Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE6_FMG_AD-7.6 - Fortinet NSE 6 - FortiManager 7.6 Administrator

Page: 1 / 2
Total 65 questions

You want to let multiple administrators work in the same ADOM without creating configuration conflicts.

What is the best and the most effective solution to apply?

A.

Configure RADIUS authentication to assign ADOM roles to each user.

B.

Enable workflow mode, which is the only way to prevent concurrent configuration conflicts.

C.

Assign administrators with JSON API access to the FortiManager.

D.

Activate workspace mode in the ADOM settings.

Refer to the exhibits.

An administrator needs to push a FortiToken Mobile to assign it to HR_user in the HQ-NGFW-1.

However, when installing the policy package, they receive the following error message:

Why is the administrator not able to install the FortiToken on the HQ-NGFW-1 firewall?

A.

The administrator must use a user local meta field to assign FortiToken.

B.

The administrator must use a valid FortiToken that exists on HQ-NGFW-1.

C.

The administrator must use a metadata variable to assign the same FortiToken to multiple users in FortiManager.

D.

The administrator must use per-device mapping to assign the FortiToken to HQ-NGFW-1.

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

The administrator uses FortiManager to push a CLI script using the Remote FortiGate Directly (via CLI) option to configure an IPsec VPN. However, when running the script, the administrator receives the following error:

config vpn ipsec phase2-interface [parameter(s) invalid. detail: object mismatch]

What must the administrator do to resolve the script error and successfully apply the IPsec configuration?

A.

Add the end command after finishing the IPsec phase 1-interface configuration block.

B.

Use IPsec templates to deploy provisioning templates.

C.

Add a second config vpn ipsec phase2-interface block without linking it to phase1.

D.

Run the script using the policy package or ADOM database method.

Refer to the exhibit.

An administrator has assigned the default system template to install all devices with the FortiAnalyzer IP address 10.0.13.12. However, not all FortiGate devices can reach FortiAnalyzer using the default interface. Some devices may use the LAN interface, while others may use the WAN interface. How can the administrator change the source interface for FortiGate devices using the default system template? Choose one answer

A.

Use per-device dynamic object configurations at the ADOM level and apply them in the template.

B.

Configure a metadata variable at the ADOM level and use it in the template.

C.

Create a different system template for each FortiGate, if the configuration is different.

D.

Create a meta field on FortiManager system settings of type Device and use it in the template.

Refer to the exhibit.

FortiManager is operating behind a network address translation (NAT) device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings.

What is the expected result during discovery?

A.

FortiManager sets both the 100.65.0.120 IP address and 10.0.13.120 IP address on FortiGate.

B.

FortiManager sets both the 100.65.0.120 IP address and 100.65.0.101 IP address on FortiGate.

C.

FortiManager sets the 100.65.0.101 IP address on FortiGate.

D.

FortiManager sets the 100.65.0.120 IP address on FortiGate.

Refer to the exhibit.

What can you conclude from the downloaded import report?

A.

FortiManager does not support per-device mapping for firewall addresses.

B.

The administrator will see a new policy package named Remote-FortiGate_root in the FortiManager ADOM database.

C.

FortiManager will change the configuration of REMOTE_SUBNET to match the interface mapping coming in from Remote-FortiGate.

D.

As a result of this policy import process, FortiManager will create a new firewall address called REMOTE_SUBNET in the ADOM database.

Refer to the exhibit.

An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes.

Based on the exhibit, which two things will happen if they continue with the installation? (Choose two.)

A.

FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.

B.

FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.

C.

FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.

D.

FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.

Refer to the exhibit.

What are two results from the configuration shown in the exhibit? Choose two answers.

A.

The same administrator can lock more than one ADOM at the same time.

B.

Multiple administrators can lock and work on separate ADOMs at the same time.

C.

All changes must be approved before they can be installed on a device.

D.

Concurrent read-write access to an ADOM is disabled.

Which output is displayed right after moving the ISFW device from one ADOM to another?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D