Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet FCP_FMG_AD-7.6 - Fortinet NSE 5 - FortiManager 7.6 Administrator

Page: 2 / 2
Total 65 questions

An administrator created a new ADOM named Training for FortiGate devices only. Then, the administrator added the root FortiGate device of a Security Fabric group to the Training ADOM. Which statement correctly describes the expected result for the downstream devices in the Security Fabric, given the actions taken by the administrator? Choose one answer

A.

The downstream devices are automatically authorized.

B.

The downstream devices will appear in the Managed FortiGate section of the root ADOM.

C.

The downstream devices show as unauthorized in the root ADOM.

D.

The downstream devices must be added using the Add Device wizard.

Refer to the exhibits.

An administrator added BR1-FGT-1 to FortiManager and started importing the policy package. During the process, they saw that they need to choose values from FortiGate or FortiManager.

Which conclusion is most clearly supported by the exhibits?

A.

BR1-FGT-1 does not support the SSL/SSH profile with HTTPS on port 443.

B.

The administrator must match the FortiOS firmware version with the FortiManager ADOM firmware version to resolve the conflict status.

C.

The default Firewall Profile-Protocol-Options object is the only profile that does not significantly affect any configuration changes on either FortiManager or FortiGate.

D.

FortiManager has a different FortiGuard database compared to FortiGate BR1-FGT-1 for the QUIC protocol.

Refer to the exhibit.

An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes.

Based on the exhibit, which two things will happen if they continue with the installation? (Choose two.)

A.

FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.

B.

FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.

C.

FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.

D.

FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.

Refer to the exhibits.

An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.

However, when they try to install the policy package, they receive the error shown in the exhibit.

What should the administrator do to resolve the error?

A.

Use the API to assign a system template interface for FortiGateRugged-70F model.

B.

Use a metadata variable to dynamically assign an interface when this error occurs.

C.

Create a per-device mapping for the LAN interface.

D.

Replace LAN with lan1, which is supported by FortiGateRugged-70F models.

Refer to the exhibit.

How does FortiManager get antivirus and IPS updates? Choose one answer

A.

It uses all URLs in the list that contain the fds host name.

B.

It gets updates from the server with IP address 10.0.1.50.

C.

It connects to all servers marked as FortiGuard Distribution Network through Internet FDNI sources.

D.

It connects to the public FortiGuard servers listed in the configuration

An administrator suspects that the Collector Agent is not forwarding login events to FortiGate.

What is the most effective troubleshooting step?

A.

Verify if DC agent is enabled on the FortiGate.

B.

Restart the domain controller to refresh authentication services.

C.

Verify if FortiGate is set to use LDAP authentication instead of FSSO.

D.

Check if TCP port 8000 is open between the collector agent and FortiGate.

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

A.

FortiGate devices using the legacy login method.

B.

The secure management tunnel between FortiManager and FortiGate devices.

C.

The script using the Remote FortiGate Directly via CLI option.

D.

The script on the FortiManager device database.

An administrator notices that CLI scripts are failing on some FortiGate devices because they use different FortiOS versions.

Which two actions should the administrator take to fix the failing CLI scripts? Choose two answers.

A.

Create separate ADOMs for each FortiOS version.

B.

Disable CLI scripts for devices using older firmware.

C.

Modify the CLI scripts to include conditional commands based on FortiOS version.

D.

Create version-specific CLI script groups and assign them to the appropriate devices.

FortiGate is integrated with FortiAnalyzer and FortiManager.

When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

A.

Policy ID

B.

Log ID

C.

Universally Unique Identifier

D.

Sequence ID