Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > Fortinet > NSE 6 Network Security Specialist > NSE6_FMG_AD-7.6

NSE6_FMG_AD-7.6 Fortinet NSE 6 - FortiManager 7.6 Administrator Question and Answers

Question # 4

Refer to the exhibits.

An administrator needs to push a FortiToken Mobile to assign it to HR_user in the HQ-NGFW-1.

However, when installing the policy package, they receive the following error message:

Why is the administrator not able to install the FortiToken on the HQ-NGFW-1 firewall?

A.

The administrator must use a user local meta field to assign FortiToken.

B.

The administrator must use a valid FortiToken that exists on HQ-NGFW-1.

C.

The administrator must use a metadata variable to assign the same FortiToken to multiple users in FortiManager.

D.

The administrator must use per-device mapping to assign the FortiToken to HQ-NGFW-1.

Full Access
Question # 5

You want to let multiple administrators work in the same ADOM without creating configuration conflicts.

What is the best and the most effective solution to apply?

A.

Configure RADIUS authentication to assign ADOM roles to each user.

B.

Enable workflow mode, which is the only way to prevent concurrent configuration conflicts.

C.

Assign administrators with JSON API access to the FortiManager.

D.

Activate workspace mode in the ADOM settings.

Full Access
Question # 6

Refer to the exhibit.

What are two results from the configuration shown in the exhibit? Choose two answers.

A.

The same administrator can lock more than one ADOM at the same time.

B.

Multiple administrators can lock and work on separate ADOMs at the same time.

C.

All changes must be approved before they can be installed on a device.

D.

Concurrent read-write access to an ADOM is disabled.

Full Access
Question # 7

Refer to Exhibit:

Which two actions will occur if you run the script using the Remote FortiGate Directly via CLI option? Choose two answers

A.

FortiManager will provide a preview of CLI commands before executing this script on a managed FortiGate.

B.

FortiManager will create a new revision history.

C.

FortiGate will auto-updated the FortiManager device-level database.

D.

You will have to install these changes using the Install Wizard.

Full Access
Question # 8

Refer to the exhibits.

FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ- NGFW-1 However, FortiGate does not recognize the new IPS signature from FortiManager.

What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?

A.

FortiGate must enable rating for the FortiManager IP address, 192.168.1.120, in server list 1.

B.

FortiManager and FortiGate have different IPS database versions.

C.

The administrator must enable IPv6 connections for FortiGuard services on FortiManager.

D.

The administrator must enable the fortiguard-anycast option to correctly download all signatures from the local FDS.

Full Access
Question # 9

A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM. The customer administrator has access only to My_ADOM.

How can the customer administrator edit the global header policy of the global policy package?

A.

The customer administrator can edit the header policy by using workspace mode on the global ADOM.

B.

The customer administrator can edit the header policy by using workflow mode on the global ADOM and My_ADOM.

C.

The service provider administrator can unlock the global policy from the global ADOM to authorize changes to the customer administrator.

D.

The customer administrator cannot edit the global header policy; only the service provider administrator can make changes from the global ADOM.

Full Access
Question # 10

Refer to the exhibits.

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Full Access
Question # 11

Refer to the exhibit.

An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes.

Based on the exhibit, which two things will happen if they continue with the installation? (Choose two.)

A.

FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.

B.

FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.

C.

FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.

D.

FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.

Full Access
Question # 12

Refer to the following configuration. FortiManager # config system global global# set workspace-mode normal global# end FortiManager # What are two results from the configuration shown in the exhibit? Choose two answers

A.

The same administrator can lock more than one ADOM at the same time.

B.

Multiple administrators can lock and work on separate ADOMs at the same time.

C.

All changes must be approved before they can be installed on a device.

D.

Concurrent read-write access to an ADOM is disabled.

Full Access
Question # 13

Refer to the exhibit.

What are two results from the configuration shown in the exhibit? (Choose two.)

A.

Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out.

B.

The administrator can lock policy blocks and FortiManager global ADOM.

C.

The same administrator can lock more than one ADOM at the same time.

D.

The administrator must have access to the ADOM to approve changes.

Full Access
Question # 14

An administrator must create a policy and install it on a FortiGate device within an ADOM in backup mode.

How can the administrator perform this task?

A.

Use the Install Wizard located on the device manager.

B.

Enable workflow mode to allow policy creation and approval.

C.

Make sure the ADOM and FortiGate firmware versions match and use the ADOM policy package.

D.

Use a FortiManager script to apply the configuration changes.

Full Access
Question # 15

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

Full Access
Question # 16

FortiGate is integrated with FortiAnalyzer and FortiManager.

When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

A.

Policy ID

B.

Log ID

C.

Universally Unique Identifier

D.

Sequence ID

Full Access
Question # 17

What is the best explanation of how FortiManager helps with mass provisioning?

A.

It upgrades the OS of each FortiGate device.

B.

It provides local FortiGuard Distribution Server (FDS) services to the network.

C.

It uses templates to configure the same settings on many devices simultaneously.

D.

It sends email alerts when new devices connect.

Full Access
Question # 18

An administrator created a new global policy package that includes both header policies and footer policies. What two things must the administrator know before deploying the global policy package to ADOM2? Choose two answers

A.

They can promote ADOM2 objects to global objects.

B.

They can assign the global policy package to all or selected policy packages within ADOM2.

C.

They must install from the ADOM2 layer to FortiGate when using the Automatically install policies to ADOM devices option.

D.

They can synchronize policy packages by importing from the ADOM2 policy package into the global ADOM policy package.

Full Access
Question # 19

Refer to the exhibits.

An administrator added BR1-FGT-1 to FortiManager and started importing the policy package. During the process, they saw that they need to choose values from FortiGate or FortiManager.

Which conclusion is most clearly supported by the exhibits?

A.

BR1-FGT-1 does not support the SSL/SSH profile with HTTPS on port 443.

B.

The administrator must match the FortiOS firmware version with the FortiManager ADOM firmware version to resolve the conflict status.

C.

The default Firewall Profile-Protocol-Options object is the only profile that does not significantly affect any configuration changes on either FortiManager or FortiGate.

D.

FortiManager has a different FortiGuard database compared to FortiGate BR1-FGT-1 for the QUIC protocol.

Full Access