Exit demo FCP_FMG_AD-7.6 FortiManager 7.6 Administrator PDF format · free preview

Fortinet FCP_FMG_AD-7.6 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/fcp-fmg-ad-76.html

Question 1
Single choice

An administrator has a FortiGate-HQ device with VDOMs--root, HR and Facilities, currently managed under the FortiManager ADOM--Site1. They try to move VDOM HR to the FortiManager ADOM--Site2, but
it does not work.

Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM--Site2?

A.

The FortiGate-HQ must be managed under the FortiManager ADOM--root to allow moving its VDOMs to different ADOMs.

B.

The administrator must have full access in the device layer of FortiGate-HQ VDOM-root before they can VDOMs to different ADOMs.

C.

FortiManager must be in ADOM normal mode, which does not allow VDOMs to be managed separately.

D.

The administrator must delete the FortiGate-HQ device from FortiManager and add it again using the Add Device wizard before moving the VDOM.

Question 2
Single choice

Refer to the exhibit.

An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.

After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall [VDOM1] for the LAN firewall address object?

A.

21.21.2.5/255.255.255.255

B.

172.16.5.20/255.255.255.255

C.

172.16.5.0/255.255.255.0

D.

10.10.10.5/255.255.255.255

Question 3
Multiple choice

Refer to the exhibit.

FortiManager # config system global
(global)# set workspace-mode normal
(global)# end
FortiManager #

What are two results from the configuration shown in the exhibit? (Choose two.)

A.

Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out.

B.

The administrator can lock policy blocks and FortiManager global ADOM.

C.

The same administrator can lock more than one ADOM at the same time.

D.

The administrator must have access to the ADOM to approve changes.

Question 4
Single choice

Which is recommended when you are managing a high volume of logs in your network?

A.

Store logs on FortiManager and use FortiView.

B.

Add and manage FortiAnalyzer from FortiManager.

C.

Enable advanced ADOM mode on FortiManager.

D.

Forward logs from FortiAnalyzer to FortiManager daily.

Question 5
Single choice

Refer to the exhibits.

An administrator runs the reload failure commanddiagnose test deploymanager reloadconf 262on
FortiManager.

Why does the administrator receive an error message?

A.

The administrator must use the FortiGate name instead of the ID number.

B.

The administrator just recently added FortiGate HQ-NGFW as a model device.

C.

FortiManager requires the FortiGate serial number instead of the ID number.

D.

FortiManager does not support FortiOS version 7.0.

Question 6
Multiple choice

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

Question 7
Single choice

An administrator wants to configure and manage multiple objects in the FortiManager database and give access to other users who work in the same database.

To stay in control of the changes made to firewall policies by other team members, the administrator needs a setup where all modifications go through a central check before they can be installed.

How can the administrator create this setup?

A.

Enable the prompt asking the administrator to accept firewall policies changes before saving.

B.

Enable the workspace (for all ADOMs) to control all changes made by any administrator.

C.

Enable device lock and the advanced mode feature in the ADOM.

D.

Enable workflow mode and the ADOM lock feature.

Question 8
Single choice

An administrator has assigned a global policy package to a new ADOM named ADOM1.

What will happen if the administrator tries to create a new policy package in ADOM1?

A.

The administrator will be able to select the option to assign the global policy package to the new policy package.

B.

FortiManager will automatically assign the global policy package to the new policy package.

C.

FortiManager will automatically install policies on the policy package in ADOM1.

D.

The administrator will have to assign the global policy package from the global ADOM.

Question 9
Single choice

What is the best explanation of how FortiManager helps with mass provisioning?

A.

It upgrades the OS of each FortiGate device.

B.

It provides local FortiGuard Distribution Server (FDS) services to the network.

C.

It uses templates to configure the same settings on many devices simultaneously.

D.

It sends email alerts when new devices connect.

Question 10
Single choice

Refer to the exhibits.

FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ-NGFW-1
However, FortiGate does not recognize the new IPS signature from FortiManager.

What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?

A.

FortiGate must enable rating for the FortiManager IP address, 192.168.1.120, in server list 1.

B.

FortiManager and FortiGate have different IPS database versions.

C.

The administrator must enable IPv6 connections for FortiGuard services on FortiManager.

D.

The administrator must enable the fortiguard-anycast option to correctly download all signatures from the local FDS.

Showing 10 of 109 questions · Unlock the full set