Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Network Security Expert > FCP_FMG_AD-7.6

FCP_FMG_AD-7.6 Fortinet NSE 5 - FortiManager 7.6 Administrator Question and Answers

Question # 4

An administrator is copying a system template profile between ADOMs by running the following command:

execute fmprofile export-profile ADOM 3547 /tmp/Backup_File

output dump to file: [/tmp/Backup_File]

Where does this command export the system template profile from?

A.

FortiManager /tmp/Backup_File folder

B.

FortiManager ADOM policy database

C.

ADOM device database

D.

FortiManager configuration backup file

Full Access
Question # 5

What are two expected results when both FortiManager and FortiGate are behind network address translation NAT devices? Choose two answers

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

C.

FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.

D.

If the FortiGate–FortiManager communication protocol FGFM tunnel is torn down, FortiManager will try to reestablish the FGFM tunnel.

Full Access
Question # 6

An administrator assigned the Training global policy package to the Branches policy package in ADOM1. Later, the administrator created a new policy package named Remotes on ADOM1.

What should the administrator do to sync the Training global policy package with the Remotes policy package in ADOM1?

A.

Manually add and assign the Remotes policy package to the Training global policy package

B.

Use the automatically install policies to ADOM devices method to sync from the Training global policy package to the Remotes policy package

C.

Assign the Training global policy package to the Remotes policy package

D.

Unassign the Training policy package and reassign it to all policy packages within ADOM1

Full Access
Question # 7

Refer to the exhibits.

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Full Access
Question # 8

An administrator has a FortiGate-HQ device with VDOMs—root, HR and Facilities, currently managed under the FortiManager ADOM—Site1. They try to move VDOM HR to the FortiManager ADOM—Site2, but it does not work.

Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM—Site2?

A.

The FortiGate-HQ must be managed under the FortiManager ADOM—root to allow moving its VDOMs to different ADOMs.

B.

The administrator must have full access in the device layer of FortiGate-HQ VDOM-root before they can VDOMs to different ADOMs.

C.

FortiManager must be in ADOM normal mode, which does not allow VDOMs to be managed separately.

D.

The administrator must delete the FortiGate-HQ device from FortiManager and add it again using the Add Device wizard before moving the VDOM.

Full Access
Question # 9

Company policy dictates that any time a change is made to a policy package on FortiManager an ADOM revision is created before the change installed, and that revision is held for a minimum of 90 days.

Over the past three months, each installed change has resulted in several unused policies and duplicate objects.

The FortiManager administrator plans to upgrade the FortiGate devices and then upgrade the FortiManager ADOM from version 7.4 to 7.6.

Which action can the administrator take to avoid slow ADOM upgrades?

A.

Check and repair the global configuration database before upgrading.

B.

Export firewall policies to Excel, delete them on the ADOM. then reimport them after upgrading the ADOM.

C.

Find unused firmware templates, then delete them before upgrading.

D.

Limit ADOM revisions before upgrading.

Full Access
Question # 10

The administrator uses FortiManager to push a CLI script using the Remote FortiGate Directly (via CLI) option to configure an IPsec VPN. However, when running the script, the administrator receives the following error:

config vpn ipsec phase2-interface [parameter(s) invalid. detail: object mismatch]

What must the administrator do to resolve the script error and successfully apply the IPsec configuration?

A.

Add the end command after finishing the IPsec phase 1-interface configuration block.

B.

Use IPsec templates to deploy provisioning templates.

C.

Add a second config vpn ipsec phase2-interface block without linking it to phase1.

D.

Run the script using the policy package or ADOM database method.

Full Access
Question # 11

An administrator created a new global policy package that includes both header policies and footer policies. What two things must the administrator know before deploying the global policy package to ADOM2? Choose two answers

A.

They can promote ADOM2 objects to global objects.

B.

They can assign the global policy package to all or selected policy packages within ADOM2.

C.

They must install from the ADOM2 layer to FortiGate when using the Automatically install policies to ADOM devices option.

D.

They can synchronize policy packages by importing from the ADOM2 policy package into the global ADOM policy package.

Full Access
Question # 12

Refer to the exhibits.

An administrator needs to push a FortiToken Mobile to assign it to HR_user in the HQ-NGFW-1.

However, when installing the policy package, they receive the following error message:

Why is the administrator not able to install the FortiToken on the HQ-NGFW-1 firewall?

A.

The administrator must use a user local meta field to assign FortiToken.

B.

The administrator must use a valid FortiToken that exists on HQ-NGFW-1.

C.

The administrator must use a metadata variable to assign the same FortiToken to multiple users in FortiManager.

D.

The administrator must use per-device mapping to assign the FortiToken to HQ-NGFW-1.

Full Access
Question # 13

If one of the secondary FortiManager devices fails, which action must be performed to return the FortiManager HA manual mode to a working state?

A.

The FortiManager high availability HA state transition is transparent to administrators and does not require any reconfiguration.

B.

Run a sanity check on the failed device to make sure HA heartbeat packets are using TCP port 5199.

C.

Manually promote one of the working secondary devices to the primary role.

D.

Remove the peer IP of the failed device on the primary device.

Full Access
Question # 14

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

Full Access
Question # 15

An administrator has assigned a global policy package to a new ADOM named ADOM1.

What will happen if the administrator tries to create a new policy package in ADOM1?

A.

The administrator will be able to select the option to assign the global policy package to the new policy package.

B.

FortiManager will automatically assign the global policy package to the new policy package.

C.

FortiManager will automatically install policies on the policy package in ADOM1.

D.

The administrator will have to assign the global policy package from the global ADOM.

Full Access
Question # 16

Refer to the exhibits.

An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.

However, when they try to install the policy package, they receive the error shown in the exhibit.

What should the administrator do to resolve the error?

A.

Use the API to assign a system template interface for FortiGateRugged-70F model.

B.

Use a metadata variable to dynamically assign an interface when this error occurs.

C.

Create a per-device mapping for the LAN interface.

D.

Replace LAN with lan1, which is supported by FortiGateRugged-70F models.

Full Access
Question # 17

FortiGate is integrated with FortiAnalyzer and FortiManager.

When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

A.

Policy ID

B.

Log ID

C.

Universally Unique Identifier

D.

Sequence ID

Full Access
Question # 18

Refer to the exhibits.

An administrator runs the reload failure command diagnose test deploymanager reloadconf 262 on FortiManager.

Why does the administrator receive an error message?

A.

The administrator must use the FortiGate name instead of the ID number.

B.

The administrator just recently added FortiGate HQ-NGFW as a model device.

C.

FortiManager requires the FortiGate serial number instead of the ID number.

D.

FortiManager does not support FortiOS version 7.0.

Full Access
Question # 19

Refer to the exhibits.

Which IP/netmask will be present in the LAN firewall address object on the Remote-Firewall?

A.

172.16.0.0/255.255.255.0

B.

10.0.0.0/255.255.255.0

C.

192.168.1.0/255.255.255.0

D.

172.16.10.0/255.255.255.0

Full Access