Fortinet free flashcards

Free FCP-FGT-AD flashcards

8 real FCP-FGT-AD flashcards, sampled across every domain the exam tests. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.

The full deck has 461 flashcards. For a domain-by-domain breakdown and a study plan, read the FCP-FGT-AD study guide.

ConceptDeployment and system configuration

Which FortiGate setting changes the device identifier shown both at the CLI prompt and in the GUI dashboard system information widget?

The hostname configured under system global. FortiOS substitutes this value into the CLI prompt and displays it in the dashboard system information widget, so giving each unit its own hostname removes the ambiguity caused by identical defaults.

MisconceptionDeployment and system configuration

Configuring a second heartbeat interface on the WAN port will force the cluster to switch units when that link fails.

This confuses heartbeat with port monitoring. Heartbeat interfaces detect peer reachability between cluster members, not the up or down state of a data interface like the WAN port, so they will not react to a WAN link failure.

ConceptFirewall policies and authentication

In FSSO DC agent mode, what must be installed on each monitored domain controller, and what does it do?

A DC agent (dcagent.dll) is loaded on each domain controller and intercepts user logon events in real time, forwarding them to the collector agent. The collector then sends consolidated user-to-IP-to-group mappings to the FortiGate. This per-controller agent is what separates DC agent mode from agentless polling.

MisconceptionFirewall policies and authentication

For FSSO DC agent mode, you install a collector agent on every domain controller so each one independently sends user-to-IP mappings to the FortiGate.

Tempting because the collector agent is central to FSSO, but in DC agent mode the collector is a single (or redundant) service that aggregates events from the DC agents, not a per-controller component that talks to the FortiGate on its own.

ConceptContent inspection

When a flow-based firewall policy references a web filter profile configured for proxy-based inspection, what determines how the web filtering actually runs?

The firewall policy inspection mode is authoritative for the security profiles it applies. A flow-based policy executes the referenced web filter profile using flow-based inspection, so proxy-specific options map to their flow equivalent or are not enforced, rather than forcing the policy into proxy mode or dropping traffic.

MisconceptionContent inspection

Believing the web filter profile's own proxy-based setting takes precedence, so FortiGate applies it as proxy regardless of the policy's flow-based mode.

Tempting because it assumes the profile's own inspection mode wins, but the policy inspection mode governs how security profiles run, so a flow-based policy cannot execute a proxy-based profile as proxy.

ConceptRouting

Two static default routes exit different ISP links with the same administrative distance and the same priority. How does FortiGate treat traffic on the default route?

FortiGate first compares administrative distance to decide which routes enter the table, then compares priority among same-distance routes. With both values equal the routes are equal-cost, so FortiGate installs both and uses ECMP to spread sessions across the two links.

MisconceptionRouting

Two equal default routes get installed, but only the most recently configured one forwards traffic until it fails over to the other.

This describes failover, which is tempting but wrong: equal routes do not behave as an active and passive pair when distance and priority match. Active/passive failover requires differing priority or distance, otherwise both routes forward together via ECMP.

Get all 461 FCP-FGT-AD flashcards free

Drop your email and we will keep you posted as new FCP-FGT-AD study material ships. No spam - we mail you only when it is worth your time.

Frequently asked questions

Are these FCP-FGT-AD flashcards free?

Yes. Every card on this page is free to read with no sign-up. The full deck has 461 flashcards; drop your email below and we will keep you posted, or create a free account to study the rest.

What is a misconception card?

A card built from a tempting wrong answer in our question bank, naming the trap and explaining why it fails. Most flashcard decks only drill the fact (a concept card); we pair each one with the misconception the exam actually tests you against.

Are these real FCP-FGT-AD exam questions or vendor content?

No. These are original flashcards written from our own blueprint-aligned practice questions. We never reproduce live exam items or vendor material.

How many flashcards are in the full FCP-FGT-AD deck?

461 cards spread across all 5 domains. For the full domain-by-domain breakdown, read the study guide.

Examworthy is not affiliated with or endorsed by Fortinet. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. FCP-FGT-AD and related marks belong to their respective owners.