Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE6_FMG_AD-7.6 - Fortinet NSE 6 - FortiManager 7.6 Administrator

Page: 2 / 2
Total 65 questions

Refer to Exhibit:

An administrator admin used the Configuration Revision History window to revert the FortiGate device configuration to revision ID 6. After running the reinstall policy package, the administrator noticed problems with the firewall policy- they could not see the unset comment on policy ID 1.

Why did FortiManager not remove the comment from policy ID 1 when the administrator ran reinstall policy package?

A.

Because the administrator student must install the configuration changes to correctly see the expected results.

B.

Because the administrator must import the firewall policies to update the firewall policy package.

C.

Because every time the administrator uses the revert config file, they must use the Install Wizard instead of running the reinstall policy package.

D.

Because the administrator used the Revision Diff view, which shows what changed, not what will be installed.

Which two statements about the integrity of databases on FortiManager are correct? Choose two answers.

A.

Scheduled backups run database integrity commands automatically.

B.

The diagnose dvm check-integrity command attempts to fix a corrupted file system.

C.

The diagnose cdb check adom-integrity command can correct issues related to locked devices.

D.

You should fix all database integrity issues before performing a script.

E.

Not following the correct upgrade path may cause inconsistencies in the databases.

An administrator created a new ADOM named Training for FortiGate devices only. Then, the administrator added the root FortiGate device of a Security Fabric group to the Training ADOM. Which statement correctly describes the expected result for the downstream devices in the Security Fabric, given the actions taken by the administrator? Choose one answer

A.

The downstream devices are automatically authorized.

B.

The downstream devices will appear in the Managed FortiGate section of the root ADOM.

C.

The downstream devices show as unauthorized in the root ADOM.

D.

The downstream devices must be added using the Add Device wizard.

While attempting to push a NetFlow configuration script through the FortiManager policy package: an administrator encounters an error stating that an object is unrecognized in line 4.

What must the administrator do to successfully apply the NetFlow configuration script and avoid the object unrecognized error?

A.

Make sure the user running the script has full access to the VDOM—AGEUSR.

B.

Run the script on the device database.

C.

Use metadata variables if they use VDOMs in the script.

D.

Create a normalized interface on the policy layer before running the script.

After correcting a policy package configuration issue, you want to prevent administrators from repeating the mistake that caused the issue.

Which FortiManager approach best meets this need?

A.

Configure an TCL script to run locally on FortiManager for each FortiGate.

B.

Restrict administrators with an administration profile from viewing the revision history to limit who can make changes.

C.

Enable the change note to require administrators to add a note whenever they change object configurations.

D.

Enable a workflow requiring approval before installing policy packages on any FortiGate.

What are two outcomes of ADOM revisions? Choose two answers.

A.

ADOM revisions can save the current state of the entire ADOM.

B.

ADOM revisions do not increase the size of configuration backups.

C.

ADOM revisions can save the current state of all policy packages and objects for an ADOM.

D.

ADOM revisions appear in the Install Policy and Package Settings section of the install wizard.

An administrator suspects that the Collector Agent is not forwarding login events to FortiGate.

What is the most effective troubleshooting step?

A.

Verify if DC agent is enabled on the FortiGate.

B.

Restart the domain controller to refresh authentication services.

C.

Verify if FortiGate is set to use LDAP authentication instead of FSSO.

D.

Check if TCP port 8000 is open between the collector agent and FortiGate.

An administrator created a new global policy package that includes both header policies and footer policies. What two things must the administrator know before deploying the global policy package to ADOM2? Choose two answers

A.

They can promote ADOM2 objects to global objects.

B.

They can assign the global policy package to all or selected policy packages within ADOM2.

C.

They must install from the ADOM2 layer to FortiGate when using the Automatically install policies to ADOM devices option.

D.

They can synchronize policy packages by importing from the ADOM2 policy package into the global ADOM policy package.

An administrator wants to configure and manage multiple objects in the FortiManager database and give access to other users who work in the same database.

To stay in control of the changes made to firewall policies by other team members, the administrator needs a setup where all modifications go through a central check before they can be installed.

How can the administrator create this setup?

A.

Enable the prompt asking the administrator to accept firewall policies changes before saving.

B.

Enable the workspace (for all ADOMs) to control all changes made by any administrator.

C.

Enable device lock and the advanced mode feature in the ADOM.

D.

Enable workflow mode and the ADOM lock feature.