Sign In
Home/Fortinet/FortiClient EMS 7.4 Administrator/Free questions

Fortinet NSE 6 - FortiClient EMS 7.4 Administrator — Free Practice Questions

10 free sample questions from a bank of 50, with the correct answers and explanations. No signup required — start practising right now.

1An administrator is configuring a zero trust network access (ZTNA) access proxy solution to share endpoint information with a FortiGate device.Which two configuration actions will achieve this solution? (Choose two.)
  • Add the FortiGate IP address to the Fabric device configurations on FortiClient EMS.
  • Authorize FortiGate on FortiClient EMS as a Fabric connector.
  • Use the FortiClient EMS connector on FortiGate to connect to FortiClient EMS.
  • Apply the ZTNA license on FortiGate.
Answer: B, C

The short version

B and C — share endpoint intel via EMS-side FortiGate authorization plus the FortiGate-side EMS connector. Authorize there, connect here.

Key concepts in this question

  • Fabric connector authorization on EMS admits FortiGate.
  • The EMS connector on FortiGate pulls endpoint data including ZTNA posture.

Why B and C are correct

Two-sided pairing is the documented ZTNA-sharing setup.

Why the others are wrong

  • A. Fabric device IPs alone do not establish the connector pairing.
  • D. ZTNA licensing enables features; it does not share data.

FortiClient EMS exam tip

Share endpoint intel = authorize + connect.

2An administrator installs FortiClient on Windows Server.What is the default behavior of real-time protection control?
  • Real-time protection must update AV signature database
  • Real-time protection sends malicious files to FortiSandbox when the file is not detected locally
  • Real-time protection is disabled
  • Real-time protection must update the signature database from FortiSandbox
Answer: C

The short version

C — real-time protection ships disabled on Windows Server. Server workloads opt in deliberately.

Key concepts in this question

  • Windows Server defaults disable real-time AV to protect server performance.
  • Signature updates and sandbox submission are separate behaviors.

Why C is correct

Disabled-by-default is the documented server-install behavior.

Why the others are wrong

  • A. Signature updates are independent of the enablement default.
  • B. Sandbox submission is a detection-action setting, not the default state.
  • D. FortiSandbox does not supply signature updates.

FortiClient EMS exam tip

Windows Server install = RTP off by default.

3Refer to the exhibit. Why is the endpoint tagged as indicator of compromise (IOC) suspicious?
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator question 3
  • The endpoint hq-pc-1 is tagged with the security posture tag IOC suspicious.
  • The FortiClient EMS fabric connector is configured on FortiAnalyzer.
  • The FortiClient EMS administrator manually tagged it using the console.
  • The administrator student1 on FortiAnalyzer executed the playbook.
Answer: D

The short version

D — approved. The exhibit log line FAZ tagged hq-pc-1 as [IOC Suspicious] beside the student1 sessions shows a FortiAnalyzer-driven tag, matching a playbook execution rather than an EMS posture or manual tag.

Key concepts in this question

  • IOC tagging via FortiAnalyzer: FAZ playbooks push IOC verdicts to EMS endpoints.
  • Log correlation: the FAZ tag event sits between student1 logout/login lines, tying it to that operator session.
  • Posture tags vs IOC tags: Zero Trust posture tags come from EMS rule sets, not from FAZ.

Why D is correct

  • The highlighted message source is the FAZ integration tagging hq-pc-1 as IOC Suspicious.
  • The surrounding Console lines place administrator student1 on the box at the identical timestamp, consistent with executing the FAZ playbook.
  • FortiClient EMS 7.4 administration documentation describes IOC suspicious state arriving via the FortiAnalyzer fabric/playbook path.

Why the others are wrong

  • A. No security posture (Zero Trust tagging rule) event is shown; the tag source is FAZ, not an EMS posture tag.
  • B. The direction is reversed: nothing shows an EMS fabric connector configured on FortiAnalyzer, and that would not itself tag the endpoint.
  • C. There is no manual console-tagging action in the log; the actor recorded is FAZ.

FCP_FCT_AD-7.4 exam tip

FAZ tagged as IOC Suspicious = playbook did it, not EMS posture.

4Refer to the exhibit. Based on the settings shown in the exhibit, which two actions must the administrator take to make the endpoint compliant? (Choose two.)
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator question 4
  • Enable the web filter profile.
  • Run Calculator application on the endpoint.
  • Integrate FortiSandbox tor infected file analysis
  • Patch applications that have vulnerability rated as high or above.
Answer: B, D

The short version

B and D — approved. The Sales Department Compliance rule set demands a running Calculator process and no medium-or-higher vulnerabilities, so the endpoint must run Calculator and patch qualifying apps.

Key concepts in this question

  • Zero Trust tagging rules as compliance gates: running-process and vulnerability-severity rules must all pass.
  • Vulnerable Devices Severity Level: Medium or higher means high/critical items fail compliance.
  • Running Process rule: the named executable must be active on the endpoint.

Why B and D are correct

  • The exhibit lists Running Process: Calcualtor.exe, so launching Calculator satisfies that rule (B).
  • The exhibit lists Vulnerable Devices Severity Level: Medium or higher, so patching high-or-above apps clears that rule (D).
  • No other rule types appear in the exhibit, so these two actions are exactly what compliance needs.

Why the others are wrong

  • A. No web filter rule exists in this rule set, so enabling a web filter profile changes nothing.
  • C. No sandbox-analysis rule exists in this rule set, and the typo-laden option is unrelated to the shown rules.

FCP_FCT_AD-7.4 exam tip

Compliance exhibit = satisfy literally the rules you see: process running, vulns patched.

5Which two statements about FortiClient EMS integration with Active Directory (AD) are true?(Choose two.)
  • FortiClient EMS has full read-write access on the AD server.
  • FortiClient installations on domain endpoints can deployed from FortiClient EMS.
  • Endpoint profiles can be assigned to endpoints based on domain groups.
  • Imported AD endpoints cannot be directly deleted on FortiClient EMS.
Answer: C, D

The short version

C and D — AD integration assigns profiles by domain group and preserves imported endpoints from direct deletion. Group-driven profiles, protected imports.

Key concepts in this question

  • Domain-group profile assignment targets policies by AD membership.
  • Imported AD endpoints cannot be deleted directly (AD owns the record).

Why C and D are correct

The two documented AD-integration truths.

Why the others are wrong

  • A. EMS holds read-only AD access, not read-write.
  • B. Domain-push deployment is not the integration mechanism.

FortiClient EMS exam tip

AD + EMS = group profiles on, direct deletes off.

6Refer to the exhibit, which shows the Zero Trust Tagging Rule Set configuration.Which two statements about the rule set are true? (Choose two.)
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator question 6
  • The endpoint must satisfy that only Windows 10 is running.
  • The endpoint must satisfy that only AV software is installed and running.
  • The endpoint must satisfy that antivirus is installed and running and Windows 10 is running.
  • The endpoint must satisfy that only Windows Server 2012 R2 is running.
Answer: C, D

The short version

C and D — approved. Rule Logic (1 and 3) or 2 means the tag applies when AV-plus-Windows-10 holds, or independently when Windows Server 2012 R2 holds.

Key concepts in this question

  • Zero Trust tagging Rule Logic: numbered rules combine with AND/OR expressions.
  • Compound condition (1 and 3): AV installed/running together with Windows 10.
  • Standalone condition (2): Windows Server 2012 R2 alone suffices.

Why C and D are correct

  • C restates the first sufficient branch exactly: antivirus installed and running (1) AND Windows 10 running (3).
  • D restates the second sufficient branch exactly: Windows Server 2012 R2 running (2) alone.
  • The exhibit's numbered rules and logic string leave no other reading.

Why the others are wrong

  • A. Windows 10 alone is insufficient; rule 1 (AV) must also hold per (1 and 3).
  • B. AV alone is insufficient; rule 3 (Windows 10) must also hold unless rule 2 matches.

FCP_FCT_AD-7.4 exam tip

Read the Rule Logic line first: (1 and 3) or 2 gives two winning combos.

7Refer to the exhibits. Which shows the configuration of endpoint policies.Based on the configuration, what will happen when someone logs in with the user account student on an endpoint in the trainingAD domain?
  • FortiClient EMS will assign the Sales policy
  • FortiClient EMS will assign the Training policy
  • FortiClient EMS will assign the Default policy
  • FortiClient EMS will assign the Training policy for on-fabric endpoints and the Sales policy for the off-fabric endpoint
Answer: B

The short version

B — the student/trainingAD login maps to the Training policy. Domain-user match wins.

Key concepts in this question

  • Endpoint policies match on user and domain criteria.
  • student-in-trainingAD satisfies the Training policy scope (Q15 confirms the same mapping).

Why B is correct

User-plus-domain matching assigns Training — consistent across both duplicate questions.

Why the others are wrong

  • A. Sales scope does not match this user/domain.
  • C. Default applies only when nothing matches.
  • D. Single-policy assignment results; no split assignment occurs.

FortiClient EMS exam tip

User + domain match = named policy, not Default.

8An administrator wants to simplify remote access without asking users to provide user credentials Which access control method provides this solution?
  • ZTNA full mode
  • SSL VPN
  • L2TP
  • ZTNA IP/MAC littering mode
Answer: A

The short version

A — credential-less remote access is ZTNA full mode. Identity and posture replace passwords.

Key concepts in this question

  • ZTNA full mode brokers access on certificate identity plus posture.
  • VPN transports still demand credentials.

Why A is correct

Passwordless brokering is the documented ZTNA-full-mode outcome.

Why the others are wrong

  • B. SSL VPN requires user credentials.
  • C. L2TP requires credentials.
  • D. IP/MAC filtering modes still layer credential checks.

FortiClient EMS exam tip

No credentials = ZTNA full mode.

9Refer to the exhibit. Based on the settings shown in the exhibit, which statement about FortiClient behaviour is true?
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator question 9
  • FortiClient quarantines infected files and reviews later, after scanning them.
  • FortiClient blocks and deletes infected files after scanning them.
  • FortiClient scans infected files when the user copies files to the Resources folder.
  • FortiClient copies infected files to the Resources folder without scanning them.
Answer: D

The short version

D — approved (flip from bank A). The exhibit's Exclusions list contains C:\Desktop\Resources\, so files copied there skip scanning and land without inspection.

Key concepts in this question

  • Antivirus exclusions: listed files/folders are skipped by on-download/on-copy scans.
  • Scan-on-download scope: Scan files as they are downloaded or copied applies except where excluded.
  • Exhibit-first reading: the Resources path is the only setting distinguishing the options.

Why D is correct

  • The profile checks scanning on download/copy AND excludes C:\Desktop\Resources\.
  • An infected file copied into that excluded folder is therefore copied without being scanned.
  • D is the only option describing this exclusion behavior shown in the exhibit.

Why the others are wrong

  • A. Quarantine-after-scan cannot happen inside an excluded path that is never scanned.
  • B. Nothing is blocked or deleted here; the file lands unscanned because of the exclusion.
  • C. The exclusion means the opposite: files copied to Resources are NOT scanned there.

FCP_FCT_AD-7.4 exam tip

Excluded folder + infected file = copied, never scanned.

10A FortiClient EMS administrator has created multiple deployment configurations, and the endpoint is eligible to receive all of them. Which two factors determine which deployment configuration FortiClient EMS applies to the endpoint? (Choose two.)
  • A name of the deployment configuration in alphabetical order.
  • A priority level of the deployment configuration.
  • A status of the deployment configuration.
  • A scheduled time configured on the deployment configuration.
Answer: B, C

The short version

B and C — competing deployment configs resolve by priority level and enabled status. Ranked, then live-only.

Key concepts in this question

  • Priority level orders overlapping deployment configurations.
  • Status gates whether a config participates at all.

Why B and C are correct

Priority-plus-status is the documented resolution pair.

Why the others are wrong

  • A. Alphabetical names never decide assignment.
  • D. Schedules trigger timing, not selection.

FortiClient EMS exam tip

Config clash = priority, then status.

Want the full bank of 50 questions for Fortinet NSE 6 - FortiClient EMS 7.4 Administrator? See all practice exams.