Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Fortinet NSE5_FMG-7.2 Fortinet NSE 5 - FortiManager 7.2 Exam Practice Test

Fortinet NSE 5 - FortiManager 7.2 Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$42  $119.99

PDF Study Guide

  • Product Type: PDF Study Guide
$36.75  $104.99
Question 1

In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator authorized the FortiGate device on FortiManager using the Fortinet Security Fabric.

Given the administrator's actions, which statement correctly describes the expected result?

Options:

A.

The FortiManager administrator must add the authorized device to the Training ADOM using the Add Device wizard only.

B.

The authorized FortiGate will be automatically added to the Training ADOM.

C.

The authorized FortiGate will appear in the root ADOM.

D.

The authorized FortiGate can be added to the Training ADOM using FortiGate Fabric Connectors.

Question 2

An administrator is replacing a failed device on FortiManager by running the following command:

execute device replace sn .

Which device name and serial number must the administrator use?

Options:

A.

The device name of the new device and serial number of the failed device

B.

The device name and serial number of the failed device

C.

The device name of the failed device and serial number of the new device

D.

The device name and serial number of the new device

Question 3

View the following exhibit.

Which one of the following statements is true regarding the object named ALL?

Options:

A.

FortiManager updated the object ALL using FortiGate’s value in its database

B.

FortiManager updated the object ALL using FortiManager’s value in its database

C.

FortiManager created the object ALL as a unique entity in its database, which can be only used by this

managed FortiGate.

D.

FortiManager installed the object ALL with the updated value.

Question 4

What will happen if FortiAnalyzer features are enabled on FortiManager?

Options:

A.

FortiManager will keep all the logs and reports on the FortiManager.

B.

FortiManager will enable ADOMs to collect logs automatically from non-FortiGate devices.

C.

FortiManager will install the logging configuration to the managed devices

D.

FortiManager can be used only as a logging device.

Question 5

An administrator is in the process of moving the system template profile between ADOMs by running the following command:

execute improfile import-profile ADOM2 3547 /tmp/myfile

Where does the administrator import the file from?

Options:

A.

File system

B.

ADOM1

C.

ADOM2 object database

D.

ADOM2

Question 6

Refer to the exhibit.

A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices

Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?

Options:

A.

The administrator had restored the FortiManager configuration file

B.

The administrator must refresh both devices to restore connectivity

C.

FortiManager test internet connectivity therefore, both devices appear to be down

D.

The administrator can reclaim the FGFM tunnel to get both devices online

Question 7

What is the advantage of using FortiManager to manage PortiAnalyzer?

Options:

A.

It allows FortiManager to manage all FortiGate devices

B.

It allows FortiManager to fun reports based on FortiAnalyzer

C.

It allows FortiManager to store all managed FortiGate device logs

D.

It allows FortiManager to act as a collector and FortiAnalyzer device

Question 8

Which of the following statements are true regarding VPN Manager? (Choose three.)

Options:

A.

VPN Manager must be enabled on a per ADOM basis.

B.

VPN Manager automatically adds newly-registered devices to a VPN community.

C.

VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time.

D.

Common IPsec settings need to be configured only once in a VPN Community for all managed gateways.

E.

VPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.

Question 9

Refer to the exhibit.

In the event that the monitored interface for the primary FortiManager device fails, which statement is true about FortiManager HA?

Options:

A.

Manually promote one of the working secondary devices to the primary role, and reboot the old primary device to remove the peer IP of the failed device.

B.

Reboot the failed device to remove its IP from the primary device.

C.

Reconfigure the primary device lo remove the peer IP of the failed device.

D.

The FortiManager HAfailover is transparent to administrators and does not require any reconfiguration.

Question 10

What is the purpose of the Policy Check feature on FortiManager?

Options:

A.

It provides recommendations for optimizing policies in a policy package.

B.

It provides recommendations to combine similar policy packages within an ADOM into one single policy package.

C.

It compares the policy packages with the revision history, and updates policy packages in the ADOM database.

D.

It merges and creates dynamic mappings for duplicate objects used in a policy package.

Question 11

View the following exhibit:

How will FortiManager try to get updates for antivirus and IPS?

Options:

A.

From the list of configured override servers with ability to fall back to public FDN servers

B.

From the configured override server list only

C.

From the default server fdsl.fortinet.com

D.

From public FDNI server with highest index number only

Question 12

View the following exhibit.

What is the purpose of setting ADOM Mode to Advanced?

Options:

A.

The setting allows automatic updates to the policy package configuration for a managed device

B.

The setting enables the ADOMs feature on FortiManager

C.

This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.

D.

The setting disables concurrent ADOM access and adds ADOM locking

Question 13

An administrator wants to delete an address object that is currently referenced in a firewall policy.

What can the administrator expect to happen?

Options:

A.

FortiManager will not allow the administrator to delete a referenced address object

B.

FortiManager will disable the status of the referenced firewall policy

C.

FortiManager will replace the deleted address object with the none address object in the referenced

firewall policy

D.

FortiManager will replace the deleted address object with all address object in the referenced firewall policy

Question 14

Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

Options:

A.

The same administrator can lock more than one ADOM at the same time

B.

Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out

C.

Unlocking an ADOM will submit configuration changes automatically to the approval administrator

D.

Unlocking an ADOM will install configuration automatically on managed devices

Question 15

An administrator would like to review, approve, or reject all the firewall policy changes made by the junior

administrators.

How should the Workspace mode be configured on FortiManager?

Options:

A.

Set to workflow and use the ADOM locking feature

B.

Set to read/write and use the policy locking feature

C.

Set to normal and use the policy locking feature

D.

Set to disable and use the policy locking feature

Question 16

View the following exhibit:

Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)

Options:

A.

You must install these changes using Install Wizard

B.

FortiGate will auto-update the FortiManager’s device-level database.

C.

FortiManager will create a new revision history.

D.

FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.

Question 17

In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?

Options:

A.

The FortiGate will be added automatically to the default ADOM named FortiGate.

B.

The FortiGate will be automatically added to the Training ADOM.

C.

By default, the unregistered FortiGate will appear in the root ADOM.

D.

The FortiManager administrator must add the unregistered device manually to the unregistered device

manually to the Training ADOM using the Add Device wizard

Question 18

An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.

What can prevent an admin account that has Super_User rights over the device from approving a workflow session?

Options:

A.

Trainer is not a part of workflow approval group

B.

Trainer does not have full rights over this ADOM

C.

Trainer must close Student’s workflow session before approving the request

D.

Student, who submitted the workflow session, must first self-approve the request

Question 19

Which two settings must be configured for SD-WAN Central Management? (Choose two.)

Options:

A.

SD-WAN must be enabled on per-ADOM basis

B.

You can create multiple SD-WAN interfaces per VDOM

C.

When you configure an SD-WAN, you must specify at least two member interfaces.

D.

The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.

Question 20

An administrator has assigned a global policy package to a new ADOM called ADOM1. What will happen if the administrator tries to create a new policy package in ADOM1?

Options:

A.

When creating a new policy package, the administrator can select the option to assign the global policy

package to the new policy package

B.

When a new policy package is created, the administrator needs to reapply the global policy package to

ADOM1.

C.

When a new policy package is created, the administrator must assign the global policy package from the global ADOM.

D.

When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.

Question 21

What will be the result of reverting to a previous revision version in the revision history?

Options:

A.

It will install configuration changes to managed device automatically

B.

It will tag the device settings status as Auto-Update

C.

It will generate a new version ID and remove all other revision history versions

D.

It will modify the device-level database

Question 22

Which two items are included in the FortiManager backup? (Choose two.)

Options:

A.

FortiGuard database

B.

Global database

C.

Logs

D.

All devices

Question 23

What is the purpose of ADOM revisions?

Options:

A.

To create System Checkpoints for the FortiManager configuration.

B.

To save the current state of the whole ADOM.

C.

To save the current state of all policy packages and objects for an ADOM.

D.

To revert individual policy packages and device-level settings for a managed FortiGate by reverting to a specific ADOM revision

Question 24

Refer to the exhibit.

An administrator has created a firewall address object, Training which is used in the Local-FortiGate policy package.

When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for the Training firewall address object?

Options:

A.

192.168.0.1/24

B.

10.200.1.0/24

C.

It will create a firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values.

D.

Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.

Question 25

An administrator is replacing a device on FortiManager by running the following command:

execute device replace sn .

What device name and serial number must the administrator use?

Options:

A.

Device name and serial number of the original device.

B.

Device name and serial number of the replacement device.

C.

Device name of the replacement device and serial number of the original device.

D.

Device name of the original device and serial number of the replacement device.

Question 26

An administrator has enabled Service Access on FortiManager.

What is the purpose of Service Access on the FortiManager interface?

Options:

A.

Allows FortiManager to download IPS packages

B.

Allows FortiManager to respond to request for FortiGuard services from FortiGate devices

C.

Allows FortiManager to run real-time debugs on the managed devices

D.

Allows FortiManager to automatically configure a default route

Question 27

An administrator’s PC crashes before the administrator can submit a workflow session for approval. After the PC is restarted, the administrator notices that the ADOM was locked from the session before the crash.

How can the administrator unlock the ADOM?

Options:

A.

Restore the configuration from a previous backup.

B.

Log in as Super_User in order to unlock the ADOM.

C.

Log in using the same administrator account to unlock the ADOM.

D.

Delete the previous admin session manually through the FortiManager GUI or CLI.

Question 28

What does a policy package status of Conflict indicate?

Options:

A.

The policy package reports inconsistencies and conflicts during a Policy Consistency Check.

B.

The policy package does not have a FortiGate as the installation target.

C.

The policy package configuration has been changed on both FortiManager and the managed device

independently.

D.

The policy configuration has never been imported after a device was registered on FortiManager.

Question 29

Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

Options:

A.

It allows two or more administrators to make configuration changes at the same time, in the same ADOM.

B.

It disables concurrent read-write access to an ADOM.

C.

It allows the same administrator to lock more than one ADOM at the same time.

D.

It is used to validate administrator login attempts through external servers.