Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet FCP_FMG_AD-7.4 FCP - FortiManager 7.4 Administrator Exam Practice Test

FCP - FortiManager 7.4 Administrator Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

An administrator is in the process of copying a system template profile between ADOMs by running the following command: execute fmprofile import-profile ADOM2 3547 /tmp/myfile Where does this command import the system template profile from?

Options:

A.

FortiManager file system

B.

ADOM2 object database

C.

ADOM2 device database

D.

Source ADOM policy database

Question 2

An administrator runs the reload failure command diagnose test deploymanager reloadconf on FortiManager.

What does this command do?

Options:

A.

It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.

B.

It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.

C.

It reloads the policy package from the FortiManager to FortiGate.

D.

It installs the latest configuration on the specified FortiGate and updates the revision history database.

Question 3

What are two outcomes of ADOM revisions? (Choose two.)

Options:

A.

ADOM revisions can create System Checkpoints for the FortiManager configuration.

B.

ADOM revisions can save the current state of the whole ADOM.

C.

ADOM revisions can significantly increase the size of the configuration backups.

D.

ADOM revisions can save the current state of all policy packages and objects for an ADOM.

Question 4

Exhibit.

What is true about the objects highlighted in the image?

Options:

A.

They can be set to optional or required.

B.

They are available across all ADOMs by default.

C.

They can be used as variables in scripts.

D.

They cannot be created in the global database ADOM.

Question 5

Which API method is used to create objects or overwrite existing ones?

Options:

A.

Set

B.

Add

C.

Exec

D.

Update

Question 6

Exhibit.

Given the configuration shown in the exhibit, what are two results from this configuration? {Choose two.)

Options:

A.

You can validate administrator login attempts through external servers.

B.

The same administrator can lock more than one ADOM at the same time.

C.

Two or more administrators can make configuration changes at the same time, in the same ADOM.

D.

Concurrent read-write access to an ADOM is disabled.

Question 7

Refer to the exhibit.

You are using the Quick Install option to install configuration changes on the managed FortiGate.

Which two statements correctly describe the result? (Choose two.)

Options:

A.

It installs provisioning template changes on the FortiGate device.

B.

It provides the option to preview only the policy package changes before installing them.

C.

It installs all the changes in the device database first and the administrator must reinstall the changes on the FortiGate device.

D.

It installs device-level changes on the FortiGate device without launching the Install Wizard

Question 8

Refer to the exhibit.

An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.

After the installation operation is performed, which IP/netmask will be installed on Local-FortiGate for theLOCAL_SUBNETfirewall address object?

Options:

A.

192.168.1.0/24

B.

Local-FortiGate automatically chooses an IP/netmask based on its network interface settings.

C.

It will create two firewall address objects on Local-FortiGate with 192.168.1.0/24 and 10.0.5.0/24 values.

D.

10.0.5.0/24

Question 9

Which output is displayed right after moving the ISFW device from one ADOM to another?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 10

Which two statements about the integrity of databases on FortiManager are correct? (Choose two.)

Options:

A.

The diagnose dvm check-integrity command attempts to fix a corrupted file system.

B.

Scheduled backups run database integrity commands automatically.

C.

Not following the correct upgrade path may cause inconsistencies in the databases.

D.

You should fix all database integrity issues before performing a backup.

E.

The diagnose cdb check adom-integrity command can correct issues related to looked devices.

Question 11

Refer to the exhibit.

An administrator is about to add the FortiGate device to FortiManager using the discovery process.

FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings.

What is the expected result?

Options:

A.

During discovery. FortiManager uses only the FortiGate serial number to establish the connection.

B.

During discovery, FortiManager sets both the FortiManager NATed IP address and NAT device IP address on FortiGate.

C.

During discovery. FortiManager sets the NATed device IP address on FortiGate.

D.

During discovery, FortiManager sets the FortiManager NATed IP address on FortiGate.

Question 12

An administrator has enabled Service Access on FortiManager. What is the purpose of Service Access on the FortiManager interface?

Options:

A.

It allows administrative access to FortiManager.

B.

It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices.

C.

It allows third-party applications to gain read/write access to FortiManager.

D.

It allows FortiManager to determine the connection status of managed devices.

Question 13

Which two items are included in the FortiManager backup? (Choose two.)

Options:

A.

All devices

B.

Firmware images

C.

FortiGuard database

D.

Flash configuration

Question 14

Push updates are failing on a FortiGate device that is located behind a NAT device. Which two settings should the administrator check? (Choose two.)

Options:

A.

That the override server IP address is set on FortiManager and the NAT device

B.

That the external IP address on the NAT device is set to DHCP and configured with the virtual IP

C.

That the NAT device IP address and correct ports are configured on FortiManager

D.

That the virtual IP address and correct ports are set on the NAT device

Question 15

An administrator created a new ADOM named Training for FortiGate devices only, and added the root FortiGate device of a Security Fabric group to the Training ADOM.

Given the administrator's actions, which statement correctly describes the expected result for the downstream devices in the Security Fabric?

Options:

A.

The downstream devices show as unauthorized in the Training ADOM

B.

The downstream devices are automatically authorized.

C.

The downstream devices will appear in the root ADOM.

D.

The downstream devices must be added using the Add Device wizard.

Question 16

Which configuration setting for FortiGate is part of an ADOM-level database on FortiManager?

Options:

A.

NSX-T Service Template

B.

Routing

C.

SNMP

D.

Security profiles

Question 17

An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.

How should the workspace mode settings be configured on FortiManager?

Options:

A.

Set to workspace and using the policy locking feature

B.

Set to read/write and using the policy locking feature

C.

Set to workflow and using the ADOM locking feature

D.

Set to normal and using the approval group feature

Question 18

Exhibit.

Which two statements about the output are true? (Choose two.)

Options:

A.

The latest revision history for the managed FortiGate does not match the device-level database.

B.

Configuration changes have been installed on FortiGate, which means the FortiGate configuration has been changed.

C.

Configuration changes directly made on FortiGate have been automatically updated to the device-level database.

D.

The latest revision history for the managed FortiGate does match the FortiGate running configuration.