FSCP Exam Questions & Answers
Forescout Certified Professional • Forescout
100% money-back guarantee
Sample FSCP Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Policies will recheck when certain conditions are met. These may include...
Comprehensive and Detailed Explanation From Exact Extract of Forescout Platform Administration and Deployment:
According to theForescout Administration Guide, policies recheck when the following conditions are met:Policy recheck timer expires, admission event, or SC event change.
Policy Recheck Conditions:
According to the Main Rule Advanced Options documentation:
'By default, both matched endpoints and unmatched endpoints are rechecked every eight hours, and on any admission event.'
Additionally, according to the documentation:
'You can also configure several recheck settings to work simultaneously. For example, when a host IP address changes every five hours, recheck settings can be configured for:
Policy recheck timer expires- Default 8 hours
Admission events- Triggers like DHCP request, IP address change
SC (SecureConnector) event change- When SecureConnector status changes'
Three Main Policy Recheck Triggers:
According to the documentation:
Policy Recheck Timer Expires
Default: Every 8 hours
Can be customized (1 hour to infinite)
Applies to all endpoints matching or not matching the policy
Admission Event
DHCP Request
IP Address Change
Switch Port Change
Authentication event
VPN user connection
Immediate recheck when triggered
SC Event Change
SecureConnector deployed or removed
SecureConnector status changes (online/offline)
SecureConnector version changes
Why Other Options Are Incorrect:
A . Admission event, group name change, Scope recheck timer expires- Group name change is NOT a recheck trigger
C . Admission event, policy categorization, SC event change- Policy categorization is NOT a recheck trigger
D . Policy categorization, admission event, action schedule activation- Neither policy categorization nor action schedule activation triggers rechecks
E . Policy recheck timer expires, group name change, SC event change- Group name change does NOT trigger policy rechecks
Recheck Configuration:
According to the documentation:
'You can configure under what conditions to perform a recheck. By default, endpoints are rechecked every eight hours, and on any admission event. To define the recheck policy, you can configure:
Custom recheck interval (instead of 8 hours)
Which admission events trigger rechecks
Whether SecureConnector events trigger rechecks'
Referenced Documentation:
Main Rule Advanced Options
Forescout eyeSight policy main rule advanced options
When Are Policies Run - Policy Recheck section
Which of the following is true regarding CounterACT 8 FLEXX Licensing?
Comprehensive and Detailed Explanation From Exact Extract of Forescout Platform Administration and Deployment:
According to theForescout Licensing and Sizing Guide and Failover Clustering Licensing Requirements documentation, the correct statement is:For member appliances, HA and Failover Clustering are part of Resiliency licensing.
Resiliency Licensing for Member Appliances:
According to the Failover Clustering Licensing Requirements documentation:
'To begin working with Failover Clustering, you need a license for the feature. The license required depends on which licensing mode your deployment is using.'
When using FLEXX licensing with member appliances:
High Availability (HA)- Part of Resiliency licensing
Failover Clustering- Part of Resiliency licensing (called 'eyeRecover License')
Disaster Recovery- Separate from member appliance resiliency
Resiliency License Components:
According to the documentation:
'When using Flexx licensing, Failover Clustering functionality is supported by the Forescout Platform eyeRecover license (Forescout CounterACT Resiliency license).'
The Resiliency license covers:
For Member Appliances:
High Availability (HA) Pairing
Failover Clustering
For Enterprise Manager:
HA Pairing for EM
FLEXX Licensing Model:
According to the Licensing and Sizing Guide:
'Flexx Licensing: Licenses are independent of hardware appliances, providing an intuitive and flexible way to license, deploy and manage Forescout products across your extended enterprise.'
Why Other Options Are Incorrect:
A . Can be installed on all CTxx and 51xx models- FLEXX is for 5100/4100 series and later; CT series supports per-appliance licensing only
B . Disaster Recovery is used for member appliances- Disaster Recovery is separate; member appliances use HA/Failover Clustering from Resiliency license
D . Changing via Customer Portal- Changes from per-appliance to FLEXX must be done through official Forescout channels, not self-service Customer Portal
Which of the following properties can be determined by the HPS Plugin? (Choose two)
Comprehensive and Detailed Explanation From Exact Extract of Forescout Platform Administration and Deployment:
According to theForescout HPS Inspection Engine Configuration Guide and HPS Applications Plugin documentation, the properties that can be determined by the HPS Plugin are:Operating System (C) and HTTP banner (E).
HPS Plugin Capabilities:
According to the HPS Inspection Engine guide:
'The HPS (Host Property Scanner) Inspection Engine provides host properties for detecting endpoint characteristics including operating system, services, and applications.'
The HPS plugin determines:
Operating System- OS type, version, service pack level
HTTP Banner- Service versions from HTTP banner scanning
Services and Applications- Running processes and installed software
System Information- Hardware vendor, NIC vendor, etc.
Operating System Detection:
According to the HPS Applications Plugin guide:
'Windows operating system information is detected by the HPS Applications Plugin, including: Release, Package/flavor, Service Pack'
The plugin detects:
Windows OS versions (XP, Vista, 7, 8, 10, etc.)
Server editions (2003, 2008, 2012, 2016, etc.)
Service pack levels
OS build information
HTTP Banner Detection:
According to the HPS Inspection Engine guide:
'Service Banner: Indicates the service and version information, as determined by Nmap. HTTP banner scanning returns service identification information.'
The HTTP banner property is resolved by NMAP scanning with the-sVparameter, which is part of the HPS plugin's classification capabilities.
Why Other Options Are Incorrect:
A . Application installed on Mac OS- The HPS Applications Plugin is for Windows applications only; it does not detect Mac OS applications
B . External Device on Windows- External Device detection is a separate property unrelated to HPS plugin discovery
D . AD group membership- This is determined by the User Directory plugin via LDAP, not the HPS plugin
HPS Plugin vs. Other Plugins:
According to the documentation:
Property
HPS Plugin
Other Plugins
Operating System
Yes
N/A
HTTP Banner
Yes (NMAP)
N/A
Windows Applications
Yes
N/A
AD Group Membership
No
User Directory
Mac OS Applications
No
macOS-specific
External Devices
No
Network discovery
Referenced Documentation:
CounterACT Endpoint Module HPS Inspection Engine Configuration Guide v10.8
CounterACT HPS Applications Plugin Configuration Guide v2.1.4
About the HPS Applications Plugin
Based on ForeScout's recommended troubleshooting approach, where should you start the troubleshooting process?
Comprehensive and Detailed Explanation From Exact Extract of Forescout Platform Administration and Deployment:
According to theForescout troubleshooting methodology, the recommended starting point for the troubleshooting process is to'Check that requirements are met'. This foundational step must come before any detailed investigation.
Forescout Troubleshooting Approach:
The basic troubleshooting workflow consists of:
text
Step 1: CHECK THAT REQUIREMENTS ARE MET (START HERE)
System requirements
Software versions
Network connectivity
Licensing
Step 2: Look at Dependencies
Network dependencies
Service dependencies
Appliance dependencies
Step 3: Gather Information from CounterACT
GUI logs
Properties
Policies
Step 4: Gather Information from Command Line
CLI logs
Network diagnostics
Step 5: Form Hypothesis and Diagnose
Analyze findings
Determine root cause
Why Checking Requirements is the First Step:
According to the troubleshooting best practices:
Foundation- Verifying requirements prevents wasting time on invalid configurations
System Integrity- Ensures all prerequisites are met before investigating issues
Efficiency- Many issues stem from unmet requirements; fixing these resolves the problem immediately
Logical Flow- Without meeting requirements, no further troubleshooting will be effective
Why Other Options Are Incorrect:
A . Run fstool tech-support- This is an advanced diagnostic tool, not the starting point
C . Look at dependencies- Dependencies are examined AFTER confirming requirements are met
D . Examine the GUI Logs- Logs are reviewed AFTER requirements and dependencies are checked
E . Review command line logs- CLI logs are examined later in the process, not first
Requirements Verification Includes:
According to the methodology:
System Requirements
Supported OS versions
Memory and storage requirements
CPU specifications
Software Versions
Forescout platform version
Plugin/module compatibility
Browser versions for Console
Network Connectivity
IP address configuration
Network interfaces
Firewall rules
Licensing
Valid licenses
License not expired
License for required modules
Referenced Documentation:
Basic troubleshooting approach methodology
Which of the following User Directory server settings is necessary to enable guest approval by sponsors?
Comprehensive and Detailed Explanation From Exact Extract of Forescout Platform Administration and Deployment:
TheSponsor Groupis the necessary User Directory server setting required to enable guest approval by sponsors. According to theForescout User Directory Plugin Configuration Guide and Guest Management Portal documentation, Sponsor Groups must be created and configured to define the corporate employees (sponsors) who are authorized to approve or decline guest network access requests.
Sponsor Group Configuration:
In theGuest Management pane, theSponsors tabis used to define the corporate employees who are authorized to log into the Guest Management Portal to approve network access requests from guests. These employees are assigned to specificSponsor Groups, which control which sponsors can approve guest access requests.
How Sponsor Groups Enable Guest Approval:
Sponsor Definition- Corporate employees must be designated as sponsors and assigned to a Sponsor Group
Approval Authority- Sponsors in assigned groups can approve or decline guest network access requests
Authentication- When 'Enable sponsor approval without authentication via emailed link' is selected, sponsors in the designated group can approve guests based on email link authorization
Guest Registration- Guest registration options connect Sponsor Groups to the guest approval workflow
Why Other Options Are Incorrect:
A . Policy to control- While policies are used for guest control, they do not define which sponsors can approve guests
B . Guest Tags- Guest Tags are used to classify and organize guest accounts, not to enable sponsor approval
D . Guest password policy- This setting controls password requirements for guests, not sponsor approval authority
E . Authentication Server- Authentication servers verify credentials but do not establish sponsor approval groups
Referenced Documentation:
Forescout User Directory Plugin Configuration Guide - Create Sponsors section
Guest Management Portal - Sponsor Configuration documentation
'Create sponsors' - Forescout Administration Guide section
Get access to all 80 verified questions with detailed answers.
Unlock All FSCP Questions