Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet FCP_FMG_AD-7.6 Fortinet NSE 5 - FortiManager 7.6 Administrator Exam Practice Test

Fortinet NSE 5 - FortiManager 7.6 Administrator Questions and Answers

Question 1

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

Options:

A.

FortiGate devices using the legacy login method.

B.

The secure management tunnel between FortiManager and FortiGate devices.

C.

The script using the Remote FortiGate Directly via CLI option.

D.

The script on the FortiManager device database.

Question 2

What are two expected results when both FortiManager and FortiGate are behind network address translation NAT devices? Choose two answers

Options:

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

C.

FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.

D.

If the FortiGate–FortiManager communication protocol FGFM tunnel is torn down, FortiManager will try to reestablish the FGFM tunnel.

Question 3

Refer to the exhibit.

Question # 3

An administrator has assigned the default system template to install all devices with the FortiAnalyzer IP address 10.0.13.12. However, not all FortiGate devices can reach FortiAnalyzer using the default interface. Some devices may use the LAN interface, while others may use the WAN interface. How can the administrator change the source interface for FortiGate devices using the default system template? Choose one answer

Options:

A.

Use per-device dynamic object configurations at the ADOM level and apply them in the template.

B.

Configure a metadata variable at the ADOM level and use it in the template.

C.

Create a different system template for each FortiGate, if the configuration is different.

D.

Create a meta field on FortiManager system settings of type Device and use it in the template.

Question 4

What are two outcomes of ADOM revisions? Choose two answers.

Options:

A.

ADOM revisions can save the current state of the entire ADOM.

B.

ADOM revisions do not increase the size of configuration backups.

C.

ADOM revisions can save the current state of all policy packages and objects for an ADOM.

D.

ADOM revisions appear in the Install Policy and Package Settings section of the install wizard.

Question 5

An administrator sees that the policy package status of HQ-NGFW-1 is Never Installed. What can you conclude from this status? Choose one answer

Options:

A.

The policies have not yet been retrieved from the HQ-NGFW-1 device-level database of FortiManager.

B.

The policy package was never imported to the revision history after HQ-NGFW-1 was registered on FortiManager.

C.

The firewall policies were created or changed in the ADOM, and they need to be installed on the managed HQ-NGFW-1 for the first time.

D.

The firewall policies exist only in the HQ-NGFW-1 device-level database, and no policy package has been assigned to the firewall.

Question 6

Refer to Exhibits:

Question # 6

Question # 6

An administrator has observed the performance status outputs on an HA cluster for 55 seconds.

Which FortiGate is the primary?

Options:

A.

HQ-NGFW-2 with the parameter memory-failover-threshold setting

B.

HQ-NGFW-2 with the parameter priority setting

C.

HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting

D.

HQ-NGFW-1 with the parameter override setting

Question 7

Refer to the exhibit.

Question # 7

What percentage of the available RAM is being used by the process in charge of downloading the web and email filter databases from the public FortiGuard servers?

Options:

A.

1.5

B.

3.1

C.

4.1

D.

2.9

Question 8

While attempting to push a NetFlow configuration script through the FortiManager policy package: an administrator encounters an error stating that an object is unrecognized in line 4.

Question # 8

What must the administrator do to successfully apply the NetFlow configuration script and avoid the object unrecognized error?

Options:

A.

Make sure the user running the script has full access to the VDOM—AGEUSR.

B.

Run the script on the device database.

C.

Use metadata variables if they use VDOMs in the script.

D.

Create a normalized interface on the policy layer before running the script.

Question 9

Refer to the exhibits.

Question # 9

Question # 9

Which IP/netmask will be present in the LAN firewall address object on the Remote-Firewall?

Options:

A.

172.16.0.0/255.255.255.0

B.

10.0.0.0/255.255.255.0

C.

192.168.1.0/255.255.255.0

D.

172.16.10.0/255.255.255.0

Question 10

Refer to the exhibit.

Question # 10

Which two statements about the configuration shown in the exhibit are true? Choose two answers.

Options:

A.

An administrator can lock the Local-FortiGate_root policy package.

B.

The administrator created a snapshot of the Remote-FortiGate policy package.

C.

The FortiManager ADOM workspace mode is set to normal.

D.

The FortiManager is in workflow mode.

Question 11

A FortiManager administrator opens the revision history and choose to revert to a previous version.

What will this action do to the current device configuration?

Options:

A.

It will trigger an unknown device-level database status, and the administrator will have to import a policy package to sync.

B.

It will trigger a conflict status if it is using any provisioning template, and the administrator will have to install changes.

C.

It will revert both configurations: device-level database and policy layer database.

D.

It will modify the device-level database.

Question 12

Refer to the exhibit.

Question # 12

An administrator added a FortiGate device to FortiManager with the default object settings at the ADOM layer.

What can you conclude from the import policy package process of the HQ-NGFW- 1 device?

Options:

A.

The administrator must select Per Platform for all interfaces to correctly detect all interfaces from HQ-NGFW-1.

B.

The administrator must manually create the port4 interface on the ADOM layer to avoid import policy errors.

C.

FortiManager will create LAN, port4, and port6 as normalized interfaces at the ADOM layer.

D.

FortiGate may not work as expected when the administrator does not import all objects.

Question 13

What is the best explanation of how FortiManager helps with mass provisioning?

Options:

A.

It upgrades the OS of each FortiGate device.

B.

It provides local FortiGuard Distribution Server (FDS) services to the network.

C.

It uses templates to configure the same settings on many devices simultaneously.

D.

It sends email alerts when new devices connect.

Question 14

An administrator is copying a system template profile between ADOMs by running the following command:

execute fmprofile export-profile ADOM 3547 /tmp/Backup_File

output dump to file: [/tmp/Backup_File]

Where does this command export the system template profile from?

Options:

A.

FortiManager /tmp/Backup_File folder

B.

FortiManager ADOM policy database

C.

ADOM device database

D.

FortiManager configuration backup file

Question 15

An administrator configures a new BGP peer in the FortiManager device-level database of FortiGate. They reinstall the policy package to the managed FortiGate device without any errors. However, when the administrator logs in to FortiGate, they do not see the BGP configuration changes.

What is the most likely reason why FortiManager did not push the BGP peer changes to FortiGate?

Options:

A.

The administrator must run a sanity check on FortiManager to make sure the database is not corrupted.

B.

Fortigate has a BGP template assigned on the FortiManager database.

C.

The administrator must use the Install Wizard and select Install device settings only to push BGP settings

D.

The FortiGate firmware version is different from the FortiManager ADOM version.

Question 16

Refer to the exhibit.

Question # 16

FortiManager is operating behind a network address translation (NAT) device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings.

What is the expected result during discovery?

Options:

A.

FortiManager sets both the 100.65.0.120 IP address and 10.0.13.120 IP address on FortiGate.

B.

FortiManager sets both the 100.65.0.120 IP address and 100.65.0.101 IP address on FortiGate.

C.

FortiManager sets the 100.65.0.101 IP address on FortiGate.

D.

FortiManager sets the 100.65.0.120 IP address on FortiGate.

Question 17

Refer to the exhibit.

Question # 17

How does FortiManager get antivirus and IPS updates? Choose one answer

Options:

A.

It uses all URLs in the list that contain the fds host name.

B.

It gets updates from the server with IP address 10.0.1.50.

C.

It connects to all servers marked as FortiGuard Distribution Network through Internet FDNI sources.

D.

It connects to the public FortiGuard servers listed in the configuration

Question 18

Refer to the exhibit.

Question # 18

What are two results from the configuration shown in the exhibit? Choose two answers.

Options:

A.

The same administrator can lock more than one ADOM at the same time.

B.

Multiple administrators can lock and work on separate ADOMs at the same time.

C.

All changes must be approved before they can be installed on a device.

D.

Concurrent read-write access to an ADOM is disabled.

Question 19

Which output is displayed right after moving the ISFW device from one ADOM to another?

A)

Question # 19

B)

Question # 19

C)

Question # 19

D)

Question # 19

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D