Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Certification > NSE5_FMG-7.2

NSE5_FMG-7.2 Fortinet NSE 5 - FortiManager 7.2 Question and Answers

Question # 4

An administrator is replacing a device on FortiManager by running the following command:

execute device replace sn .

What device name and serial number must the administrator use?

A.

Device name and serial number of the original device.

B.

Device name and serial number of the replacement device.

C.

Device name of the replacement device and serial number of the original device.

D.

Device name of the original device and serial number of the replacement device.

Full Access
Question # 5

An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package, Fortinet, in the custom ADOM1.

Which statement about the global policy package assignment to the newly-created policy package Fortinet is true?

A.

When a new policy package is created, it automatically assigns the global policies to the new package.

B.

When a new policy package is created, you need to assign the global policy package from the global

ADOM.

C.

When a new policy package is created, you need to reapply the global policy package to the ADOM.

D.

When a new policy package is created, you can select the option to assign the global policies to the new package.

Full Access
Question # 6

What is the purpose of the Policy Check feature on FortiManager?

A.

It provides recommendations for optimizing policies in a policy package.

B.

It provides recommendations to combine similar policy packages within an ADOM into one single policy package.

C.

It compares the policy packages with the revision history, and updates policy packages in the ADOM database.

D.

It merges and creates dynamic mappings for duplicate objects used in a policy package.

Full Access
Question # 7

Refer to the exhibit.

Which two statements are true if the script is executed using the Device Database option? (Choose two.)

A.

You must install these changes using the Install Wizard to a managed device

B.

The successful execution of a script on the Device Database will create a new revision history

C.

The script history will show successful installation of the script on the remote FortiGate

D.

The Device Settings Status will be tagged as Modified

Full Access
Question # 8

Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

A.

The FortiManager ADOM workspace mode is set to Normal.

B.

An administrator can also lock the Local-FortiGate-1 policy package.

C.

The FortiManager ADOM is locked by the administrator.

D.

FortiManager is in workflow mode.

Full Access
Question # 9

Refer to the exhibit.

A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices

Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?

A.

The administrator had restored the FortiManager configuration file

B.

The administrator must refresh both devices to restore connectivity

C.

FortiManager test internet connectivity therefore, both devices appear to be down

D.

The administrator can reclaim the FGFM tunnel to get both devices online

Full Access
Question # 10

Refer to the exhibit.

How will FortiManager try to get updates for antivirus and IPS?

A.

From the list of configured override servers or public FDN servers

B.

From the default server fds1.fortinet.com

C.

From the configured override server IP address 10.0.1.50 only

D.

From public FDNI server IP address with the fourth highest octet only

Full Access
Question # 11

Refer to the exhibit.

Given the configuration shown in the exhibit, how did FortiManager handle the service category named General?

A.

FortiManager ignored the firewall service category General but created a new service category in its database.

B.

FortiManager ignored the firewall service category general and deleted the duplicate value In Its database

C.

FortiManager ignored the firewall service category General and updated the FortiGate duplicate value in the FortiGate database.

D.

FortiManager ignored the firewall service category General and did not update Its database with the value

Full Access
Question # 12

Refer to the exhibit.

An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.

What two conclusions can you draw from the design shown in the exhibit? (Choose two.)

A.

Admin A can access VDOM2 and VDOM3 with the super user profile.

B.

The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.

C.

The administrator must set the FortiManager ADOM mode to Advanced.

D.

The administrator must configure FortiManager in workspace mode.

Full Access
Question # 13

Refer to the exhibit showing a Download Import Report.

Why is it failing to import firewall policy ID 1?

A.

Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager.

B.

The address object used in policy ID 1 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.

C.

Policy ID 1 does not have the ADOM Interface mapping configured on FortiManager.

D.

Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate.

Full Access
Question # 14

Which three settings are the factory default settings on FortiManager? (Choose three.)

A.

The administrative domain is disabled.

B.

The Port1 interface IP address is 192.168.1.99/24.

C.

Management Extension applications are enabled.

D.

The FortiManager setup wizard is disabled.

E.

FortiAnalvzer features are disabled.

Full Access
Question # 15

Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)

A.

Backs up all devices and the FortiGuard database.

B.

Does not back up firmware images saved on FortiManager

C.

Supports FTP, SCP, and SFTP

D.

Can be configured from the CLI and GUI

Full Access
Question # 16

View the following exhibit.

Which of the following statements are true based on this configuration setting? (Choose two.)

A.

This setting will enable the ADOMs feature on FortiManager.

B.

This setting is applied globally to all ADOMs.

C.

This setting will allow assigning different VDOMs from the same FortiGate to different ADOMs.

D.

This setting will allow automatic updates to the policy package configuration for a managed device.

Full Access
Question # 17

What are two outcomes of ADOM revisions? (Choose two.)

A.

ADOM revisions can significantly increase the size of the configuration backups.

B.

ADOM revisions can save the current size of the whole ADOM

C.

ADOM revisions can create System Checkpoints for the FortiManager configuration

D.

ADOM revisions can save the current state of all policy packages and objects for an ADOM

Full Access
Question # 18

Which two items does an FGFM keepalive message include? (Choose two.)

A.

FortiGate uptime

B.

FortiGate license information

C.

FortiGate IPS version

D.

FortiGate configuration checksum

Full Access
Question # 19

Refer to the exhibit.

Which statement about the object named ALL is true?

A.

FortiManager updated the object ALL using the FortiGate value in its database.

B.

FortiManager installed the object ALL with the updated value.

C.

FortiManager created the object ALL as a unique entity in its database, which can be only used by this

managed FortiGate.

D.

FortiManager updated the object ALL using the FortiManager value in its database.

Full Access
Question # 20

What will happen if FortiAnalyzer features are enabled on FortiManager?

A.

FortiManager will reboot

B.

FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager

C.

FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices

D.

FortiManager can be used only as a logging device.

Full Access
Question # 21

View the following exhibit:

How will FortiManager try to get updates for antivirus and IPS?

A.

From the list of configured override servers with ability to fall back to public FDN servers

B.

From the configured override server list only

C.

From the default server fdsl.fortinet.com

D.

From public FDNI server with highest index number only

Full Access
Question # 22

In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?

A.

The FortiGate will be added automatically to the default ADOM named FortiGate.

B.

The FortiGate will be automatically added to the Training ADOM.

C.

By default, the unregistered FortiGate will appear in the root ADOM.

D.

The FortiManager administrator must add the unregistered device manually to the unregistered device

manually to the Training ADOM using the Add Device wizard

Full Access
Question # 23

In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?

A.

Secondary device with highest priority will automatically be promoted to the primary role, and manually

reconfigure all other secondary devices to point to the new primary device

B.

Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.

C.

Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.

D.

FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.

Full Access
Question # 24

View the following exhibit, which shows the Download Import Report:

Why it is failing to import firewall policy ID 2?

A.

The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate

B.

Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager

C.

Policy ID 2 does not have ADOM Interface mapping configured on FortiManager

D.

Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.

Full Access
Question # 25

Refer to the exhibit.

You are using the Quick Install option to install configuration changes on the managed FortiGate.

Which two statements correctly describe the result? (Choose two.)

A.

It will not create a new revision in the revision history

B.

It installs device-level changes to FortiGate without launching the Install Wizard

C.

It cannot be canceled once initiated and changes will be installed on the managed device

D.

It provides the option to preview configuration changes prior to installing them

Full Access
Question # 26

View the following exhibit:

Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)

A.

You must install these changes using Install Wizard

B.

FortiGate will auto-update the FortiManager’s device-level database.

C.

FortiManager will create a new revision history.

D.

FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.

Full Access
Question # 27

Refer to the exhibit.

An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.

What is the purpose of this command?

A.

It allows FortiGate to unset central management settings.

B.

It allows FortiGate to reboot and recover the previous configuration from its configuration file.

C.

It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.

D.

It allows FortiGate to reboot and restore a previously working firmware image.

Full Access
Question # 28

An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the

managed FortiGate.

In which database will the configuration be saved?

A.

Device-level database

B.

Revision history database

C.

ADOM-level database

D.

Configuration-level database

Full Access
Question # 29

What will be the result of reverting to a previous revision version in the revision history?

A.

It will install configuration changes to managed device automatically

B.

It will tag the device settings status as Auto-Update

C.

It will generate a new version ID and remove all other revision history versions

D.

It will modify the device-level database

Full Access