Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Fortinet > Fortinet Certification > NSE5_FMG-7.2

NSE5_FMG-7.2 Fortinet NSE 5 - FortiManager 7.2 Question and Answers

Question # 4

Refer to the exhibit.

Which two statements are true if the script is executed using the Device Database option? (Choose two.)

A.

You must install these changes using the Install Wizard to a managed device

B.

The successful execution of a script on the Device Database will create a new revision history

C.

The script history will show successful installation of the script on the remote FortiGate

D.

The Device Settings Status will be tagged as Modified

Full Access
Question # 5

What will be the result of reverting to a previous revision version in the revision history?

A.

It will install configuration changes to managed device automatically

B.

It will tag the device settings status as Auto-Update

C.

It will generate a new version ID and remove all other revision history versions

D.

It will modify the device-level database

Full Access
Question # 6

An administrator’s PC crashes before the administrator can submit a workflow session for approval. After the PC is restarted, the administrator notices that the ADOM was locked from the session before the crash.

How can the administrator unlock the ADOM?

A.

Restore the configuration from a previous backup.

B.

Log in as Super_User in order to unlock the ADOM.

C.

Log in using the same administrator account to unlock the ADOM.

D.

Delete the previous admin session manually through the FortiManager GUI or CLI.

Full Access
Question # 7

An administrator has enabled Service Access on FortiManager.

What is the purpose of Service Access on the FortiManager interface?

A.

Allows FortiManager to download IPS packages

B.

Allows FortiManager to respond to request for FortiGuard services from FortiGate devices

C.

Allows FortiManager to run real-time debugs on the managed devices

D.

Allows FortiManager to automatically configure a default route

Full Access
Question # 8

Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

A.

It allows two or more administrators to make configuration changes at the same time, in the same ADOM.

B.

It disables concurrent read-write access to an ADOM.

C.

It allows the same administrator to lock more than one ADOM at the same time.

D.

It is used to validate administrator login attempts through external servers.

Full Access
Question # 9

What is the purpose of ADOM revisions?

A.

To create System Checkpoints for the FortiManager configuration.

B.

To save the current state of the whole ADOM.

C.

To save the current state of all policy packages and objects for an ADOM.

D.

To revert individual policy packages and device-level settings for a managed FortiGate by reverting to a specific ADOM revision

Full Access
Question # 10

Refer to the exhibit.

In the event that the monitored interface for the primary FortiManager device fails, which statement is true about FortiManager HA?

A.

Manually promote one of the working secondary devices to the primary role, and reboot the old primary device to remove the peer IP of the failed device.

B.

Reboot the failed device to remove its IP from the primary device.

C.

Reconfigure the primary device lo remove the peer IP of the failed device.

D.

The FortiManager HAfailover is transparent to administrators and does not require any reconfiguration.

Full Access
Question # 11

Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)

A.

Managed gateways are devices managed by FortiManager in the same ADOM

B.

External gateways are third-party VPN gateway devices only

C.

Protected subnets are the subnets behind the device that you don’t want to allow access to over the IPsec

VPN

D.

Managed devices in other ADOMs must be treated as external gateways

Full Access
Question # 12

What does a policy package status of Modified indicate?

A.

FortiManager is unable to determine the policy package status

B.

The policy package was never imported after a device was registered on FortiManager

C.

The Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager

D.

The Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.

Full Access
Question # 13

Refer to the exhibit.

How will FortiManager try to get updates for antivirus and IPS?

A.

From the list of configured override servers or public FDN servers

B.

From the default server fds1.fortinet.com

C.

From the configured override server IP address 10.0.1.50 only

D.

From public FDNI server IP address with the fourth highest octet only

Full Access
Question # 14

Which three settings are the factory default settings on FortiManager? (Choose three.)

A.

The administrative domain is disabled.

B.

The Port1 interface IP address is 192.168.1.99/24.

C.

Management Extension applications are enabled.

D.

The FortiManager setup wizard is disabled.

E.

FortiAnalvzer features are disabled.

Full Access
Question # 15

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

A.

When FortiManager is auto-updated with configuration changes made directly on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager installs device-level changes on a managed device

D.

When a configuration revision is reverted to a previous revision in the revision history

Full Access
Question # 16

What does a policy package status of Never Installed indicate?

A.

The policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager.

B.

FortiManager is unable to determine the policy package status.

C.

The policy configuration has been changed on FortiManager and changes have not yet been installed on the managed device.

D.

The policy package was never imported after a device was registered on FortiManager

Full Access
Question # 17

An administrator would like to authorize a newly-installed AP using AP Manager. What steps does the administrator need to perform to authorize an AP?

A.

Authorize the new AP using AP Manager and wait until the change is updated on the FortiAP. Changes to the AP's state do not require installation.

B.

Changes to the AP's state must be performed directly on the managed FortiGate.

C.

Authorize the new AP using AP Manager and install the policy package changes on the managed FortiGate.

D.

Authorize the new AP using AP Manager and install the device level settings on the managed FortiGate.

Full Access
Question # 18

An administrator would like to create an SD-WAN using central management. What steps does the

administrator need to perform to create an SD-WAN using central management?

A.

First create an SD-WAN firewall policy, add member interfaces to the SD-WAN template and create a static route

B.

You must specify a gateway address when you create a default static route

C.

Remove all the interface references such as routes or policies

D.

Enable SD-WAN central management in the ADOM, add member interfaces, create a static route and SDWAN firewall policies.

Full Access
Question # 19

An administrator has enabled Service Access on FortiManager. What is the purpose of Service Access on the FortiManager interface?

A.

It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices.

B.

It allows FortiManager to determine the connection status of managed devices.

C.

It allows administrative access to FortiManager.

D.

It allows third-party applications to gain read/write access to FortiManager.

Full Access
Question # 20

An administrator wants to delete an address object that is currently referenced in a firewall policy.

What can the administrator expect to happen?

A.

FortiManager will not allow the administrator to delete a referenced address object

B.

FortiManager will disable the status of the referenced firewall policy

C.

FortiManager will replace the deleted address object with the none address object in the referenced

firewall policy

D.

FortiManager will replace the deleted address object with all address object in the referenced firewall policy

Full Access
Question # 21

Which configuration setting for FortiGate is part of a device-level database on FortiManager?

A.

VIP and IP Pools

B.

Firewall policies

C.

Security profiles

D.

Routing

Full Access
Question # 22

In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?

A.

The FortiGate will be added automatically to the default ADOM named FortiGate.

B.

The FortiGate will be automatically added to the Training ADOM.

C.

By default, the unregistered FortiGate will appear in the root ADOM.

D.

The FortiManager administrator must add the unregistered device manually to the unregistered device

manually to the Training ADOM using the Add Device wizard

Full Access
Question # 23

Refer to the exhibit.

Which two statements about the output are true? (Choose two.)

A.

The latest revision history for the managed FortiGate does match with the FortiGate running configuration

B.

Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed

C.

The latest history for the managed FortiGate does not match with the device-level database

D.

Configuration changes directly made on the FortiGate have been automatically updated to device-level

database

Full Access
Question # 24

An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.

What can prevent an admin account that has Super_User rights over the device from approving a workflow session?

A.

Trainer is not a part of workflow approval group

B.

Trainer does not have full rights over this ADOM

C.

Trainer must close Student’s workflow session before approving the request

D.

Student, who submitted the workflow session, must first self-approve the request

Full Access
Question # 25

Which two statements about the scheduled backup of FortiManager are true? (Choose two.)

A.

It does not back up firmware images saved on FortiManager.

B.

It can be configured using the CLI and GUI.

C.

It backs up all devices and the FortiGuard database.

D.

It supports FTP, SCP, and SFTP.

Full Access
Question # 26

Which three settings are the factory default settings on FortiManager? (Choose three.)

A.

Username is admin

B.

Password is fortinet

C.

FortiAnalyzer features are disabled

D.

Reports and Event Monitor panes are enabled

E.

port1 interface IP address is 192.168.1.99/24

Full Access
Question # 27

View the following exhibit.

What is the purpose of setting ADOM Mode to Advanced?

A.

The setting allows automatic updates to the policy package configuration for a managed device

B.

The setting enables the ADOMs feature on FortiManager

C.

This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.

D.

The setting disables concurrent ADOM access and adds ADOM locking

Full Access
Question # 28

View the following exhibit:

Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)

A.

You must install these changes using Install Wizard

B.

FortiGate will auto-update the FortiManager’s device-level database.

C.

FortiManager will create a new revision history.

D.

FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.

Full Access
Question # 29

Refer to the exhibit.

Which statement about the object named ALL is true?

A.

FortiManager updated the object ALL using the FortiGate value in its database.

B.

FortiManager installed the object ALL with the updated value.

C.

FortiManager created the object ALL as a unique entity in its database, which can be only used by this

managed FortiGate.

D.

FortiManager updated the object ALL using the FortiManager value in its database.

Full Access
Question # 30

Refer to the exhibit.

An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.

Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)

A.

The administrator logged in using the unsecure protocol HTTP, so the view is restricted.

B.

The administrator profile does not have full access privileges like the Super_User profile.

C.

The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.

D.

FortiAnalyzer features are not enabled on FortiManager.

Full Access