About the Fortinet FCP FortiGate Administrator Exam (FCP_FGT_AD-7.6)

Key Takeaways

  • The FCP FortiGate 7.6 Administrator exam (FCP_FGT_AD-7.6) consists of 50 multiple-choice questions administered in a 90-minute timed session via Pearson VUE.
  • Candidates are evaluated on a pass/fail scale based on minimum passing standards established by Fortinet, with earned credentials valid for 2 years.
  • Exam registration costs $200 USD and tests direct administrative competence against FortiOS 7.6.0 software features and CLI/GUI workflows.
  • The exam blueprint encompasses 7 core technical domains, led by System & VDOM Deployment (22%), Firewall Policies & NAT (18%), and Content Inspection & Security Profiles (18%).
  • Successful completion of FCP_FGT_AD-7.6 satisfies the core requirement for the Fortinet Certified Professional (FCP) in Network Security credential.
Last updated: July 2026

About the Fortinet FCP FortiGate Administrator Exam (FCP_FGT_AD-7.6)

Quick Summary: The Fortinet Certified Professional (FCP) in Network Security credential validates your ability to configure, administer, and troubleshoot FortiGate next-generation firewalls (NGFW) running FortiOS 7.6.0. The standalone core exam, FCP_FGT_AD-7.6 (FortiGate 7.6 Administrator), costs $200 USD, consists of 50 multiple-choice questions, carries a 90-minute time limit, and is administered globally via Pearson VUE test centers or online proctoring. Certification validity spans 2 years from the date of passing.


Certification Overview & Role Alignment

The Fortinet Certified Professional (FCP) in Network Security designation is designed for network security engineers, firewall administrators, systems integrators, and security analysts responsible for day-to-day configuration, monitoring, and operation of enterprise network security infrastructure based on Fortinet products.

Achieving the FCP in Network Security certification demonstrates that a candidate possesses practical, hands-on expertise in deploying FortiGate devices, establishing system administration profiles, building firewall policy matrices, implementing Network Address Translation (NAT), configuring high availability (HA) clusters, managing Virtual Domains (VDOMs), enforcing deep content inspection security profiles, routing traffic across complex topologies, and establishing secure IPsec/SSL VPN tunnels.

Under Fortinet's revised certification structure, the FCP_FGT_AD-7.6 exam serves as the core technical evaluation. Passing this exam proves mastery over FortiOS 7.6.0, the major operating system release underpinning Fortinet's Security Fabric architecture.


Exam Specifications & Logistics

The following table outlines the key administrative and technical logistics governing the FCP_FGT_AD-7.6 exam:

Specification ParameterOfficial Exam Standard
Exam NameFortinet Certified Professional — FortiGate 7.6 Administrator
Exam CodeFCP_FGT_AD-7.6
Target OS VersionFortiOS 7.6.0
Question Count50 multiple-choice and multiple-response questions
Exam Duration90 minutes (1.5 hours)
Registration Fee$200 USD (or equivalent local currency / 1 Fortinet Exam Voucher)
Delivery MethodPearson VUE Test Center or Online Proctored (OnVUE)
Scoring ModelPass / Fail (instant score report generated upon completion)
PrerequisitesNone mandatory (6+ months hands-on FortiGate administration recommended)
Credential Validity2 Years from pass date
Retake Waiting Period15 calendar days following an unsuccessful attempt

Official Exam Blueprint & Domain Weightings

The FCP_FGT_AD-7.6 exam measures candidate competency across 7 core technical domains. Questions range from fundamental operational syntax to complex troubleshooting scenarios involving CLI diagnostic outputs, GUI configuration panels, and log analyses.

Domain IDDomain TopicWeightingKey Competency Areas
1.0Deployment & System Configuration22%Initial setup, admin profiles, FortiGuard, firmware, VDOMs, Security Fabric, FGCP HA, logging & diagnostics
2.0Firewall Policies & NAT18%Policy matching order, object creation, Central NAT, SNAT IP pools, VIPs (DNAT)
3.0Content Inspection & Security Profiles18%Flow vs Proxy inspection, Antivirus, FortiSandbox, IPS sensors, Web Filtering, Application Control, DNS filtering
4.0Authentication & FSSO12%Local/remote auth (LDAP, RADIUS, SAML), 2FA, FSSO architecture & Collector Agent modes
5.0Routing & SD-WAN12%Static routing, policy routes, Reverse Path Forwarding (RPF), SD-WAN rules, SLA performance probes
6.0SSL VPN & IPsec VPN10%SSL VPN web & tunnel modes, IPsec Phase 1/Phase 2, dialup VPN, ADVPN topologies
7.0SSL/SSH Inspection8%Certificate inspection vs Deep SSL inspection, CA certificate deployment, port handling, exempt lists

Deep Dive: Core Technical Domains

1. Deployment & System Configuration (22%)

Candidates must demonstrate proficiency in executing initial FortiGate setup via CLI and Web-based Manager (GUI), configuring administrative users with custom Access Control Lists (ACLs) and Two-Factor Authentication (FortiToken), managing FortiGuard service contracts, performing safe firmware upgrades/downgrades, and configuring Virtual Domains (VDOMs) in split-task or multi-VDOM modes. Furthermore, candidates are evaluated on Fortinet Security Fabric integration, FortiGate Clustering Protocol (FGCP) High Availability election mechanics, active-passive heartbeat synchronizations, and system diagnostic logging.

2. Firewall Policies & NAT (18%)

This domain tests candidate knowledge of FortiOS packet processing logic. You must understand how firewall policies evaluate traffic based on source/destination interfaces, addresses, services, and schedules. Concepts include Central NAT vs interface-based NAT, Source NAT (SNAT) using outgoing interface IP or IP Pools (Overload, One-to-One, Fixed Port Range), and Destination NAT (DNAT) via Virtual IPs (VIPs) for server publishing.

3. Content Inspection & Security Profiles (18%)

Security profile evaluation forms the core of FortiGate next-generation protection. Candidates are tested on the operational trade-offs between Flow-based inspection (high throughput, pattern matching in memory) and Proxy-based inspection (full buffering, deep protocol parsing). Topics encompass Antivirus scanning engines, FortiSandbox cloud/on-prem integration, Intrusion Prevention System (IPS) anomaly detection and signature filters, Web Filtering URL categories and safe search enforcement, Application Control traffic shaping, and DNS Filtering botnet C&C domain blocking.

4. Authentication & Fortinet Single Sign-On (FSSO) (12%)

Security policy enforcement frequently relies on user identity. Candidates must understand local user database configuration as well as remote authentication integrations utilizing LDAP, RADIUS, and SAML 2.0. A significant portion of this domain focuses on FSSO architecture, distinguishing between Collector Agent mode (Active Directory domain controller agent polling) and Agentless polling mode (WinSec log polling directly by FortiGate).

5. Routing & SD-WAN (12%)

Network connectivity knowledge is mandatory. Candidates are evaluated on static route configuration (distance and priority metrics), policy-based routing (PBR) overrides, and Reverse Path Forwarding (RPF) checks (strict vs loose). Additionally, the domain tests Software-Defined Wide Area Network (SD-WAN) configuration, including SD-WAN member interfaces, Performance SLAs (latency, jitter, packet loss probes), and SD-WAN rules (Manual, Best Quality, Lowest Cost, Service/SLA).

6. SSL VPN & IPsec VPN (10%)

Remote access and site-to-site connectivity require mastery of VPN technologies. Candidates must understand SSL VPN operating modes (Web mode portal vs Tunnel mode with FortiClient), authentication mappings, and split tunneling. For IPsec VPN, candidates are tested on IKE Phase 1 proposals (Diffie-Hellman groups, authentication, encryption) and Phase 2 proposals (PFS, IPsec security associations), auto-key gateway settings, and Hub-and-Spoke / Auto-Discovery VPN (ADVPN) concepts.

7. SSL/SSH Inspection (8%)

Encrypted traffic inspection is required for effective malware and web content filtering. Candidates must understand the difference between Certificate Inspection (inspects only the SSL/TLS handshake server name indication) and Deep SSL Inspection (acts as a full inline proxy, decrypting and re-encrypting SSL payloads). Requirements include managing Custom Certificate Authorities (CAs), installing FortiGate CA certificates on endpoint trust stores, handling untrusted server certificates, and configuring SSL inspection exemptions for sensitive categories like banking or healthcare.


Examination Environment & Test-Taking Rules

When sitting for the FCP_FGT_AD-7.6 exam through Pearson VUE (either at an physical testing site or online via OnVUE), candidates must adhere to strict security protocols:

  1. Identification Requirements: Two forms of valid ID are required (primary must be government-issued with photo and signature).
  2. Non-Disclosure Agreement (NDA): Before commencing the exam, candidates must accept the Fortinet Candidate Agreement within 5 minutes.
  3. Item Review Feature: Candidates may flag questions for review and navigate backward/forward within the 90-minute time window before final submission.
  4. No Reference Materials: The exam is closed-book; no personal notes, devices, or scratch paper retainers may leave the room.

Official Fortinet Learning Resources

Fortinet provides official preparation paths through its learning ecosystem:

Loading diagram...
Fortinet FCP FortiGate Administrator Certification Flow
Test Your Knowledge

What is the official registration fee and total time allowed for the FortiGate 7.6 Administrator exam (FCP_FGT_AD-7.6)?

A
B
C
D
Test Your Knowledge

Which technical content domain represents the highest weight percentage on the official FCP_FGT_AD-7.6 exam blueprint?

A
B
C
D
Test Your Knowledge

How long does the Fortinet Certified Professional (FCP) in Network Security credential remain active before requiring recertification?

A
B
C
D