Fortinet Enterprise Firewall 7.6 FCSS_EFW_AD-7.6 Web Filtering Application Control Practice Test
This practice test focuses on web filtering application control and isdb policy design through original applied scenarios aligned to the final published Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator 7.6 blueprint. It is intended for study and does not reproduce live exam content. For broader exam preparation, review the Fortinet FCSS_EFW_AD-7.6 Exam Dumps page.
Question 1
During an enterprise firewall change at Humongous Insurance, the team needs to block risky web categories while allowing approved business browsing. What should it do? The answer must address the stated cause rather than a different feature. Only one site is affected; peer sites are healthy.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Use the narrowest applicable ISDB service object and explicit policy scope
- Apply a web filter profile with explicit category actions to the matching policy
- Apply application control with the specific application or category action rather than relying only on TCP port
- Reference the appropriate Internet Service Database object in policy where the service is supported
Correct answer: C
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Web filtering enforces category and URL decisions on allowed web traffic. This directly addresses the stated requirement.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply a web filter profile with explicit category actions to the matching policy. Web filtering enforces category and URL decisions on allowed web traffic.
Question 2
A production review at Margie Travel identifies this requirement: block a prohibited application even when it uses common web ports. Which Fortinet action is most appropriate? Preserve the existing design unless the requirement says otherwise. The change must be validated on a pilot device before broader rollout.
- Apply application control with the specific application or category action rather than relying only on TCP port
- Apply a web filter profile with explicit category actions to the matching policy
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Reference the appropriate Internet Service Database object in policy where the service is supported
Correct answer: A
Explanation
- Application control identifies traffic beyond simple port numbers. This directly addresses the stated requirement.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply application control with the specific application or category action rather than relying only on TCP port. Application control identifies traffic beyond simple port numbers.
Question 3
While troubleshooting at Northwind Health, the network security architect needs to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually. What is the best next step? Prefer a change that is reversible and easy to verify. Existing production IP addressing must remain unchanged.
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Use the narrowest applicable ISDB service object and explicit policy scope
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: D
Explanation
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This directly addresses the stated requirement.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, reference the appropriate Internet Service Database object in policy where the service is supported. ISDB objects track service address ranges and can simplify policy for known Internet services.
Question 4
Blue Yonder Airlines is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to allow one required URL inside a category that is otherwise blocked? The team needs an auditable result. The resulting configuration must remain centrally auditable.
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply a web filter profile with explicit category actions to the matching policy
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply application control with the specific application or category action rather than relying only on TCP port
Correct answer: C
Explanation
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- A specific URL exception can refine a broad category decision without opening the entire category. This directly addresses the stated requirement.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a narrowly scoped static URL filter or override consistent with policy precedence. A specific URL exception can refine a broad category decision without opening the entire category.
Question 5
A change ticket for Trey Research states that administrators must investigate why an application remains unidentified in encrypted traffic. Which choice is correct? Use normal enterprise Fortinet administration practice. A known-good rollback point is available before the change.
- Apply a web filter profile with explicit category actions to the matching policy
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
Correct answer: E
Explanation
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify the policy, application-control profile, and SSL-inspection visibility available for the session. Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details.
Question 6
The security team at Apex Retail wants to avoid permitting an entire cloud provider when only one supported Internet service is required. Which configuration or operational action most directly satisfies that goal? Assume the platform versions are compatible with the feature. The design must preserve the current segmentation boundaries.
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Apply a web filter profile with explicit category actions to the matching policy
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use the narrowest applicable ISDB service object and explicit policy scope
Correct answer: E
Explanation
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the narrowest applicable ISDB service object and explicit policy scope. Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances.
Question 7
An incident at Proseware Media requires the NOC engineer to block risky web categories while allowing approved business browsing. What should be done first? No unrelated control should be weakened. The team is not allowed to disable the security feature globally.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply application control with the specific application or category action rather than relying only on TCP port
Correct answer: C
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Web filtering enforces category and URL decisions on allowed web traffic. This directly addresses the stated requirement.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply a web filter profile with explicit category actions to the matching policy. Web filtering enforces category and URL decisions on allowed web traffic.
Question 8
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at City Power & Light, which option correctly addresses the need to block a prohibited application even when it uses common web ports? The team will validate the result immediately after the change. The symptom appeared immediately after a planned configuration change.
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use the narrowest applicable ISDB service object and explicit policy scope
Correct answer: D
Explanation
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Application control identifies traffic beyond simple port numbers. This directly addresses the stated requirement.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply application control with the specific application or category action rather than relying only on TCP port. Application control identifies traffic beyond simple port numbers.
Question 9
VanArsdel has verified basic IP reachability. The remaining requirement is to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually. Which action should the team take? The change is taking place in a controlled maintenance window. Logs from the affected traffic are available for verification.
- Apply application control with the specific application or category action rather than relying only on TCP port
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
Correct answer: D
Explanation
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This directly addresses the stated requirement.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, reference the appropriate Internet Service Database object in policy where the service is supported. ISDB objects track service address ranges and can simplify policy for known Internet services.
Question 10
At Woodgrove Bank, the Fortinet administrator must allow one required URL inside a category that is otherwise blocked. Which action best addresses the requirement? Choose the smallest targeted change. The equivalent configuration works correctly at a separate site.
- Apply a web filter profile with explicit category actions to the matching policy
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Use a narrowly scoped static URL filter or override consistent with policy precedence
Correct answer: E
Explanation
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- A specific URL exception can refine a broad category decision without opening the entire category. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a narrowly scoped static URL filter or override consistent with policy precedence. A specific URL exception can refine a broad category decision without opening the entire category.
Question 11
During an enterprise firewall change at Alpine Ski House, the team needs to investigate why an application remains unidentified in encrypted traffic. What should it do? The answer must address the stated cause rather than a different feature. The change must be reversible within the same maintenance window.
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use a narrowly scoped static URL filter or override consistent with policy precedence
Correct answer: A
Explanation
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This directly addresses the stated requirement.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify the policy, application-control profile, and SSL-inspection visibility available for the session. Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details.
Question 12
A production review at Datum Corporation identifies this requirement: avoid permitting an entire cloud provider when only one supported Internet service is required. Which Fortinet action is most appropriate? Preserve the existing design unless the requirement says otherwise. The device is already synchronized with its central-management database.
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
Correct answer: E
Explanation
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the narrowest applicable ISDB service object and explicit policy scope. Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances.
Question 13
While troubleshooting at Contoso Finance, the NOC engineer needs to block risky web categories while allowing approved business browsing. What is the best next step? Prefer a change that is reversible and easy to verify. The current routing table contains the expected connected networks.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
- Apply application control with the specific application or category action rather than relying only on TCP port
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: E
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Web filtering enforces category and URL decisions on allowed web traffic. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply a web filter profile with explicit category actions to the matching policy. Web filtering enforces category and URL decisions on allowed web traffic.
Question 14
Litware Logistics is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to block a prohibited application even when it uses common web ports? The team needs an auditable result. Basic IP reachability to the remote endpoint has already been verified.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Apply application control with the specific application or category action rather than relying only on TCP port
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: B
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Application control identifies traffic beyond simple port numbers. This directly addresses the stated requirement.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply application control with the specific application or category action rather than relying only on TCP port. Application control identifies traffic beyond simple port numbers.
Question 15
A change ticket for Wide World Importers states that administrators must restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually. Which choice is correct? Use normal enterprise Fortinet administration practice. Hardware replacement is outside the approved change scope.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: B
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This directly addresses the stated requirement.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, reference the appropriate Internet Service Database object in policy where the service is supported. ISDB objects track service address ranges and can simplify policy for known Internet services.
Question 16
The security team at Relecloud wants to allow one required URL inside a category that is otherwise blocked. Which configuration or operational action most directly satisfies that goal? Assume the platform versions are compatible with the feature. The requirement applies only to one policy, peer, or managed device group.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Apply a web filter profile with explicit category actions to the matching policy
- Use the narrowest applicable ISDB service object and explicit policy scope
- Apply application control with the specific application or category action rather than relying only on TCP port
- Reference the appropriate Internet Service Database object in policy where the service is supported
Correct answer: A
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This directly addresses the stated requirement.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a narrowly scoped static URL filter or override consistent with policy precedence. A specific URL exception can refine a broad category decision without opening the entire category.
Question 17
An incident at Adventure Works requires the network operations engineer to investigate why an application remains unidentified in encrypted traffic. What should be done first? No unrelated control should be weakened. The team must avoid broadening administrative trust or permissions.
- Apply a web filter profile with explicit category actions to the matching policy
- Apply application control with the specific application or category action rather than relying only on TCP port
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Use the narrowest applicable ISDB service object and explicit policy scope
Correct answer: C
Explanation
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This directly addresses the stated requirement.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify the policy, application-control profile, and SSL-inspection visibility available for the session. Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details.
Question 18
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Fourth Coffee, which option correctly addresses the need to avoid permitting an entire cloud provider when only one supported Internet service is required? The team will validate the result immediately after the change. The design must preserve existing centralized logging and telemetry.
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply application control with the specific application or category action rather than relying only on TCP port
Correct answer: A
Explanation
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This directly addresses the stated requirement.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the narrowest applicable ISDB service object and explicit policy scope. Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances.
Question 19
Coho Winery has verified basic IP reachability. The remaining requirement is to block risky web categories while allowing approved business browsing. Which action should the team take? The change is taking place in a controlled maintenance window. Production subnets cannot be renumbered as part of this change.
- Apply a web filter profile with explicit category actions to the matching policy
- Apply application control with the specific application or category action rather than relying only on TCP port
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Use the narrowest applicable ISDB service object and explicit policy scope
- Use a narrowly scoped static URL filter or override consistent with policy precedence
Correct answer: A
Explanation
- Web filtering enforces category and URL decisions on allowed web traffic. This directly addresses the stated requirement.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply a web filter profile with explicit category actions to the matching policy. Web filtering enforces category and URL decisions on allowed web traffic.
Question 20
At Fabrikam Manufacturing, the enterprise firewall engineer must block a prohibited application even when it uses common web ports. Which action best addresses the requirement? Choose the smallest targeted change. A maintenance window is open, but service interruption must be minimized.
- Apply a web filter profile with explicit category actions to the matching policy
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply application control with the specific application or category action rather than relying only on TCP port
- Reference the appropriate Internet Service Database object in policy where the service is supported
Correct answer: D
Explanation
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
- Application control identifies traffic beyond simple port numbers. This directly addresses the stated requirement.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block a prohibited application even when it uses common web ports.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply application control with the specific application or category action rather than relying only on TCP port. Application control identifies traffic beyond simple port numbers.
Question 21
During an enterprise firewall change at Wingtip Energy, the team needs to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually. What should it do? The answer must address the stated cause rather than a different feature. The team must preserve existing certificate-trust relationships unless the requirement explicitly changes them.
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use the narrowest applicable ISDB service object and explicit policy scope
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: A
Explanation
- ISDB objects track service address ranges and can simplify policy for known Internet services. This directly addresses the stated requirement.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to restrict outbound access to a recognized SaaS provider without maintaining large static address lists manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, reference the appropriate Internet Service Database object in policy where the service is supported. ISDB objects track service address ranges and can simplify policy for known Internet services.
Question 22
A production review at Lucerne Publishing identifies this requirement: allow one required URL inside a category that is otherwise blocked. Which Fortinet action is most appropriate? Preserve the existing design unless the requirement says otherwise. The change will be reviewed later using the configuration and event audit trail.
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Apply a web filter profile with explicit category actions to the matching policy
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
Correct answer: D
Explanation
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
- A specific URL exception can refine a broad category decision without opening the entire category. This directly addresses the stated requirement.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to allow one required URL inside a category that is otherwise blocked.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a narrowly scoped static URL filter or override consistent with policy precedence. A specific URL exception can refine a broad category decision without opening the entire category.
Question 23
While troubleshooting at Bellows College, the network operations engineer needs to investigate why an application remains unidentified in encrypted traffic. What is the best next step? Prefer a change that is reversible and easy to verify. The chosen approach must continue to work as additional branch sites are added.
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: D
Explanation
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This directly addresses the stated requirement.
- Web filtering enforces category and URL decisions on allowed web traffic. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to investigate why an application remains unidentified in encrypted traffic.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, verify the policy, application-control profile, and SSL-inspection visibility available for the session. Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details.
Question 24
Tailspin Toys is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to avoid permitting an entire cloud provider when only one supported Internet service is required? The team needs an auditable result. A second engineer will verify the result using independent operational evidence.
- Use the narrowest applicable ISDB service object and explicit policy scope
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply application control with the specific application or category action rather than relying only on TCP port
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Reference the appropriate Internet Service Database object in policy where the service is supported
Correct answer: A
Explanation
- Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances. This directly addresses the stated requirement.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to avoid permitting an entire cloud provider when only one supported Internet service is required.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the narrowest applicable ISDB service object and explicit policy scope. Narrow service objects reduce unnecessary exposure compared with broad provider-wide allowances.
Question 25
A change ticket for Humongous Insurance states that administrators must block risky web categories while allowing approved business browsing. Which choice is correct? Use normal enterprise Fortinet administration practice. The team requires a deterministic rollback path if validation fails.
- Apply application control with the specific application or category action rather than relying only on TCP port
- Reference the appropriate Internet Service Database object in policy where the service is supported
- Use a narrowly scoped static URL filter or override consistent with policy precedence
- Verify the policy, application-control profile, and SSL-inspection visibility available for the session
- Apply a web filter profile with explicit category actions to the matching policy
Correct answer: E
Explanation
- Application control identifies traffic beyond simple port numbers. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- ISDB objects track service address ranges and can simplify policy for known Internet services. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- A specific URL exception can refine a broad category decision without opening the entire category. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Encrypted traffic can limit application identification when the inspection profile cannot expose the required protocol details. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to block risky web categories while allowing approved business browsing.
- Web filtering enforces category and URL decisions on allowed web traffic. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, apply a web filter profile with explicit category actions to the matching policy. Web filtering enforces category and URL decisions on allowed web traffic.