fabric, such as FortiGate, FortiManager, and FortiAnalyzer. FortiClient EMS can also share ZTNA tags across multiple VDOMs on the same FortiGate device. FortiClient EMS can be configured to control the ZTNA tag sharing behavior in the Fabric Devices settings1.
FortiGate is the device that enforces ZTNA policies using ZTNA tags. FortiGate can receive ZTNA tags from FortiClient EMS via Fabric Connector. FortiGate can also publish ZTNA services through the ZTNA portal, which allows users to access applications without installing FortiClient. FortiGate can also provide ZTNA inline CASB for SaaS application access control2.
FortiGate Access Proxy is a feature that enables FortiGate to act as a proxy for ZTNA traffic. FortiGate Access Proxy can be deployed in front of the application servers to provide ZTNA protection. FortiGate Access Proxy can also be deployed behind the application servers to provide ZTNA visibility. FortiGate Access Proxy can use ZTNA tags to identify and authenticate users and devices2.
FortiClient is the endpoint software that connects to ZTNA services. FortiClient can register ZTNA tags with FortiClient EMS based on the endpoint security posture. FortiClient can also use ZTNA tags to access ZTNA services published by FortiGate. FortiClient can also use ZTNA tags to access SaaS applications with ZTNA inline CASB2.
References :=
* Technical Tip: Behavior of ZTNA Tags shared across multiple vdoms or multiple FortiGate firewalls in the Security Fabric connected to the same FortiClient EMS Server
* Synchronizing FortiClient ZTNA tags
* Zero Trust Network Access (ZTNA) to Control Application Access
質問 # 32
Refer to the exhibits.

Based on the FortiGate Security Fabric settings shown in the exhibits, what must an administrator do on the EMS server to successfully quarantine an endpoint. when it is detected as a compromised host (loC)?
- A. The administrator must authorize FortiGate on FortiAnalyzer.
- B. The administrator must enable remote HTTPS access to EMS.
- C. The administrator must enable SSH access to EMS.
- D. The administrator must enable FQDN on EMS.
正解:B
解説:
Based on the FortiGate Security Fabric settings shown in the exhibits, to successfully quarantine an endpoint when it is detected as a compromised host (IOC), the following step is required:
Enable Remote HTTPS Access to EMS: This setting allows FortiGate to communicate securely with FortiClient EMS over HTTPS. Remote HTTPS access is essential for the quarantine functionality to operate correctly, enabling the EMS server to receive and act upon the quarantine commands from FortiGate.
Therefore, the administrator must enable remote HTTPS access to EMS to allow the quarantine process to function properly.
Reference
FortiGate Infrastructure 7.2 Study Guide, Security Fabric and Integration with EMS Sections Fortinet Documentation on Enabling Remote HTTPS Access to FortiClient EMS
質問 # 33
Exhibit.
Refer to the exhibits, which show the Zero Trust Tag Monitor and the FortiClient GUI status.
Remote-Client is tagged as Remote-User* on the FortiClient EMS Zero Trust Tag Monitor.
What must an administrator do to show the tag on the FortiClient GUI?
- A. Change the FortiClient system settings to enable lag visibility.
- B. Update tagging rule logic to enable tag visibility.
- C. Change the FortiClient EMS shared settings to enable tag visibility.
- D. Change the endpoint alerts configuration to enable tag visibility.
正解:D
解説:
* Observation of Exhibits:
* The exhibits show the Zero Trust Tag Monitor on FortiClient EMS and the FortiClient GUI status.
* Remote-Client is tagged as "Remote-Endpoints" on the FortiClient EMS Zero Trust Tag Monitor.
* Enabling Tag Visibility:
* To show the tag on the FortiClient GUI, the endpoint alerts configuration must be adjusted to enable tag visibility.
* Verification:
* The correct action is to change the endpoint alerts configuration to enable tag visibility, ensuring that the tag appears in the FortiClient GUI.
References:
* FortiClient EMS and FortiClient configuration documentation from the study guides.
質問 # 34
Refer to the exhibits.

Which shows the configuration of endpoint policies.
Based on the configuration, what will happen when someone logs in with the user account student on an endpoint in the trainingAD domain?
- A. FortiClient EMS will assign the Training policy
- B. FortiClient EMS will assign the Sales policy
- C. FortiClient EMS will assign the Training policy for on-fabric endpoints and the Sales policy for the off- fabric endpoint
- D. FortiClient EMS will assign the Default policy
正解:A
解説:
Based on the configuration shown in the exhibits:
* There are three endpoint policies configured: Training, Sales, and Default.
* The "Training" policy is assigned to the "trainingAD.training.lab" group.
* The "Sales" policy is assigned to "All Groups" and "trainingAD.training.lab/student."
* The "Default" policy has no specific groups assigned.
When someone logs in with the user account "student" on an endpoint in the "trainingAD" domain:
* The "Training" policy is specifically assigned to the "trainingAD.training.lab" group.
* The "Sales" policy includes "trainingAD.training.lab/student" but not the general "trainingAD.training.
lab" group.
* The system will prioritize the most specific match for the group.
Therefore, FortiClient EMS will assign the "Training" policy to the "student" account logging into the
"trainingAD" domain as it matches the group "trainingAD.training.lab" directly.
References
* FortiClient EMS 7.2 Study Guide, Endpoint Policy Configuration Section
* FortiClient EMS Documentation on Group Policy Assignment and Matching
質問 # 35
Which component or device shares ZTNA tag information through Security Fabric integration?
- A. FortiGate
- B. FortiGate Access Proxy
- C. FortiClient
- D. FortiClient EMS
正解:D
解説:
FortiClient EMS is the component that shares ZTNA tag information through Security Fabric integration. ZTNA tags are synchronized from FortiClient EMS as inputs for the FortiGate application gateway. They can be used in ZTNA policies as security posture checks to ensure certain security criteria are met. FortiClient EMS can share ZTNA tags across multiple devices in the Fabric, such as FortiGate, FortiManager, and FortiAnalyzer. FortiClient EMS can also share ZTNA tags across multiple VDOMs on the same FortiGate device. FortiClient EMS can be configured to control the ZTNA tag sharing behavior in the Fabric Devices settings1.
FortiGate is the device that enforces ZTNA policies using ZTNA tags. FortiGate can receive ZTNA tags from FortiClient EMS via Fabric Connector. FortiGate can also publish ZTNA services through the ZTNA portal, which allows users to access applications without installing FortiClient. FortiGate can also provide ZTNA inline CASB for SaaS application access control2.
FortiGate Access Proxy is a feature that enables FortiGate to act as a proxy for ZTNA traffic. FortiGate Access Proxy can be deployed in front of the application servers to provide ZTNA protection. FortiGate Access Proxy can also be deployed behind the application servers to provide ZTNA visibility. FortiGate Access Proxy can use ZTNA tags to identify and authenticate users and devices2.
FortiClient is the endpoint software that connects to ZTNA services. FortiClient can register ZTNA tags with FortiClient EMS based on the endpoint security posture. FortiClient can also use ZTNA tags to access ZTNA services published by FortiGate. FortiClient can also use ZTNA tags to access SaaS applications with ZTNA inline CASB2.
Reference:
Technical Tip: Behavior of ZTNA Tags shared across multiple vdoms or multiple FortiGate firewalls in the Security Fabric connected to the same FortiClient EMS Server Synchronizing FortiClient ZTNA tags Zero Trust Network Access (ZTNA) to Control Application Access
質問 # 36
When site categories are disabled in FortiClient web filter, which feature can be used to protect the endpoint from malicious web access?
- A. Block malicious websites on antivirus
- B. Web exclusion list
- C. Real-time protection list
- D. FortiSandbox URL list
正解:B
解説:
Web Filter Functionality:
When site categories are disabled in the FortiClient web filter, the endpoint still requires protection from malicious web access.
Alternative Protection Features:
The web exclusion list can be used to manage and block specific URLs that are known to be malicious, providing a way to control and secure web access even without site categories being enabled.
Conclusion:
The correct feature that can be used to protect the endpoint in this scenario is the web exclusion list (D).
Reference:
FortiClient web filter configuration and features from the study guides.
質問 # 37
An administrator configures ZTNA configuration on theFortiGate. Which statement is true about the firewall policy?
- A. It redirects the client request to the access proxy.
- B. It defines ZTNA server.
- C. It only uses ZTNA tags to control access for endpoints.
- D. It uses the access proxy.
正解:A
解説:
"The firewall policy matches and redirects client requests to the access proxy VIP"https://docs.fortinet.com/document/fortigate/7.0.0/new-features/194961/basic-ztna-configuration
質問 # 38
Which statement about FortiClient enterprise management server is true?
- A. It provides centralized management of Chromebooks running real-time protection
- B. lt provides centralized management of multiple endpoints running FortiClient software.
- C. It provides centralized management of FortiGate devices.
- D. It provides centralized management of FortiClient Android endpoints only.
正解:B
解説:
FortiClient EMS is designed to provide centralized management and control of multiple endpoints running FortiClient software. It serves as a central management server that allows administrators to efficiently manage and configure a large number of FortiClient installations across the network.
質問 # 39
When site categories are disabled in FortiClient web filter, which feature can be used to protect the endpoint from malicious web access?
- A. Block malicious websites on antivirus
- B. Web exclusion list
- C. Real-time protection list
- D. FortiSandbox URL list
正解:B
質問 # 40
Which security fabric component sends a notification to quarantine an endpoint after IOC detection in the automation process?
- A. FortiAnalyzer
- B. ForbClient EMS
- C. FortiClient
- D. Forti Gate
正解:D
質問 # 41
......
検証済み材料を使うならまずFCP_FCT_AD-7.2テストエンジンを試そう:https://jp.fast2test.com/FCP_FCT_AD-7.2-premium-file.html