Fortinet • FCP_FMG_AD-7.6
Validates the ability to centrally manage multiple FortiGate devices using FortiManager, covering administration, device registration, policy and object management, advanced configuration, and troubleshooting. Designed for network and security analysts responsible for day-to-day management of FortiGate security policies via FortiManager.
Questions
600
Duration
70 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
May 2026
The FCP – FortiManager 7.6 Administrator (FCP_FMG_AD-7.6) certification validates a professional's ability to centrally manage multiple FortiGate devices using Fortinet's FortiManager platform. The exam tests applied knowledge across the full FortiManager administrative lifecycle, including initial system configuration, administrative domain (ADOM) management, device registration and synchronization, centralized policy and object management, FortiGuard services integration, high availability configuration, logging, reporting, and troubleshooting at both device and system levels. The exam is based on FortiManager 7.6.1 and FortiOS 7.6, ensuring relevance to current production deployments.
This certification is a recognized elective within the Fortinet Certified Professional (FCP) – Network Security track. To earn the FCP – Network Security designation, candidates must pass a core exam (FCP – FortiGate Administrator) plus one elective; FCP_FMG_AD-7.6 fulfills that elective requirement. Effective July 15, 2026, the associated course and exam will transition from the NSE 5 – Secure Networking track to the NSE 6 – Secure Networking track, reflecting its increasing depth and specialization.
This certification is designed for network and security analysts, firewall administrators, and security engineers who are responsible for the day-to-day centralized management of FortiGate security policies and device configurations through FortiManager. It is particularly well-suited to professionals working in environments with multiple FortiGate devices, such as large enterprises, managed service providers (MSPs) managing multiple customer tenants, and organizations with distributed branch deployments.
Candidates typically hold roles such as Network Security Administrator, Security Operations Center (SOC) Analyst, Firewall Engineer, or IT Security Specialist. Those pursuing advancement into senior roles—such as Network Security Architect or Fortinet Consultant—also benefit from this credential as a step toward higher-level Fortinet certification tracks.
There are no formal prerequisites to register for or sit the FCP_FMG_AD-7.6 exam. However, Fortinet strongly recommends that candidates possess prerequisite knowledge of all topics covered in the FortiGate Administrator course, as FortiManager operations are deeply integrated with FortiGate configuration concepts. Hands-on familiarity with FortiGate device administration, security policy management, and basic networking fundamentals (routing, VLANs, firewall rules) is essential for success.
Fortinet's official training recommendation is completion of the FortiManager Administrator instructor-led course (7 lecture hours, 6 lab hours across approximately two days), which covers the exact domains tested in the exam. Candidates with 6–12 months of practical experience managing FortiGate devices in a production environment—particularly those who have worked with centralized management tools—are well-positioned to attempt this exam.
The FCP_FMG_AD-7.6 exam consists of 35 multiple-choice questions to be completed within 70 minutes. Questions are either single-selection or multiple-selection format. Fortinet's scoring policy requires that all selected answers in a multiple-selection question must be correct to receive credit for that question—no partial credit is awarded. Incorrect answers do not incur a score penalty.
The exam is delivered in English and Japanese through Pearson VUE, available at Pearson VUE test centers worldwide as well as via online proctoring (OnVUE) for remote candidates. The exam result is reported as Pass or Fail; no numerical score is disclosed. The exam fee is $200 USD.
Earning the FCP – FortiManager 7.6 Administrator credential positions professionals for roles directly responsible for enterprise-scale network security operations, including Network Security Administrator, Firewall Engineer, SOC Analyst, and MSP Security Engineer. Fortinet holds a leading market share in the network security space, and organizations running Fortinet Security Fabric deployments increasingly require administrators who can operate FortiManager at scale. Certified professionals with Fortinet FCP credentials typically command salaries in the range of $80,000 to $135,000 annually in the United States, depending on experience level and geography, with senior architects and consultants often exceeding those figures.
The FCP_FMG_AD-7.6 is particularly valuable for MSP engineers managing multiple customer environments through FortiManager's multi-ADOM architecture, and for enterprise administrators tasked with consolidating security policy management across distributed branch networks. Compared to vendor-neutral certifications, this credential provides immediate, role-specific validation that hiring managers at Fortinet-centric organizations directly recognize. The certification aligns with the NICE Cybersecurity Workforce Framework, supporting applicability in federal and government-sector hiring contexts.
5 sample questions with correct answers and explanations. Start a practice session to test yourself across all 600 questions.
1. A Contoso organization deploys centralized SD-WAN management through FortiManager for 45 branch offices. Each branch has both an MPLS private circuit and a broadband internet connection available. The primary application requiring SD-WAN traffic steering is a real-time VoIP system that is critically sensitive to latency, jitter, and packet loss. Which SD-WAN steering strategy should the administrator configure in FortiManager for the VoIP traffic rule? (Select one!)
Explanation
The Best Quality steering strategy in FortiManager SD-WAN Orchestrator continuously measures actual link performance — latency, jitter, and packet loss — and dynamically routes traffic via the link delivering the best current quality. VoIP applications are uniquely sensitive to these three metrics: high latency causes conversational delays, jitter causes voice breakup and distortion, and packet loss causes audible gaps or call drops. Best Quality ensures VoIP traffic always routes via the highest-performing available path and automatically switches if conditions degrade on the preferred link. Lowest Cost (SLA) selects the cheapest link meeting defined SLA thresholds — even if the MPLS circuit delivers significantly better quality, traffic may route via the cheaper broadband link as long as it technically meets minimum thresholds, which is insufficient for optimal VoIP. Maximize Bandwidth (SLA) is designed for throughput-intensive applications like large file transfers and distributes sessions across multiple links, which can introduce per-packet path inconsistency harmful to real-time voice. Manual steering uses static weights that cannot respond to dynamic link quality fluctuations, meaning VoIP continues routing via a degraded link until an administrator manually intervenes.
2. A Contoso administrator is configuring centralized SD-WAN management through FortiManager 7.2 for 30 branch offices. The branches run latency-sensitive VoIP and video conferencing applications that must always be routed over the WAN link with the best real-time performance — lowest measured latency, jitter, and packet loss. Which SD-WAN steering strategy should be configured for these traffic classes? (Select one!)
Explanation
Best Quality steering dynamically evaluates all available WAN links by measuring real-time latency, jitter, and packet loss, then selects the link with the best combination of these metrics for each traffic class. This is the optimal strategy for real-time sensitive applications such as VoIP and video conferencing, where even brief degradation in any metric can cause perceptible quality degradation such as echo, choppy audio, or frozen video. Lowest Cost (SLA) selects the cheapest link that meets minimum SLA thresholds — this may keep traffic on a link that is technically compliant but not performing optimally, making it unsuitable for real-time media applications. Manual steering uses fixed priorities or weights that do not adapt to changing WAN conditions, creating risk of routing VoIP over a degraded link during WAN events. Maximize Bandwidth (SLA) is designed for bulk throughput scenarios where aggregate bandwidth matters more than per-flow latency consistency.
3. A Litware architect is planning a FortiManager VM-100 deployment. The managed environment includes 40 standalone FortiGate devices and 10 FortiGate Active-Passive HA clusters, where each cluster contains exactly 2 physical nodes. How many total device licenses will this deployment consume on FortiManager? (Select one!)
Explanation
Each managed FortiGate physical device or VM instance consumes exactly one device license on FortiManager regardless of whether it operates as a standalone unit, an HA primary, or an HA secondary. A 2-node Active-Passive HA cluster therefore consumes 2 device licenses, not 1 — both the primary node and the secondary node each require their own license. With 10 HA clusters of 2 nodes each, the HA portion alone consumes 20 device licenses. Adding the 40 standalone devices gives a total of 60 device licenses. This is a critical planning consideration: deploying HA doubles device license consumption compared to equivalent standalone deployments. The FMG-VM-100 tier supports up to 100 devices, so this 60-device environment fits within that license tier. Counting only primary nodes or treating a cluster as a single unit would lead to license shortfalls when FortiManager actually registers both physical nodes.
4. An Adatum security architect is hardening a new FortiManager deployment. When configuring a specific administrator account, the architect adds a single trusted host entry of 10.100.0.0/24. Which statement accurately describes the access control effect of this configuration? (Select one!)
Explanation
Trusted host entries on a FortiManager administrator account enforce source IP address restrictions for that specific account. Once at least one trusted host is configured, FortiManager permits login attempts only from source addresses that fall within the defined subnets. Any authentication attempt originating from an IP outside 10.100.0.0/24 is rejected outright — no warning is generated for the connecting client. Trusted hosts are an access control mechanism, not a monitoring feature, so SNMP has no relevance here. Each administrator's trusted host list is independent; entries on one account do not propagate to other accounts. An account with no trusted hosts configured allows access from any source.
5. A Fabrikam administrator needs to run a packet capture on the FortiManager management interface to troubleshoot FGFM tunnel connectivity. The output must include full packet content with headers, payload data, ASCII interpretation, and the capturing interface name. Which packet sniffer verbosity level should the administrator specify? (Select one!)
Explanation
The FortiManager packet sniffer supports verbosity levels 1 through 6. Level 6 provides the most comprehensive output, including IP and transport layer headers, the complete packet payload displayed in hexadecimal, an ASCII interpretation of the payload content, and the name of the interface on which each packet was captured. This maximum verbosity level is appropriate when full protocol analysis is required, such as examining FGFM handshake details or verifying TLS negotiation on TCP port 541. The command syntax is: `diagnose sniffer packet <interface> 'host <FortiGate-IP> and port 541' 6 <count>`. Level 1 provides only minimal header information and is insufficient for deep protocol analysis. Level 3 provides headers and hexadecimal data but does not include ASCII interpretation or the capturing interface name. Higher verbosity levels generate significantly more output and should be used with a count limit to avoid overwhelming the terminal session.
One-time access to this exam